HodeiShield: The European TPRM platform with native NIS2, ENS, and DORA
Hodeitek's team are Spanish regulatory specialists: the National Security Framework (Esquema Nacional de Seguridad, or ENS) is a Spain-only requirement set by Spain's National Cryptologic Center (CCN), not a European or international standard, and it matters if you operate in Spain or sell to its public sector. The ENS is mandatory for all Spanish public administrations and their technology vendors — HodeiShield is the only platform with native ENS, with mapped controls, linked evidence, and automated system profiling.
Category is determined by impact across 5 dimensions (RD 311/2022).
Illustration of the categorization mechanism — the real category is set in the formal risk analysis.
Without ENS certification, you cannot contract with Spanish public administration. For technology vendors, ENS is an essential requirement in every tender and contract renewal.
Most organizations manage ENS controls in spreadsheets — without traceability, linked evidence, or the ability to automatically generate the system profile. Every audit requires weeks of manual preparation.
Basic, medium, and high categories have different requirements with progressive controls. Manual management is unviable at scale, especially for vendors that must demonstrate compliance for multiple public sector clients.
Additionally, Spain has mapped ENS to NIS2 through CCN's PCE-NIS2, meaning organizations must manage both frameworks simultaneously, with shared controls that are often unnecessarily duplicated.
Four pillars that apply to every service and every solution, not a one-off slogan.
The same team that attacks in the pentest runs the SOC and builds the AI models. Offensive insight informs defense, and AI is applied where we already operate, not bolted on as an extra layer.
HodeiShield, our own platform, automates continuous assessment, control mapping, and evidence generation — so manual work no longer sets the pace of regulatory compliance.
Infrastructure on OVHcloud (France/EU). You speak with the people who sign off on the work, not an account manager who forwards your request to another department.
HodeiShield isn't a third-party product we resell: we build and operate it ourselves, and that's what lets us offer faster compliance and evidence that's always current.
We start by generating the automated system profile across ENS's 5 dimensions: availability, authenticity, integrity, confidentiality, and traceability. HodeiShield calculates the category (basic/medium/high) and determines applicable controls automatically.
Each control is managed with its implementation status, linked evidence, assigned owners, and review dates. The ENS Evidence Pack is generated in one click — ready for the external auditor or for attaching to a public tender.
The NIS2 connection is automatic: CCN's PCE-NIS2 defines the correspondence between ENS controls and NIS2 requirements. HodeiShield implements this mapping natively, eliminating duplicate work. If you meet ENS High, 70%+ of NIS2 is already covered.
For public sector vendors, we also assess ENS compliance of their own subcontractors, creating a verifiable compliance chain.
Structured methodology for measurable outcomes.
We generate the system profile across ENS's 5 dimensions (availability, authenticity, integrity, confidentiality, traceability) and determine the applicable category and controls.
Each control with its status, linked evidence, assigned owners, and dates. ENS Evidence Pack generated in one click, ready for auditor or tender.
Automatic CCN PCE-NIS2 mapping. ENS High covers 70%+ of NIS2. We eliminate duplicate work and manage both frameworks in a single platform.
Tangible outcomes for your organization.
HodeiShield generates a 5-dimension system profile, bid-ready evidence pack in minutes, and ENS+NIS2 cross-framework without duplicated work.
Discover HodeiShieldDiscovery, execution, delivery and follow-up — a clear path to continuous operation.
System profile across 5 dimensions (availability, integrity...).
Organizational, technical, and protection measures.
Internal audit and CCN-CERT readiness.
Support during accredited auditor review.
A real scenario of how we work, not a marketing figure.
A public tender is published requiring proof of ENS conformity. Instead of assembling the documentation from scratch, the team generates the ENS Evidence Pack from HodeiShield with each control's real status and linked evidence, and attaches it to the bid — the same file also covers, without duplicate work, the NIS2 portion already mapped through PCE-NIS2.
No names — here's how we work differently, with verifiable facts.
| Criteria | Generalist integrator | Hodeitek |
|---|---|---|
| Focus | Dozens of business lines; cybersecurity is just one of them | 100% cybersecurity and AI |
| Point of contact | An account manager who forwards your request to another department | Direct contact with the founders |
| Regulatory compliance | One-off reports per regulation, manual evidence management | HodeiShield automates evidence and cross-framework NIS2/ENS/DORA mapping |
| Product | Resells third-party licenses | Builds and operates HodeiShield, its own platform |
Talk to our team to evaluate how this solution can protect your organization.
Response within 24h
Comprehensive guidance to achieve and maintain compliance with the European NIS2 cybersecurity directive.
The Digital Operational Resilience Act requires 22,000+ financial entities to actively manage third-party ICT risk since January 2025. HodeiShield automates the Information Register, classifies incidents automatically, and keeps evidence ready for ESA inspection.