Back to glossary

ENS security categories

2 min read

In Spanish public-sector security, the ENS security categories are the levels (basic, medium and high) that set how much protection a system needs under the Esquema Nacional de Seguridad. The category is what actually decides an assessment’s scope and cost, and the difference between a self-declaration and a certified conformity.

July 29, 2026
Compartir:

How it works

The ENS categorises a system by the impact that a security failure would have across a set of security dimensions (confidentiality, integrity, availability, authenticity and traceability). Each dimension is rated, and the highest rating drives the system’s overall category: basic, medium or high. That category then determines which controls apply and at what depth, so the same control is required to a lighter or heavier standard depending on the level. The detailed how-to sits in the CCN-STIC guides, which translate the categories into concrete measures. Conformity is evidenced differently by level: lower categories may be met with a self-declaration, while higher categories require a certified conformity through an accredited body.

What goes wrong

Two things trip organisations up. The first is under-categorising a system to reduce the workload, which leaves it protected to a lower standard than its real impact warrants, and an auditor or an attacker finds the gap. The second is treating the category as a paperwork label rather than a control requirement: a system rated medium or high must actually implement the corresponding controls, including system hardening to the guides’ standard, and evidence that they work. From the offensive side, the interesting systems are the ones categorised high on paper but hardened and monitored to a much lower reality, because the category set the expectation and the implementation never met it.

Where this shows up in an audit

The category sets the scope and the depth of the technical assessment: a high-category system is tested to a higher bar than a basic one, and the evidence produced has to match the conformity route (self-declaration or certification). We map the testing to the controls the category requires and produce the evidence an ENS auditor accepts, anchored where relevant in a Statement of Applicability. The finding is tied to both the technical weakness and the control it fails. This is part of how the testing that produces ENS evidence is scoped.

¿Quieres ver cómo trabajamos en Asperis Security?

Agenda 30 minutos con uno de nuestros especialistas. Revisamos tu stack y te decimos qué conviene probar primero.