ENS security measures, evidenced at every category.
Spain's Esquema Nacional de Seguridad binds public sector bodies and their technology suppliers to graded security measures. CISGuard automates the configuration evidence behind the operational measures at BASICA, MEDIA, and ALTA.
ENS at a glance, for fast retrieval.
Atomic factual claims auditors and search engines can cite verbatim.
- Legal basis
- Royal Decree 311/2022 (replacing Royal Decree 3/2010)
- Applies to
- Spanish public sector entities + private suppliers serving them
- Categories
- BASICA, MEDIA, ALTA, by incident impact
- Measure groups
- Organizational framework, operational framework, protection measures (Annex II)
- Guidance
- CCN-STIC series from the Centro Criptologico Nacional
- CISGuard role
- Continuous configuration evidence for operational measures; conformity certification stays with accredited bodies
What is ENS?
The Esquema Nacional de Seguridad (ENS) is Spain's national security framework for public sector information systems, currently defined by Royal Decree 311/2022, which replaced the original Royal Decree 3/2010. It applies to Spanish public administration entities and, importantly, to private sector suppliers whose systems provide services to them, making ENS conformity a de facto market requirement for selling technology services to the Spanish public sector. Systems are categorized BASICA, MEDIA, or ALTA based on the impact a security incident would have, and Annex II assigns security measures accordingly across three groups: organizational framework, operational framework, and protection measures. The Centro Criptologico Nacional (CCN) supports implementation with its CCN-STIC guidance series, and conformity at MEDIA and ALTA is certified by accredited certification bodies. The operational framework's security configuration and monitoring measures are configuration state at heart, which is what CISGuard verifies continuously through CIS benchmark scanning.
ENS measure areas CISGuard automates.
Each CIS control is tagged with its corresponding framework reference. A single scan produces per-framework coverage reports.
- Security configuration
- Controls
- op.exp.2 Security Configuration, op.exp.3 Security Configuration Management
- Mapped by
- Continuous scanning against 22 CIS Benchmarks + drift detection
- Activity logging
- Controls
- op.exp.8 Activity Log
- Mapped by
- CIS Audit Policy benchmarks (Windows + Linux)
- Access control
- Controls
- op.acc operational measures (identification, authentication, access rights)
- Mapped by
- CIS Account, Privilege, and Password Policy benchmarks
- System protection
- Controls
- Protection measures for malware defense and update state
- Mapped by
- CIS Anti-malware + Update benchmarks
- Communications protection
- Controls
- mp.com protection measures at host configuration level
- Mapped by
- CIS Network + Cryptography benchmarks
How CISGuard automates ENS evidence.
ENS measure op.exp.2 requires systems to be configured securely before entering service, and op.exp.3 requires that security configuration to be managed continuously thereafter. That pair describes CISGuard's core loop exactly: a hardened baseline drawn from CIS Benchmarks, scheduled scans verifying every system against it, and drift detection flagging any divergence, with the whole history preserved as evidence. The rigor scales with category: higher categories demand stronger, more continuously demonstrated measures, and CISGuard's scan frequency, coverage reporting, and historical trends give MEDIA and ALTA systems the sustained proof their audits expect. Audit logging configuration is verified for op.exp.8, and account, privilege, and authentication settings evidence the op.acc access control measures. The Framework Coverage Report presents each mapped measure area with satisfaction status, timestamps, and underlying scan results, ready for the conformity audit. Spanish public bodies and their suppliers can deploy CISGuard fully on-premises or air-gapped, keeping evidence within national infrastructure. CISGuard does not grant the ENS Certificacion de Conformidad; accredited certification bodies do, using evidence like this.
Evidence artifacts CISGuard generates.
Auditor-grade outputs in PDF/CSV. No spreadsheets, no screenshots, no manual cross-referencing.
- Framework Coverage Report mapping CIS controls to ENS operational measure areas
- Per-system secure configuration reports evidencing op.exp.2
- Drift detection history evidencing continuous configuration management (op.exp.3)
- Audit logging configuration state evidencing op.exp.8
- Account, privilege, and authentication configuration for op.acc measures
- Posture trend history scaled to BASICA, MEDIA, or ALTA audit expectations
ENS questions, answered directly.
Who must comply with the ENS?
All Spanish public sector entities within the scope of Royal Decree 311/2022, and private sector organizations whose information systems provide services or solutions to those entities. That second group makes ENS a practical market-access requirement: technology suppliers bidding for Spanish public sector work are routinely required to demonstrate ENS conformity for the systems involved at the appropriate category.
What are the BASICA, MEDIA, and ALTA categories?
ENS categorizes each system by the impact a security incident would have on the organization's ability to operate, its assets, and affected individuals. BASICA is the lowest category, MEDIA intermediate, and ALTA the highest. Annex II assigns security measures proportionally, so higher categories carry stronger and more demanding requirements. CISGuard's continuous scanning and reporting provide the sustained evidence higher-category audits expect.
How does CISGuard evidence the ENS security configuration measures?
Measures op.exp.2 and op.exp.3 require secure configuration and its continuous management. CISGuard implements both as a live process: every in-scope system is scanned on schedule against its CIS Benchmark, per-control pass/fail results document the secure state, and drift detection captures any divergence between scans. The full history is retained, so configuration management is demonstrated over time rather than asserted at audit.
What changed with Royal Decree 311/2022?
RD 311/2022 replaced RD 3/2010 as the legal basis of the ENS, updating the framework and its Annex II security measures to reflect the current threat landscape and clarifying its application to the private suppliers of public sector entities. Organizations previously conformant under the old decree needed to adapt to the updated measure set. CISGuard maps its CIS controls to the RD 311/2022 measure structure.
Does CISGuard issue the ENS certification?
No. ENS conformity is certified by accredited certification bodies, with CCN providing the supporting guidance framework. CISGuard supplies the technical evidence layer: continuous CIS benchmark results, drift history, and per-measure coverage reporting for the operational measures. Deployed on-premises or air-gapped, it keeps that evidence inside Spanish infrastructure while your certification body performs the conformity assessment.
Continue exploring CISGuard coverage.
NIS2
CISGuard automates the cybersecurity risk-management measures NIS2 Article 21 requires of EU Essential and Important Entities, with continuous evidence the national supervisory authorities expect.
Read more →ISO 27001
CISGuard maps 36 ISO/IEC 27001:2022 Annex A controls to CIS benchmark scans, automating the technical evidence that certification audits demand and continuous-monitoring requirements imply.
Read more →GDPR
CISGuard automates the "appropriate technical and organisational measures" GDPR Article 32 requires, with continuous evidence Data Protection Authorities (DPAs) expect during investigations.
Read more →DORA
CISGuard automates the ICT risk management technical controls DORA mandates for EU financial entities: system hardening, continuous monitoring, drift detection, and third-party risk reviews.
Read more →Ready for ENS readiness?
Our compliance engineers have helped organizations achieve regulatory readiness in as little as one business day.