Kardu
España · ENS

The requirementfor selling to public bodies

Spain’s National Security Framework (ENS, RD 311/2022) is the security framework for Spanish e-government. It’s already in force and a common requirement for private suppliers serving the public sector.

This guide summarizes the framework in plain language and does not replace legal advice. Always check the official text before making decisions.

What the ENS is

It applies to Spanish public bodies and to any private company that provides services to public administration, and rests on three pillars.

Three categories

Basic, Medium or High, based on the impact an incident would have on the information and services you handle.

75 security measures

Organized into organizational framework, operational framework and protective measures, proportional to each system’s category.

Declaration or certification

Basic category requires self-assessment; Medium and High require an audit by an accredited entity every two years.

From 2010 to today

01 / 2010

The ENS is created

Royal Decree 3/2010 creates the National Security Framework for Spanish e-government.

02 / 2022

ENS updated

Royal Decree 311/2022 updates the framework, aligning it with current threats and technologies.

03 / Today

Already required in tenders

The ENS is already in force and a common requirement in contracts and tenders with Spanish public administration.

By the numbers

75

Security measures

3

Categories (Basic/Medium/High)

2 years

Audit cycle (Medium/High)

2022

Last updated

Consequences of non-compliance

The ENS doesn’t impose commercial fines like the GDPR — it’s an eligibility requirement for working with public administration.

WhoConsequenceDetail
Private suppliersLoss of eligibility for public contractsWithout an ENS declaration or certification, you can’t bid on public tenders that require it.
Public sectorDisciplinary liability under civil service regulationsNon-compliance by a public body can lead to administrative liability for those responsible.

98.9%

How much ISO 27001 covers of the ENS

According to Kardu’s internal control mapping, implementing the 93 controls of ISO 27001:2022 covers 98.9% of ENS requirements for Basic and Medium categories (92 of 93 controls) — the highest coverage of the 4 frameworks, because both share nearly the same control base.

What it means for your SME

If you sell software or services to any Spanish public administration, you’ll likely be asked for an ENS declaration or certification as part of the contract or tender.

The required category (Basic, Medium or High) depends on the service you provide, not the size of your company.

5 minimum requirements

  • Categorization of your systems (Basic, Medium or High)
  • A documented risk analysis
  • An information security policy
  • A service continuity plan
  • A declaration of conformity (Basic) or audit (Medium/High)

Official sources

This guide is a summary. For the legal detail, consult the royal decree’s text directly.

Official ENS text on the BOE →
How Kardu helps

ISO 27001 as the base, ENS included

Kardu organizes your compliance evidence around ISO 27001 and maps it to the ENS and any other frameworks that apply to you, so you don’t duplicate work across regulations.