Our own servers in Europe · GDPR · Support in your language

Module 5 of 5 · ENS · Block 5

Audit and conformity certification

Medium- and high-category systems require a periodic audit that verifies compliance with the ENS.

Content reviewed on

Audit scope and frequency

Defining the scope of the audited system and the frequency required by category (every two years as a general rule).

Audit report

A document covering the level of compliance for each applicable security measure, with recommendations.

Declaration or certification of conformity

Issuing the declaration (basic level) or certification (medium/high level) of ENS conformity.

What an auditor usually asks for

  • Audit scope defined
  • Compliance evidence organized by measure
  • Audit report with findings and action plan
  • Current declaration or certificate of conformity

How to cover this block in Kimobox

  1. 1Organize evidence for each security measure in Kimobox's document manager.
  2. 2Log audit findings as nonconformities with their action plan.
  3. 3Keep the declaration or certificate of conformity as a controlled document.

Evidence for each security measure stays organized and ready for the conformity audit.

See audit and certificate management in Kimobox

Where each figure comes from

References to the official text in force. If a standard is revised, this page is updated and the review date says so.

  1. Royal Decree 311/2022 regulating the National Security Framework BOE-A-2022-7191 · 4 May 2022
  2. National Cryptologic Centre — CCN-STIC guides CCN-CERT · ENS guide series
  3. Directive (EU) 2022/2555 (NIS2) EUR-Lex · Transposition deadline: 17 October 2024