ENS Audit

Why choose our ENS audit?

Understand what sets our audit process apart and how we ensure the integrity of your information systems:
Specific experience with the National Security Framework

We don’t just know the standard – we put it into practice. We have a proven track record of helping organisations achieve certification under the National Security Scheme, as well as other certifications such as ISO 27001 for information security, ISO 9001 for quality management, ISO 14001 for environmental management, ISO 45001 for occupational health and safety, and other ISO standards.

We have a team of certified professionals who bring an objective and technical perspective. Our independence ensures an accurate assessment of your security status, identifying gaps that others might overlook, thanks to our team of certified internal auditors.

We tailor our approach to your specific needs and circumstances. We work with you from the outset to achieve ENS certification; an external auditor will conduct an internal audit, enabling you to successfully pass the certification audit.

This comprehensive approach ensures that all aspects of security at ENS Spain are covered, reducing risks and strengthening your resilience.

Our reports are strategic documents written in plain language, which include a detailed gap analysis and practical recommendations for improvement. They serve as a roadmap designed to facilitate decision-making and streamline the process of obtaining or renewing certification.

Requirements for the audit of the National Security Scheme

The audit of the National Security Framework (ENS), governed by Royal Decree 311/2022, is not merely a technical review; it is a comprehensive assessment of how your organisation protects public information and services.

Compliance Requirements

To pass the audit successfully, your organisation must demonstrate a robust structure based on Royal Decree 311/2022.

  • System Categorisation: You must have classified your systems into Basic, Medium or High levels based on an assessment of the security dimensions (Confidentiality, Integrity, Availability, Authenticity and Traceability).
  • Risk Analysis: This is the cornerstone of the ENS certificate. The auditor will verify that the analysis is up to date and that the chosen security measures effectively mitigate the identified risks.
  • Statement of Applicability (SoA): A formal document listing which measures in Annex II of the Royal Decree are applicable and how they are being complied with.

The process follows the guidelines set out in CCN-STIC Guide 802 and focuses on three frameworks:

  • Organisational Framework: This assesses the existence of an approved Security Policy, the clear allocation of roles (Information Manager, Service Manager and Security Manager) and the ongoing training of staff.
  • Operational Framework: The auditor will review critical processes such as planning, access control, incident management and business continuity.
  • Security Measures (Technical): Verification of the protection of premises, perimeters, information media and communications. An assessment is made of whether the software and hardware are configured securely.

The ENS Spain certificate adapts to the criticality of your information through three maturity levels. Depending on the sensitivity of the data you handle, the audit requirements vary:

  • Basic Level: Self-assessment or a declaration of compliance is permitted, although many companies opt for external audits for greater assurance.
  • Intermediate and Advanced Levels: An external audit by an ENAC-accredited body is mandatory every two years to maintain the certificate.

ENS Audit FAQs

How does the National Security Framework relate to ISO 27001?

The main point is that ISO 27001 covers many of the requirements for ENS certification. If your company is already ISO 27001-certified, you’ve already come a long way, and we’ll simply need to implement the specific controls and role structure required by Spanish regulations to obtain the ENS Spain certificate.

Certification is mandatory for all entities that interact with the public administration. The following must be certified:

  1. The entire Spanish public sector: central, regional and local government bodies.
  2. Technology suppliers to the Public Sector: Private companies providing IT, hosting, software development or support services to public bodies (in accordance with Article 2 of Royal Decree 311/2022).
  3. Companies participating in Public Tenders: It is increasingly common for tender documents to require the ENS Certificate as an essential prerequisite for submitting a bid.