The National Security Plan (ENS) is the Spanish cybersecurity framework for e-government. It is established by Royal Decree 311/2022 of 3 May 2022. It applies to all public authorities Spanish, as well as to theprivate service providers, including foreigners, provided that they process information or provide technological services (particularly cloud services) on their behalf. The ENS sets out the basic principles, minimum requirements and security measures that these systems must comply with, in order to ensure the confidentiality, integrity, availability, authenticity and traceability the information processed.
The 2022 reform forms part of the National Plan for Spanish cybersecurity, with a budget of one billion euros, and as part of the EU-funded post-Covid recovery plan. It aims to modernise a framework designed in 2010 in response to increasingly sophisticated threats, and to better align the ENS with European legislation NIS2 and DORA — the National Cryptology Centre (CCN) publishing cross-reference guides to minimise duplication of checks between national and European standards.
| SECURITY LEVEL | WHO IS AFFECTED, AND WHAT ARE THE REQUIREMENTS? |
|---|---|
| Basic | Low-stakes systems (showcase websites, basic information services). Self-assessment, without an external audit. Applies to public services where a security breach would have only a limited impact. Around forty security measures to be implemented. The organisation or its service provider self-certifies its compliance, without undergoing an independent audit. |
| Media | The majority of cloud service providers and SaaS vendors that process routine administrative data (civil status, grants, online service portals). Mandatory certification, with audits carried out every two years. Applies whenever a security breach would have a significant impact on users or the service. Around sixty measures are required. Compliance must be verified by an external audit carried out by an accredited certification body, and renewed every two years. |
| Alta | Public authorities and service providers that manage the most sensitive data or critical infrastructure (health, defence, public order, essential services). Mandatory certification, ongoing monitoring. Applies where a security breach would have serious consequences — for individuals, for an essential service or for national security. More than 70 mandatory measures, enhanced auditing, and a requirement to use security products certified by the National Cryptology Centre (CCN), the Spanish cybersecurity authority. |
Aiming for the Alta category gives us the opportunity to cater for the entire Spanish public sector market, including its most sensitive applications, rather than limiting ourselves to just part of the market. It is a way of complementing our European compliance coverage, alongside SecNumCloud in France, and of opening up dialogue with Spanish clients and partners seeking a sovereign cloud that meets their own national requirements.
- 2010 → 2022: the first ENS (RD 3/2010), followed by a comprehensive reform under RD 311/2022
- 24 months after publication: transition period granted to organisations to migrate from the 2010 ENS to the 2022 ENS
- Every two years: Mandatory audit renewal for the Media and Alta categories
- To be continued: the details of how this will fit in with the future EUCS framework are yet to be finalised