BOE/ENS

Royal Decree 311/2022: what the National Security Scheme requires

Keys to the ENS published in the BOE for companies that work with the Public Administration or want to prepare for tenders.

Regulatory newsReading: 4 minLinked official source

· Editorial review: Blue Moon Cybertech

Royal Decree 311/2022 regulates the National Security Scheme and is a key reference for systems linked to the Spanish public sector.

Many private companies find it in specifications, contracts or requirements of public clients, especially if they provide ICT, cloud, support or development services.

ENS can be worked together with ISO 27001 to reuse inventory, risks, controls, evidence and continuous improvement.

What a company should review

  • Categorize systems into Basic, Medium or High.
  • Define organizational, operational and protection measures.
  • Prepare declaration or certification of conformity when applicable.
  • Maintain evidence and periodic reviews.

How we work at Blue Moon

The practical recommendation is not to approach each standard as an isolated folder. ISO 27001, ENS, NIS2, DORA, data protection and secure development share assets, risks, controls, suppliers, incidents and evidence.

Next step

We can review whether this rule affects your company and turn it into a clear, prioritized and acceptable roadmap.

Request diagnosis →