The requirementfor selling to public bodies
Spain’s National Security Framework (ENS, RD 311/2022) is the security framework for Spanish e-government. It’s already in force and a common requirement for private suppliers serving the public sector.
This guide summarizes the framework in plain language and does not replace legal advice. Always check the official text before making decisions.
What the ENS is
It applies to Spanish public bodies and to any private company that provides services to public administration, and rests on three pillars.
Three categories
Basic, Medium or High, based on the impact an incident would have on the information and services you handle.
75 security measures
Organized into organizational framework, operational framework and protective measures, proportional to each system’s category.
Declaration or certification
Basic category requires self-assessment; Medium and High require an audit by an accredited entity every two years.
From 2010 to today
01 / 2010
The ENS is created
Royal Decree 3/2010 creates the National Security Framework for Spanish e-government.
02 / 2022
ENS updated
Royal Decree 311/2022 updates the framework, aligning it with current threats and technologies.
03 / Today
Already required in tenders
The ENS is already in force and a common requirement in contracts and tenders with Spanish public administration.
75
Security measures
3
Categories (Basic/Medium/High)
2 years
Audit cycle (Medium/High)
2022
Last updated
Consequences of non-compliance
The ENS doesn’t impose commercial fines like the GDPR — it’s an eligibility requirement for working with public administration.
| Who | Consequence | Detail |
|---|---|---|
| Private suppliers | Loss of eligibility for public contracts | Without an ENS declaration or certification, you can’t bid on public tenders that require it. |
| Public sector | Disciplinary liability under civil service regulations | Non-compliance by a public body can lead to administrative liability for those responsible. |
98.9%
How much ISO 27001 covers of the ENS
According to Kardu’s internal control mapping, implementing the 93 controls of ISO 27001:2022 covers 98.9% of ENS requirements for Basic and Medium categories (92 of 93 controls) — the highest coverage of the 4 frameworks, because both share nearly the same control base.
What it means for your SME
If you sell software or services to any Spanish public administration, you’ll likely be asked for an ENS declaration or certification as part of the contract or tender.
The required category (Basic, Medium or High) depends on the service you provide, not the size of your company.
5 minimum requirements
- Categorization of your systems (Basic, Medium or High)
- A documented risk analysis
- An information security policy
- A service continuity plan
- A declaration of conformity (Basic) or audit (Medium/High)
Official sources
This guide is a summary. For the legal detail, consult the royal decree’s text directly.
Official ENS text on the BOE →ISO 27001 as the base, ENS included
Kardu organizes your compliance evidence around ISO 27001 and maps it to the ENS and any other frameworks that apply to you, so you don’t duplicate work across regulations.