Skip to main content
← All frameworks
ENS (RD 311/2022) Automation

ENS security measures, evidenced at every category.

Spain's Esquema Nacional de Seguridad binds public sector bodies and their technology suppliers to graded security measures. CISGuard automates the configuration evidence behind the operational measures at BASICA, MEDIA, and ALTA.

SpainPublic Sector and Suppliers to Spanish Public Administration
Quick Facts

ENS at a glance, for fast retrieval.

Atomic factual claims auditors and search engines can cite verbatim.

Legal basis
Royal Decree 311/2022 (replacing Royal Decree 3/2010)
Applies to
Spanish public sector entities + private suppliers serving them
Categories
BASICA, MEDIA, ALTA, by incident impact
Measure groups
Organizational framework, operational framework, protection measures (Annex II)
Guidance
CCN-STIC series from the Centro Criptologico Nacional
CISGuard role
Continuous configuration evidence for operational measures; conformity certification stays with accredited bodies
Overview

What is ENS?

The Esquema Nacional de Seguridad (ENS) is Spain's national security framework for public sector information systems, currently defined by Royal Decree 311/2022, which replaced the original Royal Decree 3/2010. It applies to Spanish public administration entities and, importantly, to private sector suppliers whose systems provide services to them, making ENS conformity a de facto market requirement for selling technology services to the Spanish public sector. Systems are categorized BASICA, MEDIA, or ALTA based on the impact a security incident would have, and Annex II assigns security measures accordingly across three groups: organizational framework, operational framework, and protection measures. The Centro Criptologico Nacional (CCN) supports implementation with its CCN-STIC guidance series, and conformity at MEDIA and ALTA is certified by accredited certification bodies. The operational framework's security configuration and monitoring measures are configuration state at heart, which is what CISGuard verifies continuously through CIS benchmark scanning.

Control Mapping

ENS measure areas CISGuard automates.

Each CIS control is tagged with its corresponding framework reference. A single scan produces per-framework coverage reports.

  • Security configuration
    Controls
    op.exp.2 Security Configuration, op.exp.3 Security Configuration Management
    Mapped by
    Continuous scanning against 22 CIS Benchmarks + drift detection
  • Activity logging
    Controls
    op.exp.8 Activity Log
    Mapped by
    CIS Audit Policy benchmarks (Windows + Linux)
  • Access control
    Controls
    op.acc operational measures (identification, authentication, access rights)
    Mapped by
    CIS Account, Privilege, and Password Policy benchmarks
  • System protection
    Controls
    Protection measures for malware defense and update state
    Mapped by
    CIS Anti-malware + Update benchmarks
  • Communications protection
    Controls
    mp.com protection measures at host configuration level
    Mapped by
    CIS Network + Cryptography benchmarks
How It Works

How CISGuard automates ENS evidence.

ENS measure op.exp.2 requires systems to be configured securely before entering service, and op.exp.3 requires that security configuration to be managed continuously thereafter. That pair describes CISGuard's core loop exactly: a hardened baseline drawn from CIS Benchmarks, scheduled scans verifying every system against it, and drift detection flagging any divergence, with the whole history preserved as evidence. The rigor scales with category: higher categories demand stronger, more continuously demonstrated measures, and CISGuard's scan frequency, coverage reporting, and historical trends give MEDIA and ALTA systems the sustained proof their audits expect. Audit logging configuration is verified for op.exp.8, and account, privilege, and authentication settings evidence the op.acc access control measures. The Framework Coverage Report presents each mapped measure area with satisfaction status, timestamps, and underlying scan results, ready for the conformity audit. Spanish public bodies and their suppliers can deploy CISGuard fully on-premises or air-gapped, keeping evidence within national infrastructure. CISGuard does not grant the ENS Certificacion de Conformidad; accredited certification bodies do, using evidence like this.

Auditor Evidence

Evidence artifacts CISGuard generates.

Auditor-grade outputs in PDF/CSV. No spreadsheets, no screenshots, no manual cross-referencing.

  • Framework Coverage Report mapping CIS controls to ENS operational measure areas
  • Per-system secure configuration reports evidencing op.exp.2
  • Drift detection history evidencing continuous configuration management (op.exp.3)
  • Audit logging configuration state evidencing op.exp.8
  • Account, privilege, and authentication configuration for op.acc measures
  • Posture trend history scaled to BASICA, MEDIA, or ALTA audit expectations
Frequently Asked

ENS questions, answered directly.

Who must comply with the ENS?

All Spanish public sector entities within the scope of Royal Decree 311/2022, and private sector organizations whose information systems provide services or solutions to those entities. That second group makes ENS a practical market-access requirement: technology suppliers bidding for Spanish public sector work are routinely required to demonstrate ENS conformity for the systems involved at the appropriate category.

What are the BASICA, MEDIA, and ALTA categories?

ENS categorizes each system by the impact a security incident would have on the organization's ability to operate, its assets, and affected individuals. BASICA is the lowest category, MEDIA intermediate, and ALTA the highest. Annex II assigns security measures proportionally, so higher categories carry stronger and more demanding requirements. CISGuard's continuous scanning and reporting provide the sustained evidence higher-category audits expect.

How does CISGuard evidence the ENS security configuration measures?

Measures op.exp.2 and op.exp.3 require secure configuration and its continuous management. CISGuard implements both as a live process: every in-scope system is scanned on schedule against its CIS Benchmark, per-control pass/fail results document the secure state, and drift detection captures any divergence between scans. The full history is retained, so configuration management is demonstrated over time rather than asserted at audit.

What changed with Royal Decree 311/2022?

RD 311/2022 replaced RD 3/2010 as the legal basis of the ENS, updating the framework and its Annex II security measures to reflect the current threat landscape and clarifying its application to the private suppliers of public sector entities. Organizations previously conformant under the old decree needed to adapt to the updated measure set. CISGuard maps its CIS controls to the RD 311/2022 measure structure.

Does CISGuard issue the ENS certification?

No. ENS conformity is certified by accredited certification bodies, with CCN providing the supporting guidance framework. CISGuard supplies the technical evidence layer: continuous CIS benchmark results, drift history, and per-measure coverage reporting for the operational measures. Deployed on-premises or air-gapped, it keeps that evidence inside Spanish infrastructure while your certification body performs the conformity assessment.

Ready for ENS readiness?

Our compliance engineers have helped organizations achieve regulatory readiness in as little as one business day.