Skip to main content

Public-Sector

ENS (Esquema Nacional de Seguridad)

The Esquema Nacional de Seguridad (ENS) is Spain’s national security framework, currently governed by Royal Decree 311/2022 (effective May 2022, with a transition period that ended April 2024). It is a mandatory regulatory requirement — not a voluntary standard — enforced by Spain’s CCN (Centro Criptológico Nacional, part of the CNI intelligence service) and applies to all Spanish public administrations (central, regional, local), as well as private-sector organizations that provide technology services or process data on behalf of the public sector. The ENS defines basic security principles, 16 minimum requirements (covering risk management, access control, incident handling, continuity, personnel security, etc.), and 73 security measures organized in three groups: organizational framework (4 measures), operational framework (31 measures), and protection measures (38 measures). Systems are classified into three categories — Basic, Medium, and High — based on the potential impact of a security incident on each security dimension (confidentiality, integrity, availability, authenticity, traceability). Each category level triggers progressively stricter “reinforcement” requirements for the applicable measures. Organizations with Medium or High systems must obtain formal certification every two years through an ENAC-accredited auditor, while Basic systems require a self-assessment declaration. The ENS is aligned with ISO/IEC 27001 and is being updated to incorporate NIS2 Directive requirements as Spain transposes the directive through its draft Cybersecurity Coordination and Governance Law (approved by the Council of Ministers in January 2025).

E-ITS / ISKE (Estonian Information Security Standard)

E-ITS (Eesti infoturbestandard — Estonian Information Security Standard) is Estonia’s national information security framework, developed and maintained by the RIA (Riigi Infosüsteemi Amet — Information System Authority). It replaced the previous ISKE (Infosüsteemide kolmeastmeline etalonturbe süsteem) system, which was in effect until 31 December 2022. E-ITS entered into force in December 2022 and is mandatory for all organizations performing public duties in Estonia — state agencies, local governments, and any entity operating information systems essential for the functioning of society. Private organizations may also voluntarily adopt E-ITS to achieve their information security goals. The standard is based on the German BSI IT-Grundschutz baseline protection methodology and is designed to be fully compatible with ISO/IEC 27001 — an audited E-ITS conformity allows organizations to demonstrate compliance equivalent to the international standard. E-ITS presents a baseline protection catalog containing security modules with specific measures, organized by asset type (IT systems, networks, applications, industrial automation, vehicles, etc.). Organizations must identify their assets, determine protection needs, apply the corresponding baseline measures, and undergo periodic audits. Alternatively, organizations may satisfy their obligation by holding a valid ISO/IEC 27001 certificate and submitting it to RIA. The standard is updated annually each autumn to reflect new threats and technological developments, and RIA provides a free support application (based on the 2024 version) to guide implementers through the process.