ENS High vs ENS Medium: a practical guide to choosing the right category
The difference between ENS Medium and ENS High is strategic, not just technical. We break down the categorisation criteria, real cost, audit requirements and common mistakes.

On this page
ENS 2022: a decision that is more strategic than technical
The Esquema Nacional de Seguridad (ENS, Spain's National Security Framework), in its version in force since 2022 (Real Decreto 311/2022, of 3 May), establishes three categories of information systems — Basic, Medium and High — based on the impact that an incident compromising their security would have on essential assets [1]. Choosing between Medium and High is not a server-room question: it is a decision with implications for budget, team structure and, above all, the ability to bid for and maintain public-sector contracts.
This guide updates and expands on a previous analysis, corrects two inaccuracies that crept into the earlier version — audit frequency and the number of applicable measures — and adds official sources, a more detailed working roadmap and a frequently asked questions section.
Classification criteria (Annex I, RD 311/2022)
A system is categorised by assessing its assets across five security dimensions: confidentiality, integrity, traceability, authenticity and availability [1]. Each dimension is rated on three levels — Low, Medium, High — based on the harm that an incident compromising it would cause to the organisation, affected individuals or other organisations. The highest level obtained in any of the five dimensions determines the system's overall category (Basic, Medium or High).
It is important to stress that the category does not depend on the size of the organisation or its budget, but on the potential impact of the assets it manages. A small public body handling highly sensitive data may fall into High; a large administration with low-impact systems may fall into Medium.
When High Category typically applies
- Systems whose interruption or compromise would cause very serious harm to the exercise of essential functions or powers, to the general interest, or to citizens' rights.
- Large-scale processing of specially protected data (health, minors, public safety) where its compromise would have a very serious impact.
- Systems that support critical infrastructure or essential services subject to NIS2, depending on their own impact analysis.
- Tender specifications and contracts that explicitly require High Category as a bidding requirement (common in Defence, Interior and some large regional governments).
When Medium Category typically applies
- Systems whose interruption would cause serious, but not very serious, harm to the functions they support.
- Most general public services of a non-critical nature.
- The bulk of medium-sized town councils, autonomous bodies and public universities, unless they manage specific higher-impact assets.
Practical comparison of requirements
| Area | ENS Medium | ENS High |
|---|---|---|
| Reference catalogue of measures (Annex II) | 73 measures, with a level of application graded by category [1] | The same 73 measures, required with wider scope and additional reinforcements on several of them [1] |
| Regulatory audit | Ordinary, at least every two years [1][3] | Ordinary, at least every two years [1][3] — not annual, a correction from earlier versions of this article |
| Extraordinary audit | Where substantial modifications are made to the system [1] | Where substantial modifications are made to the system [1] |
| Declaration vs. certification of conformity | Declaration of conformity (self-assessment) or certification, depending on what the public body requires [2] | Usually certification by an accredited certification body [2] |
| Segregation of duties and access control | Required | Required, with reinforced controls and more exhaustive traceability |
| Business continuity | Documented continuity plan | Documented continuity plan, tested periodically |
| Incident management and monitoring | Detection and response capability proportional to risk | Reinforced detection and response capability; in practice, many organisations in High Category opt for 24/7 monitoring as their own risk-management decision, not as a fixed figure imposed by the regulation |
On the catalogue of measures: Annex II of RD 311/2022 does not define "73 measures for Medium and 112 for High" as two separate lists. There is a single reference catalogue — organised into organisational framework, operational framework and protection framework — and each measure is applied with a different level of reinforcement (or not applied at all) depending on the system's category [1]. The earlier version of this article presented two separate totals; that was an incorrect simplification, which we correct here.
On the audit: the most repeated error in articles popularising the ENS is assuming that High Category requires an annual audit. Article 31 and Annex III of RD 311/2022 set the same ordinary frequency — at least every two years — for both Medium and High [1][3]. What changes between categories is not the frequency of the regulatory audit, but the scope of the measures audited and, in common market practice, the conformity mechanism (declaration versus certification) [2].
The real cost of moving up to High
There are no official published figures on the differential cost of implementing High Category versus Medium: RD 311/2022 does not set budgets. The cost of raising a system from Medium to High Category varies substantially depending on volume, sector and starting point; there is no official reference figure, and any published range must be presented explicitly as Hodeitek's own estimate, not as regulatory data. The following figures are an indicative estimate from Hodeitek based on projects delivered, not regulatory data or a market study, and should be treated as such.
Line items that typically grow when moving up to High
- Certification and audit: the scope of the audit is larger and, if the public body requires certification by an accredited body rather than self-declaration, the cost of the certification process is added.
- Redundant infrastructure and continuity: the reinforcements to continuity and availability measures under High usually translate into alternative sites, communications redundancy and periodic testing of the continuity plan, with associated CAPEX and OPEX.
- Detection and response capability: covering the reinforced monitoring measures with broad coverage (24/7, in many cases) is the line item that varies most depending on whether it is resolved with an in-house team, a managed SOC, or a hybrid model.
Indirect cost
- Team time: document maintenance, compliance evidence and audit preparation consume a significant share of a GRC professional's time on a recurring basis, not only in the certification year.
- Operational friction: changes to the system go through a more demanding change-management process when High Category measures are at stake, which can slow deployments.
"The jump from Medium to High is rarely linear in budget or in operational load: in our project experience, the effort of document maintenance and evidence gathering grows more than proportionally in the first year." — Hodeitek project observation, not an externally verified statistic.
When it is worth moving up to High
We recommend seriously evaluating High Category in three scenarios:
- Obligation arising from the categorisation itself: if the impact analysis across the five dimensions (Annex I) objectively places the system in High, it is not a choice — it is the result of the analysis, and categorising below it would be a non-conformity.
- Explicit contractual requirement: when the tender specification or sector-specific regulatory framework requires High as a condition of bidding or of providing the service.
- Genuine sensitivity of the data or service: when the reputational, legal impact or impact on third parties' rights objectively justifies a higher level of requirement, beyond the strict minimum applicable.
In all other cases, a well-implemented Medium Category with no findings offers more practical assurance than a High Category that is certified on paper but sustained with difficulty. Categorising "above" the correct level to impress a client or a procurement board, without the organisational maturity to sustain it, tends to generate recurring non-conformities in biennial audits.
Recommended compliance roadmap
Phase 1 — Applicability analysis (approx. 3–4 weeks)
- Inventory and assessment of assets across the five dimensions of Annex I.
- Identification of contractual and sector-specific obligations that may set the category above the result of the impact analysis.
- Formal documentation of the categorisation, as this is the piece that underpins the entire subsequent applicability analysis.
Phase 2 — Gap analysis
- Comparison of the current state against the catalogue of measures in Annex II, applied with the level of reinforcement corresponding to the category obtained.
- Prioritisation of outstanding measures by criticality, cost and technical dependencies between them.
- Definition of a risk treatment plan for measures that cannot be implemented in the short term, documenting the accepted risk decision.
Phase 3 — Remediation, declaration/certification and maintenance
- Implementation of the outstanding measures prioritised in the previous phase.
- Internal audit prior to the formal audit, to reduce findings in the official process.
- Declaration or certification of conformity before the relevant body or entity, depending on what the scope of application requires [2].
- Schedule for the ordinary biennial audit and protocol for an extraordinary audit in the event of substantial system changes [1][3].
Common mistake to avoid: treating ENS compliance as a project with an end date. RD 311/2022 sets out a continuous-improvement model with periodic auditing; the maintenance effort (evidence, review of measures, change management) is recurring, not a one-off.
ENS and NIS2: two frameworks that should not be confused
The ENS regulates the security of Spanish public-sector systems (and their suppliers) since 2010, with the 2022 revision currently in force [1]. NIS2 — Directive (EU) 2022/2555 — is a European cybersecurity framework aimed at essential and important entities in specific sectors, public and private, with obligations covering risk management, incident notification and its own penalty regime [5].
Spain was required to transpose NIS2 by 17 October 2024; it did not, and the European Commission maintains an open infringement procedure against Spain for incomplete transposition of the NIS2 Directive. The exact status of the infringement procedure (including any eventual referral to the Court of Justice of the EU) can be checked directly in the Commission's Infringement Decisions Register (ec.europa.eu/atwork/applying-eu-law) or at ec.europa.eu/commission/presscorner. According to press sources, the Council of Ministers approved the preliminary bill for the Cybersecurity Coordination and Governance Law on 14 January 2025 [4]; as of this guide's publication date, the exact parliamentary status of that bill could not be confirmed against a live official source. We recommend checking parliamentary status at boe.es and in the Congress of Deputies' initiatives search tool (congreso.es) before making compliance decisions. Any statement about the definitive entry-into-force dates of this law in Spain should be verified against the text in force in the BOE.
The practical implication for an organisation subject to both frameworks: complying with the ENS does not equate to complying with NIS2, nor vice versa. They are independent applicability analysis exercises, although they share much of the groundwork (asset inventory, risk management, incident response capability).
Conclusion
ENS Medium and ENS High are not two intensity steps of the same measure, but two levels of requirement calibrated against the real impact of the assets the system protects. The correct category is the one that results from the Annex I impact analysis — reinforced, where applicable, by explicit contractual obligations — not the one that looks most impressive in a commercial proposal. And two facts worth always keeping in mind and verifying against the official source: the ordinary audit is biennial in both Medium and High, and the catalogue of measures in Annex II is a single catalogue, applied with a different level of reinforcement depending on category. For most public administrations and suppliers, the operational recommendation remains the same: a Medium Category implemented rigorously and with no recurring findings is preferable to a High Category certified on paper but sustained with difficulty; High should be reserved for cases where the impact analysis or the contractual context genuinely requires it.
This article cites regulations and official guidance in force as of the publication date. Spain's NIS2 transposition framework is in progress and may change; always verify the current status against the sources cited before making compliance decisions.
Sources
- https://www.boe.es/buscar/act.php?id=BOE-A-2022-7191
- https://ens.ccn.cni.es/es/que-es-el-ens/faq
- https://www.ccn-cert.cni.es/series-ccn-stic/800-guia-esquema-nacional-de-seguridad/502-ccn-stic-802-auditoria-del-ens/file.html
- https://www.dsn.gob.es/en/node/24160
- https://eur-lex.europa.eu/legal-content/ES/TXT/?uri=CELEX:32022L2555
- https://ciberseguridad.creandopatria.com/noticia/nis2-sigue-sin-publicarse-en-el-boe-en-julio-de-2026-espana-encara-la-recta-final-antes-de-la-aplicacion-plena-prevista-para-octubre-2
Does NIS2 apply to you?
Self-check your NIS2 scope (essential/important/out) and which directive domains you already cover, in 2 minutes.
Was this article useful?
Gorka Gonzalo
Founder & CEO
Founded Hodeitek in 2023 and runs the company. A cybersecurity and AI expert, he sets the technical and product direction of HodeiShield and personally leads the most critical engagements.
Need help with this?
Schedule a free consultation with our team and see how to apply it to your organization.
Schedule free consultation