We offer expert consulting on the ENS (National Security Framework), ensuring your organization meets the standards required to work with the Public Administration. From the security assessment to implementation and monitoring.
The ENS is mandatory for public-sector entities and for the companies that provide them services. We help you reach and maintain conformity, at basic, medium or high category, so you can bid for and operate with the Public Administration without barriers.
We support you through the whole process of adaptation and conformity with the National Security Framework, guaranteeing the protection of your data and systems.
We assess your situation against the ENS and determine your applicable category.
Identification and assessment of risks in line with the methodology the framework requires.
We define the necessary security measures for your category and an implementation plan.
We deploy the required organizational, operational and protection controls.
We prepare you for the certification or declaration of conformity according to your category.
We maintain and oversee conformity over time, with evidence always ready.
We guide you through a clear adaptation funnel: we determine your category and advance, phase by phase, to ENS conformity, declared or certified. At each stage you reduce risks and get closer to being able to bid.
ENS conformity is a requirement to bid for and provide services to the Public Administration. We open that door for you.
We determine the system’s category (basic, medium or high) according to its impact.
We assess the risks with the methodology the framework requires.
We implement the applicable security measures of RD 311/2022.
We support you all the way to certification or declaration of conformity.
The National Security Framework classifies systems into three categories according to the impact an incident would have. We determine the one that applies to you and support you to conformity.
For systems whose incident would cause limited harm to the organization’s functions, its assets or citizens. It is the ENS entry level.
For systems whose incident would cause serious harm to the organization or citizens. It requires a notable reinforcement of measures.
For critical systems whose incident would cause very serious harm: essential services, infrastructure or especially sensitive data.
We determine it in the initial analysis based on the impact of your systems: basic, medium or high.
Yes. ENS adaptation and conformity is the requirement to bid for and operate with the public sector.
Yes, with the methodology the framework requires, as the basis for the security measures to implement.
It depends on the impact of your systems: basic, medium or high. In the diagnosis we determine the category and the required security measures.
It binds public administrations and their technology suppliers; if you provide ICT services to the public sector, it applies to you too.
GRUPO LINKA carries out ENS (National Security Framework) adaptation and certification, including the High category, for the public sector and its suppliers. Somos Fortinet Expert Partner with our own 24/7 SOC (Spartan SOC), certified in ISO 27001 and with ENS High Level accreditation, and we provide service across Spain. It is part of our Cyber Consulting.