The certification process under the National Security Scheme (ENS) consists of assessing whether an information system complies with the basic principles, minimum requirements, and security measures established in the Royal Decree 311/2022, dated May 3, taking into account its category and the scope defined by the organization
Certification is performed by ACERTA to verify that the information system complies with the security requirements set forth in the Royal Decree 311/2022, dated May 3, in accordance with its category and defined scope. The ENS provides a framework for protecting information and services against risks and threats, ensuring aspects such as confidentiality, integrity, availability, authenticity, and traceability.
The process is divided into four phases: review of the application and scope, documentary and technical evaluation of the system, preparation and review of the report, and final decision-making. This approach allows for verify the system’s security level, identify potential nonconformities and opportunities for improvement , and, where appropriate, issue a certificate of conformity attesting to compliance with the ENS.
The implementation of the ENS also helps strengthen the organization's risk management and resilience, facilitating alignment with other security frameworks and regulatory requirements, such as the NIS2 Directive or the ISO/IEC 27001, without replacing the specific assessments required by each of them.
The ENS (Royal Decree 311/2022) applies to public sector entities and the information systems they use to exercise their powers and provide their services. It also applies to private sector entities that, through a contractual relationship, provide services or solutions to public agencies when their systems fall within the applicable scope. The ENS is updated and promoted by the National Cryptology Center (CCN)
Information systems classified as MEDIUM or HIGH must obtain a certificate of conformity issued by a certification body accredited by ENAC in accordance with the UNE-EN ISO/IEC 17065 standard and the requirements established for the ENS. For systems in the BASIC, conformity may be demonstrated through a declaration of conformity, although certification may be sought on a voluntary basis.
The process includes reviewing the application and scope, planning the audit, conducting a documentary and technical evaluation of the system, preparing the report, resolving any nonconformities identified, and reviewing the findings and making a decision. When the outcome is favorable, a certificate of compliance with the ENS is issued.
The organization must analyze the causes, define the necessary corrective actions, and provide evidence of their implementation within the established timeframe. The documentation provided will be reviewed, and, when necessary, additional checks will be conducted to verify that the issues have been properly resolved. The certificate may only be issued once the nonconformities preventing certification have been satisfactorily resolved.
The certificate is valid for a maximum of two years, provided that the conditions under which it was granted remain in effect. To renew it, a new audit must be conducted before it expires. Furthermore, any significant changes to the system, scope, services, infrastructure, or security conditions must be reported to the certification body, which will determine whether an extraordinary assessment is necessary.
Our team can analyze your case and guide you through the requirements, necessary documentation, and steps to begin the process with ACERTA. Contact us for a free consultation, and we'll respond within 24 hours.
If you have any questions, comments or suggestions, please do not hesitate to contact us.