ENS for suppliers to the Spanish Administration: what Royal Decree 311/2022 requires from your company as a subcontractor
What Royal Decree 311/2022 requires from companies providing services to the Spanish Administration, directly or as subcontractors, and how to demonstrate compliance.

On this page
If your company provides services to a town council, a regional department, an autonomous body or any other entity within the Spanish public sector — directly or as a subcontractor of another supplier — you have probably come across a clause in the tender specifications requiring "conformity with the Esquema Nacional de Seguridad" (ENS, Spain's National Security Framework). This is not a best-practice recommendation: it is a legal obligation that Real Decreto 311/2022 (RD 311/2022, Royal Decree 311/2022) itself explicitly extends to the private companies whose information systems underpin services contracted by the Administration [1].
This article explains exactly what the regulation says, what level of requirement applies to you, how it is demonstrated, and the practical steps an SME or technology supplier entering — or already present in — the public-sector supply chain must follow.
What the ENS is and why it reaches private suppliers
The Esquema Nacional de Seguridad is the regulatory framework governing the security of Spanish public-sector information systems. Its current version is RD 311/2022, which replaced the earlier RD 3/2010 [2]. Up to that point, nothing directly affects a private company.
The key lies in Article 2.3 of RD 311/2022, which provides that the administrative or technical specifications of contracts entered into by public-sector entities must include "all requirements necessary to ensure conformity with the ENS of the information systems" underpinning the services provided by contractors, including the submission of the corresponding declarations or certifications of conformity [1]. The same article adds something that is often overlooked: this caution "also extends to the supply chain of such contractors, to the extent necessary and in accordance with the results of the corresponding risk analysis" [1].
In practice, this means two things for your company:
- If you contract directly with an Administration, the ENS applies via the tender specifications, not because your company is part of the public sector.
- If you are a subcontractor of another supplier that does hold a public contract, the ENS can equally reach you, passed down through contractual clauses equivalent to those the main contractor accepted towards the Administration.
The CCN (Centro Criptológico Nacional, Spain's National Cryptologic Centre), the body that administers the ENS, confirms this reach into the supply chain in its contracting and audit guide CCN-CERT IC-02/20 [3].
Which ENS category applies to you: BASIC, MEDIUM or HIGH
RD 311/2022 classifies information systems into three categories — BASIC, MEDIUM and HIGH — determined by the impact that a breach of availability, authenticity, integrity, confidentiality or traceability of the information or services affected would have on the organisation (Annex I and Article 40) [1].
This category is not chosen by the supplier: it is set by the contracting body based on the nature of the information and the service, and is passed down into the tender specifications. As a subcontractor, your minimum level of requirement will generally be that corresponding to the part of the service you carry out, assessed under that same impact analysis. Before signing any contract or subcontract, it is reasonable to request in writing which category applies to you: it directly determines the set of security measures required and the type of accreditation you will have to present.
Declaration of conformity versus certification: not the same thing
Article 38 of RD 311/2022 distinguishes two accreditation routes, and which one applies to you depends on the category [1]:
- BASIC category: a declaration of conformity based on an internal self-assessment is sufficient. The regulation also allows voluntarily undergoing a certification audit even though it is not mandatory.
- MEDIUM or HIGH category: a security audit prior to obtaining the certification of conformity is mandatory. Stating that you comply is not enough: an auditor must verify it.
Article 38.2 adds that those responsible must publish their declarations and certifications on electronic portals, which in practice serves as verifiable evidence for third parties (for example, for the contracting body or for the main contractor if you are a subcontractor) [1].
Audits: how often and what must be verified
If your system is MEDIUM or HIGH category — the most common case among technology and managed-service providers — Article 31 of RD 311/2022 requires a regular, ordinary audit at least every two years, plus an additional extraordinary audit whenever substantial changes are made to the information systems [1]. The ordinary two-year period may be extended by up to three months only for force majeure reasons not attributable to the entity, under the same article.
The audit report must issue an opinion on the degree of compliance, expressly identifying both compliance and non-compliance findings (Article 31.4) [1]. It is not a symbolic report: it is the documentary basis underpinning the certification and the one the contracting body will review in case of doubt.
Incident management and notification: the role of CCN-CERT
Article 33 of RD 311/2022 establishes that the CCN coordinates incident response through the CCN-CERT (Computer Emergency Response Team) structure, and that it is public-sector entities — not private suppliers directly — who must notify the CCN of incidents with a significant impact on the security of the information systems concerned, in accordance with the corresponding technical instruction (Article 33.2) [1]. The regulation does not impose on your company, as a private contractor, a direct legal duty to notify the CCN: that obligation falls on the public-sector entity that owns the service. In practice, however, if the system affected by the incident is the one you operate as a supplier, the only way for the Administration to fulfil its own notification duty is for your contract or subcontract to require you to inform it (or the main contractor) within the deadline. It is therefore advisable to set out in writing the channel and timeframes for reporting upward through the chain, rather than assuming the main contractor "already handles it" without checking.
Specific compliance profiles
Article 30 of RD 311/2022 provides for specific compliance profiles, designed to facilitate "an effective and efficient application of the ENS to certain entities or sectors," validated and published by the CCN [1]. If your activity falls within a sector with a published profile of its own, this can significantly simplify which specific measures from Annex II you must implement and how to demonstrate them. Before designing your compliance plan from scratch, it is worth checking whether an applicable profile exists for your case.
What the ENS measures: the five security dimensions
RD 311/2022 organises impact — and therefore the required measures — around five security dimensions: availability, authenticity, integrity, confidentiality and traceability (Article 40 and Annex I) [1]. Not all of them carry equal weight in every contract: a records-hosting service may mainly require traceability and integrity, while an electronic identification service will focus on authenticity. This assessment by dimension, rather than a single label, is what ultimately determines the BASIC, MEDIUM or HIGH category of a system or part of it, and therefore the set of Annex II measures applicable to you as a supplier.
In practice, this has a relevant consequence for a subcontractor: within the same contract, components with different categories can coexist if they process different information or perform different functions. You should not assume that "the whole contract is MEDIUM" without requesting the breakdown by system or service; the part you carry out may have a different requirement — higher or lower — than the contract as a whole.
Deadlines: what the regulation says and what to check in your contract
The sole transitional provision of RD 311/2022 granted pre-existing systems a period of twenty-four months from the regulation's entry into force (May 2022) to achieve full compliance, a period that as of this publication has already elapsed [1]. That transitional provision was designed for systems already operating under the previous ENS (RD 3/2010), not necessarily for a new contract you sign today. The actual deadline that applies to you as a new supplier or subcontractor is the one set by your specific contract or tender specifications; it is always advisable to confirm the exact deadline with the contracting body or the main contractor, as it can vary by tender.
Consequences of being unable to demonstrate conformity
The text of RD 311/2022 itself does not include a specific penalty regime [1]. This does not mean there are no consequences: the absence of the declaration or certification required in the tender specifications is, in practice, a technical solvency requirement or a condition for contract performance, and failing to meet it can prevent contract award, lead to contract termination, or trigger penalties agreed in the contract or subcontract; the exact regime depends on each tender and on the public procurement regulations applicable to the specific case.
Practical steps for the subcontractor
Bringing together the points above, the reasonable order of work for a company entering — or already present in — the supply chain of a public contract is as follows:
- Request in writing the required category (BASIC, MEDIUM or HIGH) and the exact scope of systems affected before signing.
- Determine the accreditation route: self-assessment and declaration (BASIC) or audit and certification (MEDIUM/HIGH), under Article 38 [1].
- Check whether a specific compliance profile has been published by the CCN for your sector (Article 30) [1].
- Implement the security measures corresponding to your category (Annex II of RD 311/2022) [1] and document the evidence.
- Commission the audit with an accredited body if your category is MEDIUM or HIGH, and plan for it to be repeated at least every two years (Article 31) [1].
- Set out by contract the channel and timeframes for incident notification to the main contractor or the Administration, so that it can in turn fulfil its own duty to notify CCN-CERT when applicable (Article 33) [1].
- Pass the same requirements on in writing to any supplier you in turn subcontract, in accordance with Article 2.3 [1].
- Publish or keep accessible your declaration or certification of conformity, as provided for in Article 38.2 [1], so that you can demonstrate it to the main contractor or the contracting body.
How Hodeitek approaches this
Hodeitek is ISO 27001 certified and holds the Esquema Nacional de Seguridad conformity certification, MEDIUM category (certificate no. 34/5704/26/09103, issued by OCA Instituto de Certificación), covering all of its cybersecurity, AI and HodeiShield services. We help public-sector suppliers and subcontractors determine the actual category that applies to them, prepare conformity documentation (declaration or certification), and carry out the periodic audits required under Article 31 of RD 311/2022, without over-scaling the effort when the risk analysis does not justify it.
Sources
[1] Real Decreto 311/2022, de 3 de mayo, por el que se regula el Esquema Nacional de Seguridad (texto consolidado), artículos 2.3, 30, 31, 33, 38, 40, Anexo I y Disposición transitoria única. BOE. https://www.boe.es/eli/es/rd/2022/05/03/311/con
[2] BOE-A-2022-7191 — Ficha oficial y acceso al texto del Real Decreto 311/2022. https://www.boe.es/buscar/act.php?id=BOE-A-2022-7191
[3] CCN-CERT IC-02/20 — Guía de contratación y auditorías del ENS, Centro Criptológico Nacional (CCN/CNI). https://ens.ccn.cni.es/es/docman/documentos-publicos/informes-cocens/6-ccn-cert-ic-02-20-guia-contratacion-auditorias/file
[4] Esquema Nacional de Seguridad — Preguntas frecuentes, Centro Criptológico Nacional (CCN/CNI). https://ens.ccn.cni.es/es/que-es-el-ens/faq
Sources
- Real Decreto 311/2022, de 3 de mayo, por el que se regula el Esquema Nacional de Seguridad (texto consolidado)
- BOE-A-2022-7191 — Ficha y texto del Real Decreto 311/2022
- CCN-CERT IC-02/20 — Guía de contratación y auditorías del ENS (CCN/CNI)
- Esquema Nacional de Seguridad — Preguntas frecuentes (CCN/CNI)
Self-check your ENS category
Find out which ENS category (basic/medium/high) applies to you and which controls are still missing, in 2 minutes.
Was this article useful?
Hodeitek
Equipo Hodeitek
Hodeitek's cybersecurity, regulatory compliance and AI consulting team.
Need help with this?
Schedule a free consultation with our team and see how to apply it to your organization.
Schedule free consultation