Search Client login
Compliance · ENS

ENS with legal and technical judgement.

Independent consulting in marketing, regulatory compliance (ISO, ENS, GDPR), digitization and B2B sales from Aranda de Duero (Castilla y Leon) covering all of Spain.

Independent consulting in marketing, regulatory compliance (ISO, ENS, GDPR), digitization and B2B sales from Aranda de Duero (Castilla y Leon) covering all of Spain.

National Security Framework (ENS — Esquema Nacional de Seguridad), MAGERIT risk analysis (Spanish public-sector methodology), basic/medium/high categories, CCN-CERT (Spanish National Cryptologic Centre government CSIRT) certification and continuity plans. For organisations working with the Spanish public administration.

Compliance without useless paperwork.

The ENS framework is mandatory for the Spanish public administration and for any organisation that supplies it. The 2022 update brought 73 controls organised across three frameworks (organisational, operational and protective), and three security categories (basic, medium, high) that determine the depth of measures required.

My job: help you understand what actually applies to your case, run the MAGERIT risk analysis with judgement, prioritise controls by real impact, and prepare you for the CCN-cert certification audit without surprises.

Published articles on ENS.

Does your organisation need help with compliance?

Book a free session →

Frequently asked questions

How does this apply to my SME?

It applies as long as you serve Spanish customers or process Spanish data; the framework is mandatory above thresholds we summarise in the table.

What does it cost in 2026?

Indicative ranges for SMEs 10-50 employees: 2,500-12,000 EUR for documentation + auditor fees vary by AENOR / BV / SGS / LRQA.

Which Spanish regulation applies?

BOE references RD 311/2022 (ENS), Regulation EU 2016/679 (GDPR), LOPDGDD, NIS2, DORA and the EU AI Act 2024/1689 depending on scope.

How long does the implementation take?

Average runs 4-7 months for a single ISO. Compound integrated SGI (9001+14001+27001) usually 8-12 months.

Can I co-finance it with Kit Digital or Kit Consulting?

Yes, Kit Consulting 2026 covers up to 24,000 EUR in advisory hours; Kit Digital covers tools (CRM, ERP, ciberseguridad) up to 29,000 EUR.

References: AENOR · BOE · ISO