← Back to the cybersecurity blog

ENS for SaaS: when you need the Medium category and how to certify without inflating it

By Thilina Manana · COO y Director Técnico de Seguridad hard2bit · Published: 09 August 2026 · Updated: 09 August 2026
Certificación ENS para SaaS

The ENS usually reaches a SaaS provider as a clause in a tender, with a deadline attached and no room left to renegotiate what it covers.

By then the hard questions have nothing to do with controls. They are about boundary and category, and getting either wrong will price you out of the contract or leave you unable to bid at all.

When does the ENS reach a SaaS platform?

The framework is not limited to public bodies. Under Article 2.3 of RD 311/2022 it also applies to information systems of private entities where three conditions hold together: there is a contractual relationship with a public sector entity, the company provides a service or supplies a solution, and that service is used by the entity in the exercise of its administrative powers.

For a SaaS platform, that usually looks like this: the platform forms part of a service delivered to a public administration, and it processes data relating to citizens, case files or administrative activity. The tender behind the contract then requires ENS conformity of the system supporting that service, which is how most providers find out where they stand.

One point deserves stressing: the whole company does not need to sit inside the boundary. The usual approach is to define a specific information system tied to the contracted service and apply the framework's measures to that.

Why do most SaaS systems land on the Medium category?

The ENS categorises systems as Basic, Medium or High, based on the impact an incident would have across the framework's security dimensions: confidentiality, integrity, availability, authenticity and traceability. A system is Medium when at least one dimension reaches that level and none reaches High.

For SaaS used by an administration, at least one usually does: the data would cause real harm if exposed, the integrity of administrative processes depends on the platform, or service availability has to be guaranteed. Hence the pattern of platforms landing on Medium even when the data itself is unremarkable, because more often than not it is availability or the integrity of the administrative process, not confidentiality, that sets the category.

The boundary decision sets the cost

A common and expensive error is trying to certify the entire organisation, or the whole platform, without separating out the part actually involved in the contracted service.

A disciplined approach identifies the specific service covered by the contract, determines which technical components deliver it, draws the boundary around those components, and explicitly excludes modules, environments and features that play no part. In cloud architectures this analysis has to account for how tenancy, shared services and platform components are separated, which is where cloud security design and certification scoping meet.

Categorising without inflating the category

Categorisation should rest on the real impact of an incident on that system, not on precautionary guesswork. The analysis looks at the nature of the information processed, the type of service delivered, and the consequences of a loss in each security dimension.

Where a system handles several types of information, each dimension takes the highest impact identified for it, and the system's category follows the most demanding of those dimensions. One sensitive dataset can therefore pull the whole platform up a category. Where the architecture allows, separating it into its own boundary keeps the wider system lower, which is why segmentation comes before categorisation.

What tightens as the category rises
AreaBasicMedium and above
Access control and identityBaseline authentication and role separationStronger identity governance, privileged access control and review cycles
Logging and monitoringBasic activity recordsSystematic recording, retention and monitoring of activity
Incident managementA defined handling procedureFormal process, classification, notification and lessons learned
Systems and communicationsStandard protectionReinforced segmentation, cryptographic protection and hardening
ContinuityBackupsTested continuity planning proportionate to the service

The step between categories is qualitative as well as quantitative: it changes what you must evidence, not only how much.

What an ENS project actually looks like

  1. Initial analysis: review the contractual requirements and confirm whether the obligation applies.
  2. Boundary definition: delimit the information system that will be certified.
  3. Categorisation: assess impact by dimension and determine the system's ENS category.
  4. Gap analysis: compare the measures required for that category against what the platform already does.
  5. Remediation: implement the technical and organisational measures still missing.
  6. Evidence: document and record the controls as they run.
  7. Audit: independent verification of conformity.
  8. Certification: obtain the corresponding report or certificate.

Where the platform sits alongside Microsoft 365 or similar collaborative environments, the remediation phase usually pulls in platform-specific controls as well, which our Microsoft 365 security audit checklist covers.

Four mistakes that cost SaaS teams the most

Assuming ISO 27001 is enough. The two overlap in governance and evidence, and an ISO 27001 implementation gives you a great deal of reusable structure, but the ENS has its own categorisation method and its own measures, assessed on their own terms.

Assuming the cloud provider covers it. Azure and AWS hold extensive certifications, but conformity is assessed on your specific system and the way you have configured, operated and evidenced it. Their attestations feed your evidence pack; they do not replace it.

Over-scoping. Including systems, environments or processes that play no part in the contracted service complicates the audit and inflates the cost, often for no commercial gain.

Leaving evidence until the end. Controls that work but produce no record are indistinguishable, at audit, from controls that do not work.

Getting the first decision right

If you are selling to Spanish public bodies, or intend to, the sequence matters: boundary and category first, controls second. Everything downstream inherits those two decisions, including the price of the audit.

Our own ENS High certificate, awarded under RD 311/2022, closed without a single non-conformity, for a broad and cross-functional boundary. It matters here for a narrow reason: advising on boundary and categorisation is easier when you have made those calls yourself, defended them at audit and lived with the result. That experience sits behind our ENS service and our ENS audit readiness work, and as a cybersecurity and compliance company we run security engineering and compliance out of the same team rather than two separate ones.

This article describes the framework established by Royal Decree 311/2022 and is provided for information only. Boundary, categorisation and certification requirements depend on each contract and system, and should be confirmed with qualified advice.

Frequently asked questions

Does a SaaS platform always need the ENS Medium category?

No. The category depends on the impact an incident would have on that specific system across the framework's security dimensions. Services delivered to Spanish public bodies do frequently land on Medium, but the reason is worth knowing: it is usually availability or the integrity of an administrative process that pushes it there, not the sensitivity of the data, which is why platforms handling unremarkable information still end up in that category.

What does an ENS project cost, and what drives the number?

There is no list price, because the work is driven by the gap rather than by the framework. Four things move the number more than anything else: the category, since Medium and High demand substantially more evidence than Basic; the size of the boundary, which is the variable you control; the maturity of what already exists, where an ISO 27001 management system cuts a large slice of the effort; and the audit itself, which is a separate cost paid to the certification body. Budgeting for remediation before the boundary is settled tends to produce a number that bears no relation to the final one.

How long does ENS certification take for a SaaS platform?

In the projects we see it runs from roughly three to nine months, though where a project lands in that range depends on three variables: how cleanly the boundary can be drawn, whether evidence is already generated as systems run, and whether a management system such as ISO 27001 is in place to build on. A platform starting from nothing with an unclear boundary sits at the far end.

Does my whole platform have to be certified?

No, and attempting it is the quickest route to an oversized project. You define an information system tied to the contracted service, covering only the components that deliver it, and exclude the rest explicitly. A narrow, well-argued boundary is easier to defend at audit than a broad, vague one, and it costs considerably less to maintain year on year.

Can I certify a single tenant rather than the whole platform?

Sometimes, and it depends entirely on how the architecture separates tenants. Where a dedicated tenant or environment can be isolated with its own controls, access paths and monitoring, a boundary drawn around it can be defended. Where tenants share components, identity or administration paths, those shared elements are pulled inside the boundary regardless, which often makes the narrower option illusory. Model this before promising anything in a bid.

Who verifies ENS conformity, and what do they test?

For Medium and High systems, which is where most SaaS platforms land, conformity requires an audit by a certification body accredited by ENAC, producing a certificate for the defined boundary and category. Only Basic systems can rely on a declaration of conformity based on self-assessment. The auditor assesses the system as it actually runs against the measures for its category, so documented processes that do not match production behaviour surface quickly. Preparation is better spent on that alignment than on documentation volume.

What happens after certification?

It is not a one-off event. Conformity has to be maintained and re-examined at least every two years, whether through a renewal audit for Medium and High systems or a fresh self-assessment for Basic ones. The real risk for a SaaS business in between is drift: platforms change constantly, and a boundary defined two years ago may no longer match the architecture. Treating the boundary as a live artefact, reviewed whenever the architecture or the contracted service changes, avoids unpleasant surprises at renewal.

Not sure which EU rules reach you — or what meeting them costs?

NIS2 and DORA reach further than most companies expect, usually through a contract with a customer already in scope. We work out what genuinely applies to you in a 30-minute call with a technical consultant, not a salesperson, and you leave with priorities ranked and a price range. With what comes out of that call, we turn it into a fixed proposal. ISO 27001, NIS2, DORA and ENS — Spain's framework for suppliers to the public sector.

If your situation is different, tell us anyway — we also take one-off questions on cybersecurity and regulatory compliance.

Based in Spain · Working across the EU and LATAM · ENS High · ISO 27001 · We usually reply in under 24 business hours