What the ENS is and which regulation is in force
The National Security Framework (Esquema Nacional de Seguridad, ENS) is the Spanish legal framework setting out principles and minimum requirements for protecting public-sector information and electronic services. It is not a commercial certification or a universal checklist of controls that can be applied without context: the regulation requires security to be managed in light of each organisation’s systems, risks and responsibilities. Its purpose is to help ensure that digital public services maintain appropriate levels of confidentiality, integrity, availability, authenticity and traceability.
The current regulation is Royal Decree 311/2022 of 3 May, published in Spain’s Official State Gazette (BOE) on 4 May 2022 and in force from the following day. It replaced the previous framework under Royal Decree 3/2010. To check the regulatory position, consult the consolidated text, which records an update published on 6 November 2024. The BOE itself cautions that the consolidation is for information purposes and that, for legal purposes, the official publication of the provisions must be consulted.
It is important to distinguish the royal decree from the individual security policies that each organisation approves to organise its own compliance. Ministerial orders developing internal policies for specific departments do not replace the ENS or, on their own, determine the obligations of every public authority. For a contractual or audit decision, the main reference is the applicable regulatory text, followed by the specific documentation for the organisation and system being assessed.
Who and what it covers: public authorities, systems and suppliers
The ENS applies to the public sector as defined by administrative law, including its information systems when they are used to provide services or exercise public powers. This means looking beyond an entity’s name: what matters is which system is involved, what information it handles and which service it supports. An organisation may have systems with different functions and levels of exposure; it should not be assumed that a single label automatically describes its entire infrastructure.
Private companies may also be affected. When a public-sector entity contracts for technological services or solutions, the supplier’s systems connected with that provision are subject to ENS requirements under the terms set out in the regulation and the contract. This does not mean that every company selling technology must comply with the entire framework across all its operations. The specific relationship between the service, the systems used and the agreed obligations is essential to determining which controls and evidence are required.
For suppliers, the practical question is not simply “Do we have ENS compliance?” It is what service is being provided, which parts of the infrastructure are involved, what data is processed and which clauses allocate responsibilities. A company may need to demonstrate conformity for a specific provision without that showing that all its activities are covered. Conversely, calling a contract “hosting” or “support” does not remove requirements if the systems involved underpin the contracted public service.
Principles and measures: risk-based management
The royal decree establishes basic principles such as security as an integral process, risk-based management, prevention and detection, response and preservation, lines of defence, continuous monitoring and the separation of responsibilities. These are not interchangeable slogans: they guide how protection is organised and sustained over time. Security is not achieved merely by installing tools or drafting a policy; it requires technical, operational and governance decisions to be integrated.
The framework combines organisational and operational requirements with protection measures. System analysis and the assessment of information and services inform categorisation and the selection of measures. Therefore, there is no single recipe that applies with identical intensity to every system. An organisation must document its context, justify its decisions and check that measures remain effective as systems change, incidents occur and new dependencies emerge.
The regulation distinguishes Basic, Medium and High security categories, determined by the impact an incident would have on the relevant security dimensions. A category helps define the applicable set of measures, but it should not be presented as a quality rating or a guarantee that a system is invulnerable. Assessment must relate to the defined system and its services; it should not be used as a blanket claim about the whole organisation.
What changed with the 2022 update
Royal Decree 311/2022 replaced the 2010 regulation and updated the ENS framework. It entered into force on 5 May 2022. The revision responded to changes in digital services and threats, and reorganised obligations and measures within a framework that emphasises risk management, monitoring and adaptation. To establish which wording applies today, citing the date of approval is not enough: later amendments reflected in official sources must also be checked.
The update should not be reduced to a requirement for every supplier to obtain the same certification. Compliance depends on the scope, the system and the applicable conditions; public procurement may specify evidence, audits and responsibilities. How conformity is demonstrated can vary according to the circumstances and the regulatory and contractual requirements. Commercial claims of “ENS compliance” should therefore be checked: ask which system, service and scope the evidence covers.
In this article, the entry-into-force date and the existence of the consolidated text are treated as regulatory facts. The recommendation about what documentation to request from a supplier is practical guidance derived from that framework, not a binding legal interpretation. If an organisation needs to make a compliance decision, it should check the current text and the specific terms of its contract, and seek specialist advice where the scope is unclear.
Checklist for an organisation or supplier
A useful initial review defines the service and the assets involved before discussing certificates. Identify who is responsible for the system, what information and services are handled, what external dependencies exist and what impact an interruption or alteration would have. The organisation can then check the categorisation, documented risks, selected measures and how they are reviewed. A general statement of conformity does not, by itself, answer these questions.
In contracts, carefully review scope, allocation of responsibilities, incident management, service changes, third-party access, and the retention or return of information. It is also reasonable to request evidence appropriate to the service: documentation for the covered system, relevant results or certifications, and mechanisms for communicating significant changes. The evidence must correspond to the contracted service, not merely to the entity presenting the document.
As a short checklist, a public authority or supplier can verify the following:
- Which system and service fall within the ENS scope.
- Which category and risk assessment have been defined, and the justification for them.
- Which measures apply and who is responsible for implementing and monitoring them.
- What evidence demonstrates the specific scope and how long it remains valid.
- How incidents, changes, subcontractors and dependencies are managed.
The ENS provides a structured foundation for protection and accountability, but it is not a guarantee that incidents will not occur. Its usefulness depends on whether the assessment represents the real system and whether the measures are maintained. Documented conformity helps verify obligations; it does not replace continuous monitoring or remove the need to review risks and contracts.