forumNew topic

A public agency is asking us to comply with ENS — what is it and how do you get certified in Spain?

VVolkan A***Veteran
Job title
Digital marketing specialist
Sector
Packaging
Organization type
chain store
Joined
Jan 2023
Message
191
#1

We are a 6-person software company based in Madrid providing cloud-based document management solutions to public institutions and local governments. Last week, we started preparing a bid for a digital archiving tender in Andalusia with a budget of 140,000 EUR. Under the technical eligibility requirements, "compliance with the Esquema Nacional de Seguridad (ENS)" is explicitly stated as a prerequisite and formal documentation is required in the submission file.

We already have an ISO 27001 certification so we're no strangers to core information security processes. However, we keep hearing that national security framework requirements in the Spanish public sector are far stricter and much more bureaucratic. The tender specs also don't clearly state whether we need basic (básico), intermediate (medio) or high (alto) level compliance.

What exactly does this requirement entail in the Spanish market? Does our ISO 27001 count directly for the tender, or are we required to go through an independent ENS audit from scratch and obtain an accredited certification? What is the fastest and most cost-effective way to handle this process?

OOrhan Ç***Expert
Job title
Data Analyst
Sector
Chemistry
Organization type
family business
Joined
Oct 2024
Message
15
Most Helpful#2

Short answer: In Spain, the ENS (Esquema Nacional de Seguridad) is a mandatory national security framework for public institutions and the private companies providing technology to them. Your ISO 27001 does not directly substitute for ENS; depending on the sensitivity and scope of the data your system processes, you are required to obtain a formal certificate or declaration of conformity at the basic, intermediate, or high level.

The ENS framework is split into three security tiers: Basic (Básico) Intermediate (Medio), and High (Alto). Unless your tender directly involves critical infrastructure or confidential personal health data basic or intermediate is usually what's required. If the requirement is basic, an accredited external audit is not mandatory. You can carry out your own self-assessment following National Cryptologic Centre (CCN) guidelines and publish a formal declaration of conformity (Declaración de Conformidad).

If the tender requires intermediate or high, you must be audited by an independent ENAC-accredited certification body and obtain an official certificate of conformity (Certificación de Conformidad). Holding an ISO 27001 gives you a massive head start because a significant portion of ENS controls overlap directly with ISO standards.

Your first step should be submitting a formal inquiry to the contracting authority to clarify the required ENS tier. If it's basic you can prepare the declaration in-house within 2-3 weeks. If intermediate is required you'll need to engage an accredited auditor; this process typically takes 2 to 4 months, and audit costs generally run between 7,000 and 14,000 EUR.

SSinemExpert
Job title
Project manager
Joined
Oct 2023
Message
176
#3

If the tender doesn't specify the tier, request an official clarification (aclaración) via the procurement portal right away. If they say basic, you don't have to pay an external auditor a single cent—just fill out the standard checklist on the CCN platform and register your system. Send the question without wasting time.

DDoruk S***New memberCommunity member
Joined
Aug 2026
Message
278
#4

We bid on a 110,000 EUR public tender in Valencia last year. They asked us for ENS Medio. We already had our ISO 27001 foundation in place, but closing the gaps and passing the audit still took a solid 3 months. We paid 8,500 EUR for the accredited audit and another 4,000 EUR for consulting support.

ÖÖzge Ç***Member
Job title
Administrative manager
Sector
Accounting & advisory
Organization type
120-person company
Joined
Nov 2024
Message
2
#5

On the technical side, the biggest divergence from ISO comes down to the CCN-STIC guides. For data encryption algorithms, you can only use standards approved by the Spanish National Cryptologic Centre, you must integrate your incident reporting mechanism with the government reporting platform, and MFA is mandatory for all system administrators.

YYiğit Ç***MemberCommunity member
Joined
Mar 2025
Message
107
#6

Whatever you do, don't fall into the trap of thinking "we have an ISO certificate, we'll just attach that and the agency will accept it." In public tenders, bids lacking the proper ENS certificate or declaration are disqualified outright during the administrative screening—they won't even open your technical envelope.

MMerve B***New memberCommunity member
Joined
Aug 2026
Message
247
#7

Here is the roadmap you should follow: 1) Get written clarification on the ENS tier from the contracting authority. 2) Download the CCN-STIC 800 series guides and run a gap analysis against your existing ISO setup. 3) If basic, draft an internal declaration; if intermediate, start collecting quotes immediately from ENAC-accredited bodies.

MMurat K***Member
Job title
SaaS developer
Organization type
boutique agency
Joined
Mar 2024
Message
118

Doki · Log management setup · 2025

#8

spanish bureaucracy is super rigid on this stuff unfortunately. we narrowly saved a similar municipal contract with a basic tier self-declaration, otherwise an external audit wouldnt have made the deadline in time.

FFurkan U***Member
Job title
Administrative manager
Sector
Energy
Organization type
40-person manufacturing company
Joined
Jul 2025
Message
84
#9

It's worth noting that the updated Royal Decree issued in 2022 restructured ENS requirements for cloud providers. Verifying that the cloud provider hosting your infrastructure already holds an ENS certification will significantly streamline your audit process.

FFerhat G***New memberCommunity member
Joined
May 2026
Message
180
#10

The discussion got scattered, let me summarize. Having backups accessible on the same network and with the same identity makes them part of the target.

If you have questions, write them; I'll answer as best I can.

NNazlı Ş***New member
Job title
Product Manager
Sector
Healthcare services
Organization type
20-person company
Joined
Jun 2026
Message
351

Doki · Infrastructure migration · 2023

#11

Let me summarize the topic, since several different answers were given. Mistakes made on the national security scheme side are usually reversible but expensive.

Hope this helps.

BBurak Can M***Veteran
Job title
Founder · e-commerce
Organization type
20-person company
Joined
Apr 2023
Message
212
#12

I agree.

LLale A***Member
Job title
Site Manager
Sector
IT services
Organization type
cooperative
Joined
Jul 2023
Message
86
#13

There are three things to check when doing this. Mistakes made on the national security scheme side are usually reversible but expensive.

I'm also curious if anyone does it differently.

SSelin U***MemberCommunity member
Joined
Mar 2026
Message
2
#14

Following. If 2FA is on, a stolen password alone is useless.

ÜÜlkü B***New memberCommunity member
Joined
Sep 2026
Message
240
#15

I'll try it. Don't hesitate to ask; those who don't ask always pay more.

If you don't write this down from the start, it leads to arguments later. I'm also curious if anyone does it differently.

PPolat K***MemberCommunity member
Joined
May 2025
Message
27
#16

Noted, thanks.

İİlknur C***MemberCommunity member
Joined
Feb 2025
Message
18
#17

its rare to find an explanation this clear and like when you try to change everything at once nothing settles.

im also curious if anyone does it differently.

EEfe K***Expert
Job title
Field sales representative
Sector
Chemistry
Organization type
8-person team
Joined
Apr 2024
Message
136
#18

I've been dealing with this for a long time. Your time to detect an issue directly determines its cost.

If you have questions write them; I'll answer as best I can.

GGökhan A***Member
Job title
Manufacturer · furniture
Joined
Oct 2023
Message
74
#19

This approach has a cost, which isn't discussed. Mistakes made on the national security scheme side are usually reversible but expensive.

If you don't write this down from the start, it leads to arguments later. Good luck with that.

SSerkan U***Member
Job title
Site Manager
Sector
Education
Organization type
medium-sized business
Joined
May 2025
Message
312
#20

My question might sound amateurish, sorry about that. Solutions that work at a small scale collapse when you grow; I learned this late.

This is my opinion, I'm not claiming it's absolute truth.

Reply