{
  "node_id": "es-ens-real-decreto-311-2022-esquema-nacional-seguridad",
  "title": "Spain ENS - Real Decreto 311/2022 Esquema Nacional de Seguridad (National Security Scheme)",
  "domain": "Cybersecurity",
  "version": "1.0.0",
  "last_updated": "2026-07-10",
  "bluf": "Real Decreto 311/2022, de 3 de mayo, regulates the Esquema Nacional de Seguridad (ENS), the Spanish National Security Scheme established in Article 156.2 of Ley 40/2015, and lays down the principios basicos y requisitos minimos (basic principles and minimum requirements) for the protection of information and services handled by public sector information systems. Published in BOE numero 106 of 4 May 2022 and in force from 5 May 2022, the ENS applies to the entire Spanish public sector as defined in Article 2 of Ley 40/2015 and also applies to the information systems of private sector entities when they provide services to public entities for the exercise of their administrative competences and powers; contracts with such suppliers must include all requirements necessary to ensure conformity with the ENS. Article 5 sets seven basic principles: seguridad como proceso integral (security as an integral process); gestion de la seguridad basada en los riesgos (risk-based security management); prevencion, deteccion, respuesta y conservacion (prevention, detection, response and preservation); existencia de lineas de defensa (existence of lines of defence); vigilancia continua (continuous monitoring); reevaluacion periodica (periodic re-evaluation); and diferenciacion de responsabilidades (differentiation of responsibilities). Systems are categorized under Article 40 and Annex I into the categories BASICA, MEDIA and ALTA based on the impact of security incidents on the organization objectives, assets and service continuity, and the security measures of Annex II are organized into the marco organizativo (organizational framework), marco operacional (operational framework) and medidas de proteccion (protection measures). Under Article 38, systems in categories MEDIA and ALTA require an audit for certification of conformity, while BASICA systems require a self-assessment for the declaration of conformity, and conformity declarations and certifications must be published. ENS conformity has become the gate for supplying cloud and IT services to Spanish public administrations.",
  "paywall": {
    "status": "LOCKED",
    "unlock_cost_usd": "0.01",
    "skyfire_id": "41779894-ece2-4163-9761-b3b1b76e19b0"
  },
  "crosswalks": {
    "_available_keys": [
      "legal_basis_anchor",
      "scope_private_suppliers",
      "categorization_model",
      "conformity_model",
      "peer_schemes_crosswalk",
      "industry_mapping",
      "enforcement_anchors"
    ],
    "_note": "Full crosswalk values included in vault response"
  },
  "dependencies": [
    "es-lopdpgdd-2018",
    "es-ley-9-2017-contratos-sector-publico",
    "eu-nis2-directive-2022-2555-critical-infrastructure"
  ],
  "primary_citations_count": 6
}