Final pentest report
- One document for management, technical team and audit: executive summary, technical report with proofs of concept, and prioritised remediation guide.
The ENS (Esquema Nacional de Seguridad) is Spain’s security standard for the public sector and the companies that supply it. To pass its audit you cannot just describe your security, you have to show it holds up. We run the penetration testing that gives you that proof: real weaknesses found, fixed and checked again, in evidence your auditor accepts.
We’ll be in touch within one business day with next steps.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
We’ll be in touch within one business day with next steps.
No se ha podido enviar. Inténtalo otra vez o escríbenos.















A scanner gives you a list of maybe-problems. A pentest shows what a real attacker could actually do, and whether your defences hold when someone pushes on them.
For Medium and High categories, you re-audit at least every two years, and again after any big change to your systems. The simplest approach is to line your pentest up with that cycle, and bring it forward whenever something significant changes.
Before certifying a MEDIUM or HIGH-category system, the auditor expects evidence that the controls hold. The pentest produces it.
When the audit report points at a specific control, you have to show with evidence whether it is exploitable and how far it reaches.
A substantial change to applications, infrastructure, cloud, remote access or identity moves the scope, and what was tested before no longer covers it.
After you apply the fixes, we verify each one, update its status and leave documented evidence of closure.
For Medium and High categories you re-audit at least every two years. Lining the pentest up with that cycle means not walking into the audit blind.
You have a go-live date and ENS requires a security check before that step; at Medium category and above, in an isolated pre-production environment. We test the system there, fully built and with no users yet, and leave the evidence.
At Basic category, self-assessing the system and declaring it was enough. When it moves up to Medium, certifying it takes an independent audit, and new controls come in. We test the technical ones and leave you the evidence.
A full security cycle, packaged the way an ENS audit report needs it.
From day one, findings live in our platform, not just in a document: managed, assigned and closed with full traceability, and exportable as audit-ready evidence for your ENS file. It does not replace the report; it turns it into an operational tool.
We at Etnia highly value our collaboration with Asperis Security.
If your situation doesn’t match any answer here, that’s the call.
They are different jobs and one does not replace the other. The ENS audit rules on how far you comply with the royal decree and identifies findings of compliance and non-compliance (article 31.4), and one of the things it has to establish is that the Annex II protection measures are met (Annex III, 1.1.e).
That is where the penetration test comes in. We attack the system and show which controls hold and which do not, and Annex III itself allows audit activities involving checks on the systems, planned and agreed in advance (1.3). The auditor rules; we supply the technical proof.
It sets what has to be tested and how deep. Your category comes from the impact an incident would have (Annex I) and pulls in the Annex II controls that apply to you, with their reinforcements.
Specifically: at High category, penetration testing is listed as a required inspection [op.mon.3.r6.3]. And with third-party cloud, the systems supporting that service must either be ENS-compliant or meet a CCN-STIC guide that includes penetration testing audit requirements [op.nub.1.2]. We scope with your Statement of Applicability in front of us.
No. In the ENS, the level is an impact rating: each security dimension (confidentiality, integrity, traceability, authenticity and availability) is rated low, medium or high by the damage an incident would cause, and the highest of those ratings sets the system’s category as Basic, Medium or High (Annex I).
Risk in our report works per finding: how exploitable it is and how far it reaches. We tie every finding to the dimension it touches and the control it fails, so your auditor is not left making that link alone.
It depends on what is in scope, and any timeline we gave you before knowing that would be made up. The framework does have a clock: systems covered by the ENS are reviewed at least every two years, and again whenever the system undergoes substantial change (article 31.1). At Medium and High category that review is an audit; at Basic, a self-assessment is enough (article 38.1).
So the practical move is to start from your audit date and work backwards. The introductory meeting settles what is in scope, and the schedule is fixed in the proposal.
It is an input to the plan, not a replacement for it. The ENS does not use that name: it asks for a security policy (article 12), a risk analysis reviewed and approved every year (Annex III) and a Statement of Applicability signed by your security officer (article 28.2).
The pentest feeds all three. It tests the safeguards you already count as done, and every finding arrives with the Annex II control it fails, so it drops straight into your improvement plan.
The royal decree sets no deadline for fixing the findings. It sets who decides: the security officer analyses the report and takes the conclusions to the system owner, who then adopts the corrective measures (article 31.5). At High category, if the shortcomings are serious, the system owner can suspend the service until they are fixed (article 31.6).
In practice, severity and your next audit set the pace. There is no clock running on our side: the retest is included, at no cost and with no time limit, and it documents the closure.
No. We do not implement the ENS, run your compliance project or issue the certificate of conformity, which is awarded by an accredited certification entity. We perform the penetration testing aligned with your ENS scope so that you have the technical validation and evidence that auditors, public entities and third parties expect to see. We work alongside your ENS consultant, and the two roles fit together cleanly.
Yes. We walk you through it on the call, so you can see the level of detail, the clarity of the reporting and the evidence format, and ask about whatever matters to you. We do not email it out on its own.
Yes. If you sell services or software to the Spanish public sector and the ENS applies, you have to be able to show the right declaration or certificate for your category. The public body can ask for it at any time, so having the evidence ready is increasingly what wins and keeps public contracts.
An ENS pentesting engagement gives you the technical proof your auditor expects. You define the scope, we run the testing, we deliver the evidence. Clear findings, actionable steps, quick remediation confirmation.
Protected by reCAPTCHA. The Google Privacy Policy and Terms of Service apply.
Request received.
We’ll be in touch within one business day with next steps.
No se ha podido enviar. Inténtalo otra vez o escríbenos.
Or email [email protected] directly.
Pick a time that suits you. You tell us what you need and where you are, and we explain how we work and how we can help.