ENS
In Spanish security regulation, the ENS (Esquema Nacional de Seguridad) is the mandatory security framework for the public sector and its suppliers, established by Royal Decree 311/2022. It sets security requirements by category, and it exists to raise the baseline of public-sector systems, which is a different thing from any single test of one of them.
How it works
The ENS is the framework that governs security for Spain’s public sector, and it reaches beyond public bodies themselves to the private suppliers that provide services to them, which is why it affects many organisations that are not public. It is established in Royal Decree 311/2022. In outline, it rates a system across several security dimensions, assigns it a category (basic, medium or high) from the impact a failure would cause, and then requires a set of controls whose depth scales with that category. The concrete measures are spelled out in the CCN-STIC guides, which turn the framework into specific configuration and process requirements. Conformity is demonstrated by self-declaration at the lower categories and by certification through an accredited body at the higher ones.
What goes wrong
The recurring failure is treating the ENS as a documentation exercise: writing policies that describe the required controls without implementing or testing them. A system categorised medium or high must actually meet the corresponding measures, from hardening to logging to access control, and evidence that they operate. From an attacker’s side, the interesting systems are the ones that are certified on paper and hardened to a much lower reality, because the certificate says the controls exist while the implementation says otherwise. The framework raises the baseline only if the measures are real, and a conformity built on documents rather than working controls leaves the same exposures it was meant to remove.
Where this shows up in an audit
The ENS itself is a framework, not a test: it states what has to hold, not whether it holds in a given system. Technical testing is how the framework’s controls are shown to work: an assessment scoped to the system’s category produces the evidence that the required measures resist attack, which is what an ENS auditor accepts as proof rather than a claim. We map findings to the controls the category demands and relate them to neighbouring standards such as ISO 27001. This is part of the testing that produces the evidence an ENS auditor accepts.