Skip to content
    Back to Regulatory Radar
    ImportantNew RegulationMay 4, 2022

    Spain Royal Decree 311/2022 Updates ENS Framework

    Spain published Royal Decree 311/2022, replacing the previous Royal Decree 3/2010 that established the Esquema Nacional de Seguridad (ENS). The updated framework modernizes security requirements for Spain's public sector and any private organizations providing services to government entities. Key changes include alignment with the EU NIS Directive (2016/1148) as transposed into Spanish law, new specific compliance profiles, provisions for cloud services and supply chain security, and a 24-month transition period for pre-existing systems that ended May 5, 2024.

    ENSSaaSDefense

    Key Analytics

    May 4, 2022
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    1
    Frameworks Affected

    Impact Analysis

    Cloud service providers operating in Spain's public sector were required to recertify under the new ENS framework, which introduced more stringent requirements for supply chain risk management and incident notification. The 24-month transition period ended May 5, 2024; certificates issued against Royal Decree 3/2010 are no longer valid, and all new and renewed ENS certifications are issued against Royal Decree 311/2022. International organizations seeking to serve Spanish government clients must demonstrate compliance with the current framework, whose controls align with EU-wide cybersecurity expectations.

    Recommended Actions

    • Confirm any existing ENS certification was issued against Royal Decree 311/2022; certificates under the prior Royal Decree 3/2010 expired May 5, 2024
    • Map Royal Decree 311/2022 control requirements against your current scope, including the specific compliance profiles relevant to your service category
    • Update incident response procedures to meet ENS notification requirements and integrate with Spain's CCN-CERT reporting channels

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Significant85-170 hours
    Key Workstreams
    • Mapping of existing controls to Royal Decree 311/2022 requirements and the applicable compliance profile
    • Remediation of supply chain risk management and incident notification gaps
    • CCN-CERT reporting channel integration into existing incident procedures

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowSignificant · 85-170 hours
    Start cold under pressureMajor · 200-450 hours

    Roughly 115 to 280 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.