The Esquema Nacional de Seguridad (ENS) is Spain’s national security framework, currently governed by Royal Decree 311/2022 (effective May 2022, with a transition period that ended April 2024). It is a mandatory regulatory requirement — not a voluntary standard — enforced by Spain’s CCN (Centro Criptológico Nacional, part of the CNI intelligence service) and applies to all Spanish public administrations (central, regional, local), as well as private-sector organizations that provide technology services or process data on behalf of the public sector. The ENS defines basic security principles, 16 minimum requirements (covering risk management, access control, incident handling, continuity, personnel security, etc.), and 73 security measures organized in three groups: organizational framework (4 measures), operational framework (31 measures), and protection measures (38 measures). Systems are classified into three categories — Basic, Medium, and High — based on the potential impact of a security incident on each security dimension (confidentiality, integrity, availability, authenticity, traceability). Each category level triggers progressively stricter “reinforcement” requirements for the applicable measures. Organizations with Medium or High systems must obtain formal certification every two years through an ENAC-accredited auditor, while Basic systems require a self-assessment declaration. The ENS is aligned with ISO/IEC 27001 and is being updated to incorporate NIS2 Directive requirements as Spain transposes the directive through its draft Cybersecurity Coordination and Governance Law (approved by the Council of Ministers in January 2025).
Red Hat software is deployed across Spanish public administration and the private-sector technology providers serving it — all of whom must comply with the ENS. Red Hat’s platform maps to ENS requirements across its three measurement groups. For the operational framework (access control, system exploitation, external services, continuity): RHEL provides PAM-based authentication with SSSD integration, SELinux mandatory access control, system-wide cryptographic policies aligned with CCN-STIC guidelines, and OpenSCAP profiles that can scan systems against ENS-derived baselines. For protection measures (encryption, communications security, audit logging, backup): RHEL’s FIPS-capable cryptographic modules, LUKS encryption, auditd subsystem, and Ansible-driven backup automation address ENS requirements at the Base and Reinforced levels. At the platform layer, OpenShift’s Compliance Operator can enforce and continuously validate security profiles, namespace isolation provides the compartmentalization ENS demands for Medium and High systems, and RHACS delivers the intrusion detection and incident response capabilities required by the operational framework. For organizations undergoing ENS certification audits, Red Hat’s compliance tooling generates the documented evidence trail auditors expect — showing that security measures are not just designed but operationally effective over the audit period. Red Hat’s alignment with ISO 27001 (which ENS explicitly references) means customers with dual ISO 27001/ENS requirements can leverage a single Red Hat-based technical implementation to satisfy both frameworks.
