National Security Framework (ENS) | GRUPO LINKA
GOVERNANCE & COMPLIANCE · ENS

National Security Framework for the Public Sector

We offer expert consulting on the ENS (National Security Framework), ensuring your organization meets the standards required to work with the Public Administration. From the security assessment to implementation and monitoring.

ENSRoyal Decree 311/2022Basic/Medium/High Category
[ PUBLIC-SECTOR COMPLIANCE ]

Work with the Administration with Full Confidence

The ENS is mandatory for public-sector entities and for the companies that provide them services. We help you reach and maintain conformity, at basic, medium or high category, so you can bid for and operate with the Public Administration without barriers.

Basic Category Medium Category High Category Declaration of Conformity
SPAIN’S OFFICIAL FRAMEWORK
Official logo of the ENS, Spain’s National Security Framework
Regulated by Royal Decree 311/2022
[ OUR SERVICE ]

Comprehensive Adaptation to the ENS

We support you through the whole process of adaptation and conformity with the National Security Framework, guaranteeing the protection of your data and systems.

Gap Analysis

We assess your situation against the ENS and determine your applicable category.

Risk Analysis

Identification and assessment of risks in line with the methodology the framework requires.

Adaptation Plan

We define the necessary security measures for your category and an implementation plan.

Measure Implementation

We deploy the required organizational, operational and protection controls.

Declaration of Conformity

We prepare you for the certification or declaration of conformity according to your category.

Continuous Monitoring

We maintain and oversee conformity over time, with evidence always ready.

CategorizationBasic / Medium / HighRisk AnalysisENS MethodologyImplementationAnnex II measuresAuditEvidenceConformity
ENS ADAPTATION PATH
[ YOUR ROADMAP ]

From Categorization to Conformity

We guide you through a clear adaptation funnel: we determine your category and advance, phase by phase, to ENS conformity, declared or certified. At each stage you reduce risks and get closer to being able to bid.

ENS conformity is a requirement to bid for and provide services to the Public Administration. We open that door for you.

[ WHY GRUPO LINKA ]

Real Experience Auditing the ENS

We have audited and adapted companies for the ENS and ISO 27001. Our consulting team knows the framework in depth and works across Spain, including the Balearic and Canary Islands, so you meet the security standards the public sector requires.

Specialized consultants
Official risk methodology
Nationwide coverage
Audit support
ENS · STATUS
Category determinedOK
Risk analysisOK
Measures implementedOK
Conformity readyOK
[ PATH TO COMPLIANCE ]

From Assessment to Conformity

01

Categorization

We determine the system’s category (basic, medium or high) according to its impact.

02

Risk Analysis

We assess the risks with the methodology the framework requires.

03

Adaptation

We implement the applicable security measures of RD 311/2022.

04

Conformity

We support you all the way to certification or declaration of conformity.

[ SECURITY LEVELS ]

The Three Categories of the ENS

The National Security Framework classifies systems into three categories according to the impact an incident would have. We determine the one that applies to you and support you to conformity.

CATEGORÍA

Basic

LIMITED IMPACT

For systems whose incident would cause limited harm to the organization’s functions, its assets or citizens. It is the ENS entry level.

Essential security measures
Suited to low-risk services
Conformity by self-assessment
CATEGORÍA

Medium

SERIOUS IMPACT

For systems whose incident would cause serious harm to the organization or citizens. It requires a notable reinforcement of measures.

Reinforced measures and traceability
Formal risk analysis
Biennial conformity audit
CATEGORÍA

High

VERY SERIOUS IMPACT

For critical systems whose incident would cause very serious harm: essential services, infrastructure or especially sensitive data.

Maximum level of demand
Advanced controls and monitoring
Certification by an accredited body
[ FREQUENTLY ASKED QUESTIONS ]

We Answer Your Questions

Which ENS category applies to me?+

We determine it in the initial analysis based on the impact of your systems: basic, medium or high.

Does this let me work with the public administration?+

Yes. ENS adaptation and conformity is the requirement to bid for and operate with the public sector.

Does it include risk analysis?+

Yes, with the methodology the framework requires, as the basis for the security measures to implement.

Which ENS category does my organization need?+

It depends on the impact of your systems: basic, medium or high. In the diagnosis we determine the category and the required security measures.

Does the ENS only bind the public sector?+

It binds public administrations and their technology suppliers; if you provide ICT services to the public sector, it applies to you too.

[ TRUST & COMPLIANCE ]

Certifications & Tier-1 Alliances

We operate under the most demanding standards and with the market-leading vendors to guarantee your security, your continuity and your regulatory compliance, including the NIS2.

CERTIFIED
ISO
9001
COMPANY
Quality Management
CERTIFIED
ISO
27001
COMPANY
Information Security
CONFORMITY
ENS
HIGH CAT.
National Security Framework
CERTIFIED
ISO
27018
COMPANY
Personal Data in the Cloud
CERTIFIED
ISO
14001
COMPANY
Environmental Management
CERTIFIED
ISO
20000
COMPANY
IT Service Management
CERTIFIED
ISO
22301
COMPANY
Business Continuity

Need to Comply with the ENS?

We adapt you to the National Security Framework so you can work with the Administration.

[ IN SUMMARY ]

GRUPO LINKA carries out ENS (National Security Framework) adaptation and certification, including the High category, for the public sector and its suppliers. Somos Fortinet Expert Partner with our own 24/7 SOC (Spartan SOC), certified in ISO 27001 and with ENS High Level accreditation, and we provide service across Spain. It is part of our Cyber Consulting.

CallContact