Skip to main content
All frameworks

ENS (RD 311/2022) Automation

ENS security measures,evidenced at every category.

Spain's Esquema Nacional de Seguridad binds public sector bodies and their technology suppliers to graded security measures. CISGuard automates the configuration evidence behind the operational measures at BASICA, MEDIA, and ALTA.

SpainPublic Sector and Suppliers to Spanish Public Administration
Legal basis
Royal Decree 311/2022 (replacing Royal Decree 3/2010)
Applies to
Spanish public sector entities + private suppliers serving them
Categories
BASICA, MEDIA, ALTA, by incident impact
Measure groups
Organizational framework, operational framework, protection measures (Annex II)
Guidance
CCN-STIC series from the Centro Criptologico Nacional
CISGuard role
Continuous configuration evidence for operational measures; conformity certification stays with accredited bodies

Overview

What is ENS?

The Esquema Nacional de Seguridad (ENS) is Spain's national security framework for public sector information systems, currently defined by Royal Decree 311/2022, which replaced the original Royal Decree 3/2010. It applies to Spanish public administration entities and, importantly, to private sector suppliers whose systems provide services to them, making ENS conformity a de facto market requirement for selling technology services to the Spanish public sector. Systems are categorized BASICA, MEDIA, or ALTA based on the impact a security incident would have, and Annex II assigns security measures accordingly across three groups: organizational framework, operational framework, and protection measures. The Centro Criptologico Nacional (CCN) supports implementation with its CCN-STIC guidance series, and conformity at MEDIA and ALTA is certified by accredited certification bodies. The operational framework's security configuration and monitoring measures are configuration state at heart, which is what CISGuard verifies continuously through CIS benchmark scanning.

How CISGuard automates ENS evidence

ENS measure op.exp.2 requires systems to be configured securely before entering service, and op.exp.3 requires that security configuration to be managed continuously thereafter. That pair describes CISGuard's core loop exactly: a hardened baseline drawn from CIS Benchmarks, scheduled scans verifying every system against it, and drift detection flagging any divergence, with the whole history preserved as evidence. The rigor scales with category: higher categories demand stronger, more continuously demonstrated measures, and CISGuard's scan frequency, coverage reporting, and historical trends give MEDIA and ALTA systems the sustained proof their audits expect. Audit logging configuration is verified for op.exp.8, and account, privilege, and authentication settings evidence the op.acc access control measures. The Framework Coverage Report presents each mapped measure area with satisfaction status, timestamps, and underlying scan results, ready for the conformity audit. Spanish public bodies and their suppliers can deploy CISGuard fully on-premises or air-gapped, keeping evidence within national infrastructure. CISGuard does not grant the ENS Certificacion de Conformidad; accredited certification bodies do, using evidence like this.

Control mapping

ENS measure areas CISGuard automates.

Each CIS control is tagged with its framework reference. One scan produces the per-framework coverage report, with satisfied, partially satisfied and not-met status for every control.

Control areaControlsMapped by
Security configurationop.exp.2 Security Configuration, op.exp.3 Security Configuration ManagementContinuous scanning against 22 CIS Benchmarks + drift detection
Activity loggingop.exp.8 Activity LogCIS Audit Policy benchmarks (Windows + Linux)
Access controlop.acc operational measures (identification, authentication, access rights)CIS Account, Privilege, and Password Policy benchmarks
System protectionProtection measures for malware defense and update stateCIS Anti-malware + Update benchmarks
Communications protectionmp.com protection measures at host configuration levelCIS Network + Cryptography benchmarks

Auditor evidence

Evidence artifacts CISGuard generates.

Auditor-grade outputs in PDF, HTML, JSON, CSV and SARIF. No spreadsheets, no screenshots, no manual cross-referencing.

  • Framework Coverage Report mapping CIS controls to ENS operational measure areas
  • Per-system secure configuration reports evidencing op.exp.2
  • Drift detection history evidencing continuous configuration management (op.exp.3)
  • Audit logging configuration state evidencing op.exp.8
  • Account, privilege, and authentication configuration for op.acc measures
  • Posture trend history scaled to BASICA, MEDIA, or ALTA audit expectations

Frequently asked

ENS questions, answered directly.

Who must comply with the ENS?

All Spanish public sector entities within the scope of Royal Decree 311/2022, and private sector organizations whose information systems provide services or solutions to those entities. That second group makes ENS a practical market-access requirement: technology suppliers bidding for Spanish public sector work are routinely required to demonstrate ENS conformity for the systems involved at the appropriate category.

What are the BASICA, MEDIA, and ALTA categories?

ENS categorizes each system by the impact a security incident would have on the organization's ability to operate, its assets, and affected individuals. BASICA is the lowest category, MEDIA intermediate, and ALTA the highest. Annex II assigns security measures proportionally, so higher categories carry stronger and more demanding requirements. CISGuard's continuous scanning and reporting provide the sustained evidence higher-category audits expect.

How does CISGuard evidence the ENS security configuration measures?

Measures op.exp.2 and op.exp.3 require secure configuration and its continuous management. CISGuard implements both as a live process: every in-scope system is scanned on schedule against its CIS Benchmark, per-control pass/fail results document the secure state, and drift detection captures any divergence between scans. The full history is retained, so configuration management is demonstrated over time rather than asserted at audit.

What changed with Royal Decree 311/2022?

RD 311/2022 replaced RD 3/2010 as the legal basis of the ENS, updating the framework and its Annex II security measures to reflect the current threat landscape and clarifying its application to the private suppliers of public sector entities. Organizations previously conformant under the old decree needed to adapt to the updated measure set. CIS benchmark results from CISGuard serve as technical evidence for the RD 311/2022 measures.

Does CISGuard issue the ENS certification?

No. ENS conformity is certified by accredited certification bodies, with CCN providing the supporting guidance framework. CISGuard supplies the technical evidence layer: continuous CIS benchmark results, drift history, and per-measure coverage reporting for the operational measures. Deployed on-premises or air-gapped, it keeps that evidence inside Spanish infrastructure while your certification body performs the conformity assessment.

ENS readiness, on request.

Our compliance engineers have helped organizations achieve regulatory readiness through a seamless, fully managed deployment.