What ENS is and why it exists
The National Security Scheme (ENS), regulated by Royal Decree 311/2022, is the regulatory framework that establishes the security measures that public sector entities and their service providers must apply. Its objective is to guarantee the access, integrity, availability, authenticity, confidentiality, and traceability of electronic data and services.
It applies to all Public Administrations and their providers when processing public sector information. If your SME works with a public client or subcontracts for one, ENS may apply to you.
When it applies to your SME
ENS applies when:
- You are a technology provider to a public administration and process data or provide services on its behalf.
- You are a data processor for an obligated entity.
- You participate in public sector contracts that include ENS compliance clauses.
Public procurement specifications usually require Basic, Medium or High category depending on data criticality. The category is determined by the risk analysis: level of confidentiality, integrity, availability, and required traceability.
Annex II measures you can implement today
Annex II of RD 311/2022 groups measures into three blocks. For an SME, the most immediate actions — which you can start documenting today with a professional audit that identifies your gaps — are:
Organisational framework
- Security policy: a 2-3 page document approved by management that defines who is responsible for security.
- Operating procedures: change management, backups, incident management, activity logging.
- Authorisation and access control: each employee accesses only what they need for their work.
Operational framework
- Asset inventory: what systems you have, where they are, what software runs on them.
- Backups: regular, encrypted, verified, and stored outside the main network.
- Incident management: who does what when a problem is detected. Document at least one recent case and how it was resolved.
- Antimalware protection and updates: on all devices and servers.
Protection measures
- Encryption: data in transit (HTTPS) and data at rest for sensitive information.
- Network segmentation: separating critical equipment from the rest (guest network, office network, server network).
- Strong authentication (MFA): especially for cloud system access and the administration panel.
How to prepare for certification audit
- Initial risk analysis: identify what assets you have, what threats are realistic, and what the impact would be if they were compromised.
- Applicable category: determine whether your system will be Basic, Medium, or High. This defines which measures you must comply with.
- Gradual implementation: start with organisational framework measures (policies, procedures) and move towards technical measures.
- Pre-audit: before the official audit with an ENAC-accredited certifier, do an internal audit or with an external team that identifies the gaps.
- Certification with an accredited body: the certification audit must be conducted by an ENAC-accredited organisation. NullStrata is not a certification body, but we will prepare you to arrive at that audit with confidence.
For Basic category, conformity can be a self-assessment conformity declaration signed by the responsible person. For Medium and High, a formal audit with certification is required.