The ENS (National Security Framework): a practical guide for IT projects
Every time a company starts working with the Spanish public administration, sooner or later the same question comes up in the room: do we comply with the National Security Framework? In the projects I have led for public administration, banking and insurance, I have seen how the ENS goes from being an awkward acronym in a tender to becoming the factor that decides whether a project moves forward or gets stuck in an audit. In this article I explain, from the trenches, what the ENS is, who it obliges and how I approach it so that it does not paralyse delivery.
What the National Security Framework is and why it matters
The National Security Framework is the framework that establishes the security policy for the use of electronic means by the Spanish public sector. It was born with Royal Decree 3/2010 and today is governed by Royal Decree 311/2022, which updated it to align it with today’s threats. Its aim is simple to state and hard to execute: to ensure that the information and services the administration handles are protected with an adequate and verifiable level of security.
What is interesting, and what many teams discover late, is that the ENS does not only affect public bodies. Any supplier that provides services to the administration or handles its information falls within the perimeter. If your company aspires to public contracts, the ENS stops being optional.
Who it really obliges
It obliges the entire public sector: central government, regional governments, local authorities and their associated bodies. And, by extension, the private-sector operators that provide services to them. I have supported medium-sized technology companies that assumed this was a matter for large consultancies, until a tender required certification of them. From then on, the ENS becomes a business requirement, not a technical formality.
The three security categories of the ENS
The National Security Framework classifies systems into three categories according to the impact an incident would have on the security dimensions. Those dimensions are five: confidentiality, integrity, traceability, authenticity and availability. Depending on the assessment, the system is labelled as basic, medium or high category.
The category determines how many measures must be implemented and with what rigour. An information portal may stay at basic, while a system that handles sensitive citizen data usually scales to high. In my experience, the most common mistake is to underestimate the category at the start to save effort, and to discover in the audit that the system was misclassified. Reclassifying halfway through a project costs far more than doing it right from the design stage.
How I approach a project under the National Security Framework
First, the risk analysis
Everything starts with a serious risk analysis. It is not a document to fill in: it is the basis on which each measure is justified. Here I always connect the ENS with the general discipline of cybersecurity risk management, because the body needs to understand what assets it protects and against what threats. If the analysis is weak, everything that follows wobbles.
Then, the statement of applicability
With the category set, the statement of applicability is drawn up: the list of measures that apply and how they are implemented. The National Security Framework organises these measures into three frameworks: organisational, operational and protection. The key is to document not only what is done, but why it was decided that way. An auditor does not look for perfection, they look for consistency and traceability in the decisions.
Finally, the audit and certification
Medium and high category systems require a formal audit every two years, carried out by an accredited body. The basic category allows a self-assessment. Preparing that audit in advance makes the difference between a smooth process and a last-minute race. When I integrate the National Security Framework from the start of the project, the audit becomes a confirmation, not a surprise.
ENS, NIS2 and DORA: how they fit without duplicating effort
A recurring question among the IT managers I work with is whether the ENS clashes with other regulations. The answer is that they overlap more than it seems. The ENS shares controls with NIS2 on incident management and continuity, and with the DORA regulation on operational resilience. Whoever manages several regulations at once gains a lot by mapping those overlaps instead of treating each framework separately.
Precisely so as not to duplicate work, I build tools that cross-reference the common controls between frameworks. That cross-cutting view, which I also apply to the general IT regulations strategy, makes it possible to comply once and demonstrate several times. It is the most efficient way to face a regulatory environment that only grows.
Common mistakes I see in ENS implementation
The first I have already mentioned: misclassifying the category. The second is treating the ENS as a one-off project and not as a living process, when it requires continuous review. The third, and perhaps the most expensive, is delegating everything to the technical department without involving management. The security the National Security Framework requires is the responsibility of the governing body, not just of whoever administers the servers. When management gets involved, compliance stops being a burden and becomes part of how the organisation operates.
In the projects I support, the ENS rarely travels alone: it is usually combined with artificial intelligence initiatives and with a general strengthening of the organisation’s cybersecurity. For companies in my area I offer precisely that combined view, as I explain on my AI and cybersecurity consultancy in Almería page, where regulatory compliance and technology adoption are approached as two sides of the same project.
Conclusion: the ENS as a competitive advantage
I have spent years watching how the National Security Framework goes from being perceived as an obstacle to becoming a lever. A certified company gains access to public contracts closed off to the competition and conveys a trust the market values. My advice, after many projects, is clear: do not wait for a tender to force you. Integrate the ENS into the design of your systems and what today looks like bureaucracy will tomorrow be a hard-to-match advantage.
Frequently asked questions about the National Security Framework
The ENS is the framework that governs the security of the electronic means of the Spanish public sector, set out by Royal Decree 311/2022. It establishes the principles and measures that public bodies and their suppliers must apply to protect information and services.
It obliges the entire public sector and, by extension, the private suppliers that provide services to the administration or handle its information. If a company aspires to public contracts, complying with the ENS stops being optional.
The ENS defines three categories (basic, medium and high) according to the impact an incident would have on confidentiality, integrity, traceability, authenticity and availability. The category determines how many measures must be implemented and with what rigour.
Medium and high category systems require a formal audit every two years by an accredited body. Basic category ones allow a self-assessment. Preparing the audit from the start of the project avoids surprises.
Do you have to apply this under DORA, NIS2 or ENS? Tell me about it.
Book 20 minutes