← Back to the cybersecurity blog

Not all ENS certificates are equal: why scope and the audit result decide the value

By Adrián González · CEO · Published: 09 August 2026 · Updated: 09 August 2026
Alcance Certificado ENS Hard2bit

Seeing that a supplier is certified under the Esquema Nacional de Seguridad tends to end the security conversation. It should start one: two certificates carrying the same name can cover wildly different things.

The useful questions are narrower. Is the certification current and verifiable, what boundary does it cover, which services fall inside that boundary, and did the audit close with non-conformities?

Three very different suppliers, one identical claim

Three kinds of supplier look identical on a slide: those with no certification they can evidence; those who hold one for a narrow, single-service boundary; and those whose certification covers a broad, cross-functional part of their delivery capability.

That changes the picture. A supplier with no certificate it can evidence is not comparable to one that holds a valid certificate, and a certificate covering one contained environment is not comparable to one covering a supplier's governance, operations and delivery capability end to end.

Why the boundary is the field that decides the answer

A certificate is issued for a defined boundary: specific information systems, processes and services. From a buyer's perspective, that field tells you which capabilities were actually audited.

The broader and more cross-functional the boundary, the greater the underlying complexity: more processes involved, more teams coordinated, more traceability required, more documentation to keep consistent and more operational evidence to produce. Sustaining that is harder, which is why breadth of boundary tells you more.

That is a buyer's reading, not a supplier's. A narrow boundary is the right engineering answer for a single contract, and a broad one is what tells you a supplier can sustain the framework across its business. The mistake is comparing the two as if they measured the same thing.

Five questions to put to any ENS certificate
QuestionWhy it separates suppliers
Is the certification current and verifiable?Distinguishes a certificate from a reputational claim
Which category was awarded: Basic, Medium or High?Shows how demanding the requirements were that the system had to meet
What exactly does the boundary cover?Shows which capabilities were audited, not which are marketed
Do the certified services match what I am buying?A certificate covering another service tells you little about mine
Did the audit close with non-conformities?Shows whether the documented model matched real operation on the day of the audit

A supplier who cannot answer these promptly and specifically has given you an answer of a different kind.

What a clean audit result signals

Beyond the boundary, the audit outcome changes how a certificate should be read. Closing without non-conformities points to alignment between governance and operation, and between the controls as documented and the evidence the operation actually produces day to day.

It is worth being precise about the limits of that claim. A clean result applies within the certified boundary, on the date of the audit. It is a strong signal, not a warranty covering everything a supplier does, which is another reason to read boundary and result together.

For a buyer it usually means a shorter due-diligence cycle and fewer open questions at onboarding, rather than a guarantee about any particular engagement.

How this fits a supplier assessment

For an organisation running third-party risk management, ENS is one input among several. It works best read alongside the rest of the evidence: which services the certificate covers, what the supplier can show about its own operations, and how quickly it answers questions it has not rehearsed.

The same logic runs through the wider purchasing decision. Our guide on how to buy cybersecurity covers the questions to put to a provider or MSSP, and our comparison of cybersecurity companies in Spain explains why technical delivery and GRC capability are best assessed together.

Our own certificate, stated plainly

Hard2bit is certified at ENS High under RD 311/2022, with no non-conformities raised. The boundary spans governance, compliance and audit, business continuity, managed services, continuous monitoring, cloud security, vulnerability management, ethical hacking, forensic analysis, application development and maintenance, research and development, artificial intelligence, and infrastructure operation and support. We are also certified against five ISO standards and have been operating since 2013.

We set that out in this much detail for the same reason we suggest interrogating anyone else's certificate: a claim is only useful when the boundary behind it is visible. Put the five questions above to us, and put them to whoever else is bidding. That is the comparison we would rather compete on, and it is the standard our ENS service and compliance consulting are built to meet as a cybersecurity company in Spain.

What to take from this

ENS is a meaningful signal and a poor shortcut. It confirms that a defined system was assessed against a demanding public sector framework, and says nothing about whatever sat outside that boundary.

So the comparison worth putting in front of a buying committee is not certified versus not certified. It is whether the certification is current, covers the services being contracted, and rests on an audit result that suggests the model works as documented.

This article refers to certification under Royal Decree 311/2022 and describes Hard2bit's certification status as at the date of publication. Statements about the scope and result of third-party certifications should be verified directly with each supplier and its certification body.

Frequently asked questions

Are all ENS certificates equivalent?

No. Each one is awarded at a category, Basic, Medium or High, and issued for a defined set of systems, processes and services. Because those two variables move independently, one certificate can represent a contained environment assessed at the lowest category and another a substantial part of a supplier's operation assessed at the highest, with nothing on the logo to tell them apart.

What does the boundary of an ENS certificate mean?

It is the statement on the certificate defining exactly which systems, processes and services were audited. A narrow boundary is not a flaw in itself, but it only tells you about what sits inside it: anything outside was not assessed and should not be assumed to meet the same standard. Read the boundary and the certificate together rather than treating the badge as blanket assurance.

What does ENS High with no non-conformities mean?

High is the most demanding of the three categories, applied where the impact of an incident would be most severe. Closing an audit with no non-conformities raised means the auditor found no gaps between the requirements for that category and how the organisation actually operates, within the certified boundary and on the audit date. Both of those bounds matter when you interpret the claim.

Does an ENS certificate replace a security questionnaire in due diligence?

It shortens one without replacing it. A certificate with a broad, relevant boundary and a clean result removes much of the doubt about governance and control maturity, which cuts the number of questions you need to ask. What it cannot answer is anything specific to your contract: the architecture serving you, the people involved and the third parties behind them still warrant assessment.

What if a supplier's audit raised non-conformities?

It is not automatically disqualifying, and treating it that way encourages suppliers to say as little as possible. Findings are classified by severity and normally come with a corrective action plan and deadlines, so the informative questions are how serious they were, what has been done since, and whether closure has been verified. A supplier who explains that openly is often a safer bet than one whose certificate you cannot examine at all.

How do I verify that a supplier's certificate is genuine and current?

Ask for the certificate itself rather than a badge, and check four things on it: the issuing body and its accreditation, the validity dates, the category awarded and the exact boundary statement. If a supplier will only point at an image on a website, or the document turns out to have lapsed, that reluctance deserves more attention than the badge did.

What should I ask for if a supplier shows me a declaration instead of a certificate?

Start by checking what it implies. A declaration of conformity rests on the supplier's own self-assessment and is only available for systems in the Basic category, whereas Medium and High require an audit by a certification body accredited by ENAC. So a declaration tells you two things at once: no independent auditor examined the system, and the system was categorised as Basic. Ask what boundary it covers, what evidence supports it and when it was last reviewed, since both routes call for renewal at least every two years. If your contract requires certification, a declaration will not satisfy it however well documented.

Not sure which EU rules reach you — or what meeting them costs?

NIS2 and DORA reach further than most companies expect, usually through a contract with a customer already in scope. We work out what genuinely applies to you in a 30-minute call with a technical consultant, not a salesperson, and you leave with priorities ranked and a price range. With what comes out of that call, we turn it into a fixed proposal. ISO 27001, NIS2, DORA and ENS — Spain's framework for suppliers to the public sector.

If your situation is different, tell us anyway — we also take one-off questions on cybersecurity and regulatory compliance.

Based in Spain · Working across the EU and LATAM · ENS High · ISO 27001 · We usually reply in under 24 business hours