Compliance and regulation

Spanish National Security Framework (ENS)

Adaptation, implementation and preparation for ENS certification for public administrations and their suppliers.

What it involves

What we do

The ENS is mandatory for the public sector and for the suppliers that serve it. We carry out the categorisation, risk analysis, statement of applicability and implementation of measures through to the certification audit.

What's included

  • System categorisation and risk analysis
  • Statement of applicability and adaptation plan
  • Implementation of measures and procedures (Annex II)
  • CCN-STIC guides and compliance profiles
  • Audit preparation and support
  • Maintenance and biennial audits

Who it's for

  • Public administrations and public bodies
  • Technology suppliers to the public sector
  • Entities that need the ENS to bid for public contracts

Deliverables

  • Categorisation report
  • Statement of applicability
  • Adaptation plan
  • Audit evidence

Reference frameworks and standards

ENS (RD 311/2022)CCN-STICISO 27001

Reference frameworks used to design, implement, review and evidence. They are not presented as our own certifications unless contractually applicable.

How we approach it

  1. DiscoverWe get to know your business, environment, risks and priorities.
  2. AnalyseWe assess maturity, exposure, compliance and real capabilities.
  3. DesignWe define strategy, roadmap, architecture and action plan.
  4. ImplementWe deliver controls, processes, technology and evidence.
  5. OperateWe monitor, respond and support continuous improvement.
  6. OptimiseWe measure results, reduce risk and evolve capabilities.

Let's talk

Does Spanish National Security Framework (ENS) fit your situation?

Tell us about your challenges and let's design together the best strategy to protect and strengthen your business.