Skip to main content
Cloud Fortress, por Cloud y Olé
Capability

ENS compliance with the evidence always ready

Spain's National Security Framework is not passed the week before the audit. Cloud Fortress attaches every control to what the platform actually does, so the compliance status is alive on any day of the year.

What it is

What the ENS is and why it affects you

The Esquema Nacional de Seguridad (ENS, Spain's National Security Framework) sets the cybersecurity requirements for the Spanish public sector and for the companies that supply it. Regulated by Royal Decree 311/2022, it classifies systems into three categories —basic, medium and high— and requires a set of security measures proportionate to that category, plus a periodic audit to verify them.

The challenge is rarely complying: it is proving that you comply. Many teams run the ENS on spreadsheets updated by hand and only looked at when the audit approaches. The result is an enormous effort every cycle to rebuild evidence that the system was, in fact, already generating day by day.

How Cloud Fortress does it

From control to evidence, automatically

Cloud Fortress attaches each ENS control to the platform's real activity. The live inventory, vulnerability management with tracking and the incident record are not separate modules: they are, at the same time, the proof that the control works. The compliance status stops being an annual snapshot and becomes a panel you can open any day.

The ENS on a spreadsheetThe ENS in Cloud Fortress
Evidence rebuilt before every auditLiving evidence, generated by daily operations
«How are we doing?» is only known at the endCoverage per control, at any moment
The paper inventory does not match realityThe same real inventory feeds the control
Frequently asked questions

Frequently asked questions

  • Does Cloud Fortress issue the ENS certification?

    No. Conformity is declared or certified by an accredited body, depending on the category. Cloud Fortress gets you to that appointment with everything prepared.

  • Does it also work for ISO 27001, NIS2 or DORA?

    Yes. The manager works with several frameworks in the same platform —ENS, ISO 27001, NIS2, DORA and GDPR—, each with its controls, its owner and its progress. Many controls are shared and the evidence is reused instead of redone.

  • Which ENS categories does it cover?

    The three in Royal Decree 311/2022: basic, medium and high. The category determines which measures are required, and the manager tracks the status of each control in whichever one applies to your systems.

  • How is evidence submitted and kept?

    It is uploaded to the control it supports and stays in its thread, alongside every status change and every reassignment of owner, dated and attributed. The control's history is the audit trail: there is nothing to rebuild in a separate spreadsheet when the auditor arrives.

  • Who exactly does the ENS apply to?

    The Spanish public sector and the companies that provide services to it — which is the part that catches many people out: if you supply a public administration, it applies to you. It is high-value ground and many teams still run it on spreadsheets.

See it running with your data in front of you

30 minutes with a scenario close to yours. No canned deck, no strings attached.