Esquema Nacional de Seguridad (Real Decreto 311/2022)

Spain's mandatory security framework for the public sector and the companies that supply it. Public bodies in Spain and any supplier providing them with ICT services.

14 controls supported. References are measures from Annex II of RD 311/2022.

Our services support these controls and produce evidence for them. Certification depends on your whole management system and is granted by an accredited auditor, not by a supplier.

  • Control
    • op.cont.2Continuity plan
    • op.cont.3Periodic continuity tests
    • op.cont.4Alternative means
    How we help
    Provides the alternative means of processing your continuity plan relies on, and the periodic failover tests the plan has to include.
    Evidence you get
    Continuity architecture document, failover test reports with dates and results.
  • Mapping under review

    Control
    • mp.info.6Backups
    How we help
    Off-site, encrypted and immutable copies that can be restored when the original data is lost or encrypted by ransomware.
    Evidence you get
    Backup scope and retention configuration, restore test records.
  • Mapping under review

    Control
    • op.cont.2Continuity plan
    • op.cont.4Alternative means
    • mp.s.4Denial-of-service protection
    How we help
    On the Enterprise plan, a second authoritative DNS network is an alternative means for a service every application depends on, and keeps your domains resolving if one provider is under a denial-of-service attack or has an outage.
    Evidence you get
    NS delegation showing both networks (Enterprise), failover configuration, health-check and failover event history.
  • Mapping under review

    Control
    • op.exp.8Activity logging
    • op.mon.3Surveillance
    How we help
    Records user and system activity at the edge and feeds continuous monitoring.
    Evidence you get
    Log retention configuration and sample activity reports.
  • Mapping under review

    Control
    • mp.s.2Protection of web services and applications
    • mp.s.4Denial-of-service protection
    • op.mon.1Intrusion detection
    How we help
    Protects web services and applications, mitigates denial-of-service attacks and detects intrusion attempts.
    Evidence you get
    Security configuration export and monthly threat reports.
  • Control
    • op.acc.2Access requirements
    • op.acc.4Access rights management
    • op.acc.6Authentication of internal users
    • mp.s.3Web browsing protection
    • mp.com.1Secure perimeter
    How we help
    Identity-based access to each application, strong authentication, web browsing protection and a secure perimeter without VPNs.
    Evidence you get
    Access and Gateway policy exports, authentication logs.

Tell us what you are preparing for

We reply with the controls we can cover, what stays on your side, and a realistic timeline.

Where are you now?