Seeing that a supplier is certified under the Esquema Nacional de Seguridad tends to end the security conversation. It should start one: two certificates carrying the same name can cover wildly different things.
The useful questions are narrower. Is the certification current and verifiable, what boundary does it cover, which services fall inside that boundary, and did the audit close with non-conformities?
Three very different suppliers, one identical claim
Three kinds of supplier look identical on a slide: those with no certification they can evidence; those who hold one for a narrow, single-service boundary; and those whose certification covers a broad, cross-functional part of their delivery capability.
That changes the picture. A supplier with no certificate it can evidence is not comparable to one that holds a valid certificate, and a certificate covering one contained environment is not comparable to one covering a supplier's governance, operations and delivery capability end to end.
Why the boundary is the field that decides the answer
A certificate is issued for a defined boundary: specific information systems, processes and services. From a buyer's perspective, that field tells you which capabilities were actually audited.
The broader and more cross-functional the boundary, the greater the underlying complexity: more processes involved, more teams coordinated, more traceability required, more documentation to keep consistent and more operational evidence to produce. Sustaining that is harder, which is why breadth of boundary tells you more.
That is a buyer's reading, not a supplier's. A narrow boundary is the right engineering answer for a single contract, and a broad one is what tells you a supplier can sustain the framework across its business. The mistake is comparing the two as if they measured the same thing.
| Question | Why it separates suppliers |
|---|---|
| Is the certification current and verifiable? | Distinguishes a certificate from a reputational claim |
| Which category was awarded: Basic, Medium or High? | Shows how demanding the requirements were that the system had to meet |
| What exactly does the boundary cover? | Shows which capabilities were audited, not which are marketed |
| Do the certified services match what I am buying? | A certificate covering another service tells you little about mine |
| Did the audit close with non-conformities? | Shows whether the documented model matched real operation on the day of the audit |
A supplier who cannot answer these promptly and specifically has given you an answer of a different kind.
What a clean audit result signals
Beyond the boundary, the audit outcome changes how a certificate should be read. Closing without non-conformities points to alignment between governance and operation, and between the controls as documented and the evidence the operation actually produces day to day.
It is worth being precise about the limits of that claim. A clean result applies within the certified boundary, on the date of the audit. It is a strong signal, not a warranty covering everything a supplier does, which is another reason to read boundary and result together.
For a buyer it usually means a shorter due-diligence cycle and fewer open questions at onboarding, rather than a guarantee about any particular engagement.
How this fits a supplier assessment
For an organisation running third-party risk management, ENS is one input among several. It works best read alongside the rest of the evidence: which services the certificate covers, what the supplier can show about its own operations, and how quickly it answers questions it has not rehearsed.
The same logic runs through the wider purchasing decision. Our guide on how to buy cybersecurity covers the questions to put to a provider or MSSP, and our comparison of cybersecurity companies in Spain explains why technical delivery and GRC capability are best assessed together.
Our own certificate, stated plainly
Hard2bit is certified at ENS High under RD 311/2022, with no non-conformities raised. The boundary spans governance, compliance and audit, business continuity, managed services, continuous monitoring, cloud security, vulnerability management, ethical hacking, forensic analysis, application development and maintenance, research and development, artificial intelligence, and infrastructure operation and support. We are also certified against five ISO standards and have been operating since 2013.
We set that out in this much detail for the same reason we suggest interrogating anyone else's certificate: a claim is only useful when the boundary behind it is visible. Put the five questions above to us, and put them to whoever else is bidding. That is the comparison we would rather compete on, and it is the standard our ENS service and compliance consulting are built to meet as a cybersecurity company in Spain.
What to take from this
ENS is a meaningful signal and a poor shortcut. It confirms that a defined system was assessed against a demanding public sector framework, and says nothing about whatever sat outside that boundary.
So the comparison worth putting in front of a buying committee is not certified versus not certified. It is whether the certification is current, covers the services being contracted, and rests on an audit result that suggests the model works as documented.
This article refers to certification under Royal Decree 311/2022 and describes Hard2bit's certification status as at the date of publication. Statements about the scope and result of third-party certifications should be verified directly with each supplier and its certification body.