What is the ENS?
The Esquema Nacional de Seguridad (ENS), set by Royal Decree 311/2022, is Spain's information-security framework for electronic government. It sets the principles and requirements systems handling public-sector information must meet.
It classifies systems by category based on impact and requires a proportionate set of security measures, with a conformity mechanism that proves it.
Who does it apply to?
The ENS isn't just for the Administration: it extends to whoever provides services to it.
- Public-sector bodies and entities.
- Supplier companies providing services to the Administration or handling its information.
- Anyone wanting to bid in public tenders where conformity is required.
Categories and requirements
Each system is classified as basic, medium or high based on impact across five dimensions: confidentiality, integrity, traceability, authenticity and availability.
- Risk analysis and categorisation.
- Statement of applicability of measures.
- Organisational, operational and protection measures proportionate to the level.
- Audit and conformity maintenance.
How we help you comply
- Categorisation. We determine your level.
- Gap analysis. Where you stand against the ENS.
- Implementation. Measures, documentation and evidence.
- Conformity. Self-assessment or certification audit depending on the level.
- Ongoing maintenance.
With Tria the ENS stops being a mountain. If you already run your security with us, most measures and evidence are already in place; conformity is the last step, not the first.
ENS vs ISO 27001
The ENS is mandatory for the Spanish public sector; ISO 27001 is voluntary and international. They share many controls, so working one advances the other. If you sell to both government and private markets, aligning both often pays off.
Frequently asked questions
Is the ENS mandatory for my company?
If you provide services to the public administration or handle its information, yes. We help you confirm it and identify your level.
Which category (level) applies to me?
It depends on your systems' impact on public information. We determine it during categorisation.
How is conformity proven?
Through self-assessment (basic category) or a certification audit by an accredited body (medium and high).
Does the ENS help with NIS2?
Yes — many measures overlap. Having the ENS advances NIS2 compliance.