Document control
Versions, approvals and distribution with read receipts.
Software for ENS
Security measures under Spain's National Security Framework for public-sector services and systems, with evidence ready for the two-yearly audit.
The Spanish National Security Framework (ENS) is mandatory for the Spanish public sector and for private entities that provide services to it. Its current regulation is Royal Decree 311/2022, which repealed RD 3/2010 and aligned the framework with the European landscape. It classifies systems into three categories — basic, medium and high — according to the impact of an incident on the security dimensions, and organises the Annex II measures into organisational framework, operational framework and protection measures.
Versions, approvals and distribution with read receipts.
Publish and version documents by connecting to OneDrive, Google Drive or SharePoint, without duplicating folders.
Annual program, checklists per standard, findings linked to actions.
Root cause, action, owner, deadline and effectiveness check.
Process objectives fed with real operating data.
A register of legal and other requirements, with validity and compliance evaluation per standard.
Root cause, action, owner, deadline and effectiveness check, all linked to the nonconformity.
Improvement opportunities with an owner and tracking, beyond just fixing what already failed.
A pre-built report with indicators, audits and nonconformities, ready for the meeting.
Risk analysis according to the categorization level.
Compliance statement and evidence always ready.
Organizational, operational and protective measures with an owner.
Security incidents classified and reported under the ENS.
Requirements covered
Standards covered
Frequently asked questions
The edition in force is Royal Decree 311/2022, of 3 May. When the issuing body publishes a new one, a transition period opens; once it closes, certificates issued against the previous edition stop being valid.
Yes. Your existing system — processes, documents, records, audit history — is loaded in and kept alive from day one. Nothing needs redesigning and the certification cycle does not restart.
Yes, provided they are traceable, controlled and able to show who did what and when. No standard requires paper; every standard requires reliable evidence, and a properly controlled electronic record provides it better than a folder.
Yes, and that is the sensible route. The common Annex SL structure lets a single integrated system share the process map, document control, internal audits, nonconformities and indicators between ENS and the rest, leaving only the standard-specific parts separate.
It depends on the starting point. An organisation already working with written procedures is usually ready in two or three months; one starting from scratch needs longer. The bottleneck is rarely the tool — it is the availability of the people who know the processes.
It is migrated. Existing procedures, forms and records are loaded with their version and approver, so the history is not lost and the system starts with the memory the organisation already had.
Yes. They are given read-only access with a defined scope and an expiry date. It is more comfortable for both sides than preparing a folder of screenshots and exports.
A major one compromises the system's ability to meet a requirement — a required process missing altogether, systematic failure, or a failure affecting the product — and usually blocks certification until it is closed. A minor one is a specific lapse resolved with an action plan.
Yes, from the data the processes themselves generate. That is the difference between a dashboard that reflects what is happening and a spreadsheet somebody fills in the week before the management review.
Yes. The model is multi-company and multi-site: what makes sense to share is shared, and what belongs to each location stays separate — including the certificate scope where it differs.
We'll show you the module running with data similar to yours.
Keep exploring
Free learning path on the National Security Framework (ENS): categorization, organizational and operational…
No clouds outside the European Union and no surprises in the data processing agreement. You know where your…
Living documentation, planned audits, non-conformities with an owner, and indicators that calculate…
Register the legal requirements that apply to you, get an alert when the regulation changes, and…
Sources
References to the official text in force. If a standard is revised, this page is updated and the review date says so.
Kimobox is a software for ENS that digitizes the requirements of the standard: system categorization and risk analysis, organizational, operational and protective security measures, security policy and assigned roles, security incident management, with full traceability and evidence ready for the auditor.
The platform lets you run an integrated management system that combines ENS with other ISO standards and sector protocols, sharing the process map, document control, internal audits, non-conformities and KPIs.