ENS compliance for businesses

Without ENS you cannot tender for public-sector contracts

We take you from categorization through to certification by an ENAC-accredited OAT. Royal Decree 311/2022, official CCN tools and work reusable for ISO 27001 and NIS2.

ENS compliance for businesses
Image 1
Image 2

Adapting to ENS means proving real compliance in an audit

If you provide services to the Public Administration, ENS is a legal requirement. Without a declaration or certificate of compliance, you are left out of tenders and renewals, no matter how competitive your pricing is.

We work with the official CCN tools (PILAR, INES, CCN-STIC guides) and our own ISO 27001 auditor, who performs the internal audit before the external one. The work can be reused for ISO 27001 and NIS2.

What a properly executed ENS adaptation includes

ENS compliance for businesses

Categorization and risk analysis

Low/Medium/High category according to the 5 ENS dimensions and risk analysis with PILAR, the official CCN tool.

ENS compliance for businesses

Adaptation plan and statement of applicability

Security policy, timeline-based plan, Annex II statement of applicability and appointment of the Security Officer (RSI).

ENS compliance for businesses

Implementation of technical and organizational measures

Annex II controls implemented in phases and prioritized by risk. Integrated with your IT, not layered on top of it.

ENS compliance for businesses

Internal audit and OAT support

Internal audit with our own ISO 27001 Auditor, upload to INES and support during the external audit by the ENAC-accredited OAT.

“IN ENS, THE LEVEL IS NOT CHOSEN. IT IS CATEGORIZED”

What changes after certifying ENS in your company

You can tender with public administrations

Ministries, regional governments, city councils, universities and public healthcare.

You reduce time spent on tenders

Prepared documentation, without improvising for every call for tenders.

You comply with NIS2 by reusing work

70-80% of the ENS work can be reused directly for NIS2.

A natural bridge to ISO 27001

If you are aiming for the international certification, you already have half the work done.

Fewer serious incidents

ENS-certified organizations have a stronger real-world security posture.

Documented legal protection

Evidence of due diligence in the event of claims or incidents.

‘Very professional. We’ve been working together for many years and will continue to do so for many more!’

Marina Frau.

Companies
that already trust us

Yes, these are some of our clients

L'Arancina
Nautinort
Lionsgate Capital
Gallery Red
Rouge
Montis Advisors
Rosello
Cristalería Amanecer
Bufete Frau
Vectobal
esRadio Baleares
L'Arancina
Nautinort
Lionsgate Capital
Gallery Red
Rouge
Montis Advisors
Rosello
Cristalería Amanecer
Bufete Frau
Vectobal
esRadio Baleares

Six signs of
a poorly delivered ENS compliance project

If someone offers you a fast, cheap ENS process or suggests lowering the level to simplify it, they are selling you a future problem. How to spot it.

They propose Low to save money

The category is determined by the information and services, not by the budget. Forcing Low can lead to the certificate being withdrawn during the audit.

They do not use CCN tools

PILAR, INES and CCN-STIC guides are the official reference. Without them, the evidence will not stand up to an OAT review.

They confuse Declaration with Certification

Low allows a self-declared Declaration of Compliance. Medium and High require Certification issued by an ENAC-accredited OAT after an audit.

They work with RD 3/2010

The current regulation is Royal Decree 311/2022. If the proposal only cites the previous one, they are out of date.

They ignore specific compliance profiles

RD 311/2022 introduced compliance profiles adapted to specific groups. Whoever ignores them will overdimension the project.

There is no plan after certification

ENS requires an annual internal audit and an external audit every 2 years. Without a maintenance plan, compliance is lost at the first review.

When it makes sense
to adapt to ENS

01

You are going to tender with public administrations

Ministries, regional governments, city councils, universities, public healthcare. Without ENS, you do not pass the tender filter.

02

You are a critical supplier to a public body

ENS applies to you by contract, not because you choose it. Your client will require compliance in order to renew.

03

You want to reuse the work for NIS2 or ISO 27001

Working on the three standards in an integrated way is cheaper and faster than doing them separately. 70-80% of the work is shared.

04

As a reputation lever

Use ENS as a reputation lever

 

How we work on ENS adaptation step by step

ENS compliance for businesses
ONE
1

Categorization

TWO
2

Risk analysis with PILAR

THREE
3

Plan and implementation

FOUR
4

Internal audit and INES

FIVE
5

Certification and maintenance

FAQs
about ENS compliance

ENS Medium: €10,000-€30,000. ENS High: €20,000-€50,000. The OAT cost must be added to this (€3,000-€7,000 depending on category). Fixed price by phase after the initial categorization.

ENS Medium: 6-12 months. ENS High: 12-18 months. Add 2-3 months for the external audit. Less time if you already have ISO 27001 or ENS from the previous version.

Low allows a Declaration of Compliance (self-declared). Medium and High require a Certificate of Compliance issued by an ENAC-accredited OAT.

ENS is a Spanish regulation for the public sector and its suppliers. ISO 27001 is a voluntary international standard. They share 70-80% of the work.

To a large extent. ENS Medium or High covers the technical basis of Article 21 of NIS2. Article 23 deadlines and the supply chain still need to be reviewed.

No. The category is determined by the dimensions applied to your system. Assigning it incorrectly can lead to the certificate being withdrawn during the audit.

Yes. They are the official CCN tools, and we use them in all our ENS adaptation projects.

A 30-minute call is enough for us to categorize your system and give you a realistic cost range.