The answer rarely turns on whether you are a public body. It turns on the service you provide, the system behind it and what the contract says.
That distinction travels. If your group runs a Spanish subsidiary that sells to public administrations, Spain's Esquema Nacional de Seguridad can apply to a system operated from Frankfurt or Dublin, because the obligation follows the service, not the address on the contract.
What the ENS is
The ENS is Spain's mandatory security framework for the public sector, governed by Royal Decree 311/2022. It sets security principles, a categorisation method and a catalogue of measures, and it requires the organisations within its scope of application to demonstrate conformity. Inside that scope it is law, not a voluntary standard, and procurement is how it gets enforced.
One piece of vocabulary is worth fixing now, because the rest of this depends on it. The ENS applies to information systems rather than to companies. What gets categorised, audited and certified is a defined system and the services running on it, which we will call the boundary; the scope statement printed on a certificate is the description of that boundary.
Who is directly obliged
Article 2 of RD 311/2022 applies the ENS to the whole public sector as defined in Law 40/2015: central government, the autonomous communities, local authorities, public bodies and entities governed by public law, and public universities.
If your organisation sits in that group, the open question is how to implement the framework, categorise each system and evidence conformity.
When does a private company need ENS?
This is where the obligation gets overstated in one direction and waved away in the other.
A private company does not fall under the ENS simply because it has sold something to a public body. Article 2.3 sets three conditions that must hold together: there is a contractual relationship with a public sector entity; the company provides a service or supplies a solution; and that service or solution is used by the public entity in the exercise of its administrative powers.
Where all three hold, the systems typically caught are those run by:
- technology suppliers to public bodies and awardees of ICT contracts;
- companies that run the platforms, case-management systems or datasets an administration depends on;
- integrators that deploy or maintain systems used by public entities;
- cloud, SaaS and managed service providers supporting systems inside the boundary;
- subcontractors, where the risk analysis shows that the same requirements have to follow the work down the supply chain.
The contract and the tender documents decide it
RD 311/2022 requires the administrative and technical conditions in public tender documents to include what is needed to ensure ENS conformity of the systems underpinning a contractor's services. Those requirements may extend to producing declarations or certifications of conformity.
So companies usually discover their position when three things coincide: a service that falls inside the framework, a system that supports administrative powers, and a tender that demands conformity or evidence. The first two decide whether the ENS applies; the third is simply how most firms find out.
How this lands for a multinational with a Spanish subsidiary
This is the case that generates the most awkward conversations inside international groups, because responsibility and infrastructure sit in different countries.
If a Spanish entity in your group contracts with a public administration, and the platform serving that contract runs on a shared group system abroad, that system can still fall inside the boundary. The decision that follows is architectural before it is legal: do you draw the boundary tightly around the Spanish service, or around the shared platform that also serves a dozen other markets?
A boundary drawn tightly around the Spanish service is usually cheaper and faster to certify, but it only works if the architecture allows that separation. Taking in the shared platform costs more and takes longer, though it can pay off if the public sector is a growth market for the group. Either way, the decision is best taken before a bid deadline forces it, and it belongs with whoever owns the platform, not only with the Spanish country manager.
Who should not assume they are inside the boundary
Overreacting has its own price tag. Situations worth testing before you concede the point include goods supplied that never touch the system inside the boundary, ancillary services with no real bearing on the information system, commercial relationships that do not support the exercise of administrative powers, and engagements where neither the contract nor the risk analysis triggers ENS requirements.
The honest answer in these cases is a review, not a verdict: contract, system, service, and the link between that system and the administrative powers it supports.
Signals that you probably are inside the boundary
- You work with, or want to work with, a Spanish public administration.
- The tender documents mention ENS, conformity, declaration or certification.
- Your system processes information or delivers a service for a public entity.
- You are an ICT supplier, integrator, SaaS or managed service provider to the public sector.
- A public client is asking you for security evidence, categorisation or a remediation plan.
- You sit in a supply chain where the main contractor has to demonstrate conformity.
Is ISO 27001 the same as ENS?
No, and treating them as interchangeable is the most expensive assumption in this area. ISO 27001 gives you governance structure, risk management, controls, evidence and continuous improvement, and much of that work carries across. But the ENS has its own scope of application, principles, categorisation method and measures, and conformity is assessed against those.
The same applies to NIS2. There are real synergies and shared evidence, but the frameworks are not equivalent. If you are mapping several regimes at once, our comparison of ENS, ISO 27001, NIS2 and DORA sets out where the overlaps are, and our piece on compliance tooling covers how to stop maintaining the same evidence separately for each framework.
| Framework | Who it binds | What triggers it |
|---|---|---|
| ENS (RD 311/2022) | Spanish public sector, plus private entities whose systems serve it under contract | The contract and the system supporting administrative powers |
| ISO 27001 | Any organisation, voluntarily | A commercial or client decision to certify |
| NIS2 | Essential and important entities in listed sectors | Sector, size and criticality thresholds |
Evidence can be shared across the three. Conformity cannot: each is assessed on its own terms.
What to do if you think ENS may apply
- Read the contract and the tender documents, looking for ENS, conformity, declaration, certification, categorisation or security requirements.
- Draw the boundary of the system. Not all of your business is necessarily inside it; identify the system, service, data, assets and third parties involved.
- Confirm how the service and the system fit the legal test, in particular whether the service supports the exercise of administrative powers.
- Run a realistic gap analysis before anyone mentions audit or certification.
- Build the remediation plan with owners, measures, dependencies, evidence and a defensible timeline.
Why this is worth settling early
The costly version of this question is the one answered during a live tender, when the deadline is fixed and the gap analysis has not started. The cheap version is answered months earlier, while the boundary can still be shaped and the work sequenced sensibly.
Hard2bit holds ENS High certification under RD 311/2022, awarded with no non-conformities raised, and is certified against five ISO standards. We mention it because it changes what we can tell you: we have argued our own categorisation and boundary before an auditor, not only advised others on theirs. That experience sits behind our ENS compliance service and our ENS audit readiness work, and it is why clients hand us the technical delivery and the compliance work together instead of splitting them between two suppliers.
This article summarises the framework established by Royal Decree 311/2022 and is provided for information only. Applicability depends on the specific contract, system and risk analysis, and should be confirmed with qualified legal advice before decisions are taken.