What the National Security Framework (ENS) is and which software has it
What is the Spanish National Security Framework? The ENS is the benchmark cybersecurity certification in Spain, governed by Royal Decree 311/2022, and it is a legal requirement for any technology provider working with Spanish public administrations. It is structured in three levels of increasing demand, and very few providers in the sector reach the highest one. R2 Docuo holds the certification at its most demanding level, the HIGH category.
What is the National Security Framework?
The National Security Framework is the set of regulations governing information security in the Spanish public sector and, by extension, in any technology provider that wants to work with public administration. Unlike other international certifications, the ENS is not voluntary for those operating in that field: it is a legal requirement, governed by Royal Decree 311/2022.
The three ENS levels
| Level | What it requires | Who it applies to |
| Basic | Standard security measures | Systems with limited impact |
| Medium | Reinforced controls and periodic auditing | Systems holding sensitive information |
| High | The most demanding level, with a formal audit every two years by an accredited body | Critical systems or those with highly sensitive data |
Why the HIGH category is so uncommon
The HIGH category requires a formal audit every two years carried out by an accredited body, and it involves very demanding security controls across the whole infrastructure, not just in the user-facing product. For a software provider, especially an international one splitting its attention across many countries, reaching and maintaining that level rarely justifies the effort if its core business is not focused on Spain. That is why it is common to find providers with general international certifications, but very few with the ENS at its highest category.
ENS vs ISO 27001: they are not the same
They are often confused, but they cover different things. ISO 27001 is an international standard for managing information security, applicable in any country and sector. The ENS is a legal framework specific to the Spanish public sector, with its own levels and its own audit process. A provider may hold one, the other, or both; holding both is the strongest combination, because it covers the international standard as well as the Spanish legal framework.
What the ENS means for your company even if you do not work with public administration
Even if your company is private and will never bid for public sector work, your software provider holding the ENS at HIGH category is a sign of security maturity that goes beyond what is legally required of you: it means that provider passes a formal external audit every two years, something very few do without being obliged to.
Which document management software holds the ENS at HIGH category?
R2 Docuo is certified at ENS HIGH category and in ISO 27001, an uncommon combination in the sector, particularly among international providers.
Frequently asked questions
It is the Spanish National Security Framework, the set of Spanish regulations governing information security, established by Royal Decree 311/2022 and mandatory in order to work with Spanish public administration.
ISO 27001 is an international standard for managing information security; the ENS is a legal framework specific to the Spanish public sector, with its own levels and audit process.
It is mandatory for technology providers working with Spanish public administration. For other companies it is not mandatory, but it can be used as a trust criterion when choosing a provider.
R2 Docuo holds the HIGH category, the most demanding of the three, as well as ISO 27001 certification.
Through a formal audit carried out by an accredited body, which must be repeated every two years to keep the certification valid.