- Job title
- Digital marketing specialist
- Sector
- Packaging
- Organization type
- chain store
- Joined
- Jan 2023
- Message
- 191
We are a 6-person software company based in Madrid providing cloud-based document management solutions to public institutions and local governments. Last week, we started preparing a bid for a digital archiving tender in Andalusia with a budget of 140,000 EUR. Under the technical eligibility requirements, "compliance with the Esquema Nacional de Seguridad (ENS)" is explicitly stated as a prerequisite and formal documentation is required in the submission file.
We already have an ISO 27001 certification so we're no strangers to core information security processes. However, we keep hearing that national security framework requirements in the Spanish public sector are far stricter and much more bureaucratic. The tender specs also don't clearly state whether we need basic (básico), intermediate (medio) or high (alto) level compliance.
What exactly does this requirement entail in the Spanish market? Does our ISO 27001 count directly for the tender, or are we required to go through an independent ENS audit from scratch and obtain an accredited certification? What is the fastest and most cost-effective way to handle this process?