CCN-STIC guides
The CCN-STIC guides are the security guidance series published by Spain’s Centro Criptológico Nacional. They are the reference an ENS audit works from, and the 800 series in particular sets out how the national security scheme is interpreted, implemented and evidenced in practice.
The series covers two different kinds of document and the distinction matters when planning work. Some guides are procedural: how to categorise a system, how to build the required documentation, how an audit is conducted. Others are configuration baselines for specific products and platforms, which is the part that competes directly with the CIS Benchmarks. Where both exist for the same product and disagree, an ENS audit is conducted against the national guide, and a report that cites only the international benchmark has answered a different question.
One naming point worth fixing, because it appears wrongly in supplier documents constantly: CCN-CERT is the incident response team, and the guides are CCN-STIC. The organisation and the document series are not interchangeable names.
The practical value for a supplier to Spanish public administration is credibility. A client subject to the scheme is not asking whether a system is hardened in general; they are asking which guides apply to their category, which controls those guides require, and what evidence an auditor will accept. Establishing that list first, rather than hardening to a generic baseline and mapping backwards afterwards, is how the ENS work where the applicable guides are identified before any hardening starts is scoped.