GRC Consulting
We advise organisations on compliance with cybersecurity regulatory frameworks in Spain: ENS, NIS2 and ISO 27001. No intermediaries — senior CISO expertise applied directly.
National Security Framework (ENS)
Royal Decree 311/2022 — mandatory for public administrations and their suppliers
Who it applies to
The ENS is mandatory for all Spanish public administrations and private suppliers that handle public administration information systems or provide technology services to public entities.
This includes local councils, county councils, provincial governments, regional bodies and any company wishing to contract with the administration in ICT areas.
Security levels
- Basic — systems with limited impact in case of compromise
- Medium — systems with considerable impact
- High — systems with serious or very serious impact
The level is determined by the risk analysis across the security dimensions of each system (confidentiality, integrity, availability, authenticity and traceability).
Our process
- GAP analysis — review of the current state against the 73 ENS framework controls
- Categorisation — determination of the security level of systems
- Adequacy plan — prioritised measures to achieve compliance within the established timeframe
- Implementation — support in deploying technical and organisational measures
- Statement of applicability — document recording applied measures and justification for excluded ones
- Audit preparation — pre-audit review and support throughout the certification or conformity process
NIS2 Directive
EU Directive 2022/2555 — being transposed in Spain, in force from 2026
Who it applies to
NIS2 affects essential and important entities in the sectors listed in Annexes I and II of the Directive: energy, transport, banking, digital infrastructure, healthcare, food, manufacturing, digital services and others.
The size criterion is key: organisations with 50 or more employees or turnover exceeding €10M operating in listed sectors. Public administrations are included regardless of size.
Penalties
- Essential entity: up to €10M or 2% of annual global turnover
- Important entity: up to €7M or 1.4% of annual global turnover
- Personal liability for management bodies in case of repeated non-compliance
Our process
- Applicability assessment — we determine whether your organisation is an essential or important entity, or falls outside scope
- Gap analysis — review of the 10 mandatory measures under Art. 21 of the Directive
- Measures plan — prioritised actions with owners and deadlines
- Implementation — technical and organisational support in deployment
- Notification and registration — support in registering as an affected entity with the competent authority
- Ongoing review — NIS2 is not a one-off project, it is a permanent management obligation
ISO 27001
International standard for information security management systems (ISMS)
Who it applies to
ISO 27001 is not required by law, but is increasingly demanded by corporate clients, in public tenders and as a supply chain requirement.
Any organisation, regardless of size or sector, can implement an ISMS and obtain certification from an accredited body. Certification demonstrates that security management is systematic, audited and continuously improved.
For SMEs
The standard allows you to scale scope: you can certify a specific service, a system or the entire organisation. There is no need to do it all at once.
Our process
- GAP analysis — review of the current state against Annex A controls of ISO 27001:2022
- Scope definition — delimitation of the ISMS: systems, processes and assets included
- Risk analysis — identification, assessment and treatment of security risks
- Statement of applicability (SoA) — document justifying the inclusion or exclusion of each control
- Control implementation — technical and organisational measures from the treatment plan
- Internal audit — pre-certification review to detect gaps
- Certification audit support — accompaniment during the certification body's audit
First conversation at no cost
Tell us your situation: whether you have a pending audit, a tender that requires it, or simply want to know where to start. In 30 minutes we will give you clear guidance.
Let's talk