Schellman Announces Strategic Partnership with Goldman Sachs Alternatives

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Cybersecurity Assessments

Spanish National Security Scheme (ENS) Certification

Our ENS lead auditors specialize in evaluating information systems against Spain's Esquema Nacional de Seguridad (ENS), governed by Royal Decree 311/2022 — designed to ensure a consistent, risk-based approach to security across Spain's public sector and its technology providers.

Contact a Specialist

What is the Spanish National Security Scheme (ENS)?

The ENS provides a security framework for public administrations in Spain and any private organizations that provide digital services to them. Established under Royal Decree 311/2022, ENS defines the basic principles, requirements, and security measures for the adequate protection of the information processed and the services provided by organizations within its scope, with the aim of ensuring confidentiality, integrity, accountability / traceability, authenticity, and availability.

spanish-flag-ens

The security measures (as defined within Annex II of the Royal Decree) are organized into three families:

  • Organizational framework (org)
  • Operational controls (op)
  • Protection measures (mp)

The information system security category (Basic, Medium, High) is used to determine the minimum security measures and requirements that must be implemented by the organization. The security category is determined based upon the potential impact of a security incident, as shown in the steps below. The requirements for each security measure become more stringent as you move from a security category of basic to high.

spanish-flag-ens
ens-certification-1

Step One

Assess across five security dimensions

  • Confidentiality: Information accessible only to authorized parties
  • Integrity: Data accuracy and completeness preserved
  • Accountability / Traceability: Data accuracy and completeness preserved
  • Authenticity: Identity of users and data verified
  • Availability: Systems and data accessible when needed
ens-certification-1
spanish-government-building-ens

Step Two

Assign a level to each affected dimension

Low: Limited damage

Medium: Serious damage

High: Very serious damage

spanish-government-building-ens
ens-certification-3

Step Three

Derive the system security category

The overall category of an information system is determined by the highest level reached across any single dimension. Where a system processes multiple types of information or provides multiple services, the highest level established for any individual information or service applies.

  • BASIC Category
  • MEDIUM Category
  • HIGH Category

Note: The security category must be re-assessed annually, or whenever significant changes occur to the assessed criteria.

ens-certification-3

Benefits of ENS Certification

ens-certification-5

Our ENS Certification Process

Key steps in the ENS certification process include:

Pre-Engagement / Scoping

Assessment Fieldwork

Reporting & Certification

ens-certification-5
danny-manimbo-profile

ENS Certification Expert

Danny Manimbo

Danny Manimbo is a Principal with Schellman based in Denver, Colorado. As a member of Schellman’s West Coast / Mountain region management team, Danny is primarily responsible for leading Schellman's AI and ISO practices as well as the development and oversight of Schellman's attestation services. Danny has been with Schellman for 10 years and has over 13 years of experience in providing data security audit and compliance services.

Meet Danny Contact Us

danny-manimbo-profile

Talk to a Practice Leader