← Back to the cybersecurity blog

Who needs ENS: Spanish public bodies, their suppliers and the companies caught in scope

By Adrián González · CEO · Published: 09 August 2026 · Updated: 09 August 2026
Qué organizaciones deben cumplir el ENS

The answer rarely turns on whether you are a public body. It turns on the service you provide, the system behind it and what the contract says.

That distinction travels. If your group runs a Spanish subsidiary that sells to public administrations, Spain's Esquema Nacional de Seguridad can apply to a system operated from Frankfurt or Dublin, because the obligation follows the service, not the address on the contract.

What the ENS is

The ENS is Spain's mandatory security framework for the public sector, governed by Royal Decree 311/2022. It sets security principles, a categorisation method and a catalogue of measures, and it requires the organisations within its scope of application to demonstrate conformity. Inside that scope it is law, not a voluntary standard, and procurement is how it gets enforced.

One piece of vocabulary is worth fixing now, because the rest of this depends on it. The ENS applies to information systems rather than to companies. What gets categorised, audited and certified is a defined system and the services running on it, which we will call the boundary; the scope statement printed on a certificate is the description of that boundary.

Who is directly obliged

Article 2 of RD 311/2022 applies the ENS to the whole public sector as defined in Law 40/2015: central government, the autonomous communities, local authorities, public bodies and entities governed by public law, and public universities.

If your organisation sits in that group, the open question is how to implement the framework, categorise each system and evidence conformity.

When does a private company need ENS?

This is where the obligation gets overstated in one direction and waved away in the other.

A private company does not fall under the ENS simply because it has sold something to a public body. Article 2.3 sets three conditions that must hold together: there is a contractual relationship with a public sector entity; the company provides a service or supplies a solution; and that service or solution is used by the public entity in the exercise of its administrative powers.

Where all three hold, the systems typically caught are those run by:

  • technology suppliers to public bodies and awardees of ICT contracts;
  • companies that run the platforms, case-management systems or datasets an administration depends on;
  • integrators that deploy or maintain systems used by public entities;
  • cloud, SaaS and managed service providers supporting systems inside the boundary;
  • subcontractors, where the risk analysis shows that the same requirements have to follow the work down the supply chain.

The contract and the tender documents decide it

RD 311/2022 requires the administrative and technical conditions in public tender documents to include what is needed to ensure ENS conformity of the systems underpinning a contractor's services. Those requirements may extend to producing declarations or certifications of conformity.

So companies usually discover their position when three things coincide: a service that falls inside the framework, a system that supports administrative powers, and a tender that demands conformity or evidence. The first two decide whether the ENS applies; the third is simply how most firms find out.

How this lands for a multinational with a Spanish subsidiary

This is the case that generates the most awkward conversations inside international groups, because responsibility and infrastructure sit in different countries.

If a Spanish entity in your group contracts with a public administration, and the platform serving that contract runs on a shared group system abroad, that system can still fall inside the boundary. The decision that follows is architectural before it is legal: do you draw the boundary tightly around the Spanish service, or around the shared platform that also serves a dozen other markets?

A boundary drawn tightly around the Spanish service is usually cheaper and faster to certify, but it only works if the architecture allows that separation. Taking in the shared platform costs more and takes longer, though it can pay off if the public sector is a growth market for the group. Either way, the decision is best taken before a bid deadline forces it, and it belongs with whoever owns the platform, not only with the Spanish country manager.

Who should not assume they are inside the boundary

Overreacting has its own price tag. Situations worth testing before you concede the point include goods supplied that never touch the system inside the boundary, ancillary services with no real bearing on the information system, commercial relationships that do not support the exercise of administrative powers, and engagements where neither the contract nor the risk analysis triggers ENS requirements.

The honest answer in these cases is a review, not a verdict: contract, system, service, and the link between that system and the administrative powers it supports.

Signals that you probably are inside the boundary

  • You work with, or want to work with, a Spanish public administration.
  • The tender documents mention ENS, conformity, declaration or certification.
  • Your system processes information or delivers a service for a public entity.
  • You are an ICT supplier, integrator, SaaS or managed service provider to the public sector.
  • A public client is asking you for security evidence, categorisation or a remediation plan.
  • You sit in a supply chain where the main contractor has to demonstrate conformity.

Is ISO 27001 the same as ENS?

No, and treating them as interchangeable is the most expensive assumption in this area. ISO 27001 gives you governance structure, risk management, controls, evidence and continuous improvement, and much of that work carries across. But the ENS has its own scope of application, principles, categorisation method and measures, and conformity is assessed against those.

The same applies to NIS2. There are real synergies and shared evidence, but the frameworks are not equivalent. If you are mapping several regimes at once, our comparison of ENS, ISO 27001, NIS2 and DORA sets out where the overlaps are, and our piece on compliance tooling covers how to stop maintaining the same evidence separately for each framework.

Three frameworks, three different questions
FrameworkWho it bindsWhat triggers it
ENS (RD 311/2022)Spanish public sector, plus private entities whose systems serve it under contractThe contract and the system supporting administrative powers
ISO 27001Any organisation, voluntarilyA commercial or client decision to certify
NIS2Essential and important entities in listed sectorsSector, size and criticality thresholds

Evidence can be shared across the three. Conformity cannot: each is assessed on its own terms.

What to do if you think ENS may apply

  1. Read the contract and the tender documents, looking for ENS, conformity, declaration, certification, categorisation or security requirements.
  2. Draw the boundary of the system. Not all of your business is necessarily inside it; identify the system, service, data, assets and third parties involved.
  3. Confirm how the service and the system fit the legal test, in particular whether the service supports the exercise of administrative powers.
  4. Run a realistic gap analysis before anyone mentions audit or certification.
  5. Build the remediation plan with owners, measures, dependencies, evidence and a defensible timeline.

Why this is worth settling early

The costly version of this question is the one answered during a live tender, when the deadline is fixed and the gap analysis has not started. The cheap version is answered months earlier, while the boundary can still be shaped and the work sequenced sensibly.

Hard2bit holds ENS High certification under RD 311/2022, awarded with no non-conformities raised, and is certified against five ISO standards. We mention it because it changes what we can tell you: we have argued our own categorisation and boundary before an auditor, not only advised others on theirs. That experience sits behind our ENS compliance service and our ENS audit readiness work, and it is why clients hand us the technical delivery and the compliance work together instead of splitting them between two suppliers.

This article summarises the framework established by Royal Decree 311/2022 and is provided for information only. Applicability depends on the specific contract, system and risk analysis, and should be confirmed with qualified legal advice before decisions are taken.

Frequently asked questions

Who is legally obliged to comply with the ENS?

The ENS applies directly to the whole Spanish public sector as defined in Law 40/2015, and also to information systems of private entities where, under a contractual relationship, they provide services or supply solutions to public sector entities for the exercise of their administrative powers. Those three elements must hold together; a public client on its own is not enough.

How much notice do you get before conformity is required?

Usually very little, because the requirement surfaces in the tender documents and the deadline belongs to the procurement calendar rather than your roadmap. Some tenders ask for evidence with the bid, others allow conformity to be reached during the contract, and the two scenarios call for completely different plans. Reading the administrative and technical conditions the week a tender opens, rather than the week before it closes, is what keeps the second option available.

Does the ENS reach subcontractors?

It can. The decree provides for the same requirements to follow the work down the main contractor's supply chain where the risk analysis makes it necessary. In practice a subcontractor operating part of the system may have to demonstrate conformity, and it is the main contractor who has to evidence that end to end. If you subcontract hosting, support or development on a public sector contract, that dependency belongs in your own risk analysis.

Which ISO 27001 evidence can I reuse for an ENS project?

The governance layer travels well: risk methodology and treatment records, asset inventory, supplier management, access control policy, incident procedure, internal audit and management review. What rarely travels untouched is anything the ENS specifies its own way, particularly the categorisation of the system by security dimension and the measures tied to the resulting category. Expect to reuse most of the management system and to rebuild the categorisation and the mapping of measures from scratch.

Which entity in an international group holds the ENS conformity?

The conformity attaches to the information system supporting the contracted service, and in practice it is the entity that signs the public contract, normally the Spanish subsidiary, that has to demonstrate it. That gets awkward when the platform is owned and operated by the parent or by a shared services centre abroad, because the entity holding the obligation does not control the system. The workable arrangements make the operating entity's responsibilities explicit in an intra-group agreement, so the Spanish entity can evidence control it does not directly exercise.

What is a declaration of conformity, and when is it enough?

It is only enough for systems in the Basic category. There, the organisation can declare conformity itself on the basis of a self-assessment, reviewed at least every two years. Systems categorised as Medium or High cannot use that route: they require certification of conformity, based on an audit carried out by a certification body accredited by ENAC, and likewise repeated at least every two years. Since the tender sets the requirement contract by contract, confirm which of the two is being asked for before scoping any project around it.

How do I know whether my company is inside the ENS boundary?

Review four things in order: the contract and tender documents, the specific system involved, the type of service provided, and the relationship between that system and the administrative powers it supports. Only then does it make sense to look at categorisation and controls. Starting from the control catalogue before the boundary is settled is one of the reliable ways to inflate these projects.

Not sure which EU rules reach you — or what meeting them costs?

NIS2 and DORA reach further than most companies expect, usually through a contract with a customer already in scope. We work out what genuinely applies to you in a 30-minute call with a technical consultant, not a salesperson, and you leave with priorities ranked and a price range. With what comes out of that call, we turn it into a fixed proposal. ISO 27001, NIS2, DORA and ENS — Spain's framework for suppliers to the public sector.

If your situation is different, tell us anyway — we also take one-off questions on cybersecurity and regulatory compliance.

Based in Spain · Working across the EU and LATAM · ENS High · ISO 27001 · We usually reply in under 24 business hours