Skip to main content

ENS and MDM: guide for Spanish public sector and suppliers (EN)

What Spain's Esquema Nacional de Seguridad (RD 311/2022) requires for phones and laptops, which controls an MDM supports, and how to pick a vendor.

Julien Ott Julien Ott
10 min read
ENS and MDM: Spain's RD 311/2022 for Mobile Devices

Spain's Esquema Nacional de Seguridad (ENS) never uses the word "MDM", yet several of its measures are very hard to defend in front of an auditor without a mobile device management tool. This guide covers what Real Decreto 311/2022 asks for on laptops, tablets and phones, what an MDM can give you as evidence, and where it stops.

What the ENS is and who it applies to

The ENS (National Security Framework) is the mandatory security framework for information systems in the Spanish public sector. The current version is Real Decreto 311/2022 of 3 May 2022, which replaced Real Decreto 3/2010 and gave existing systems twenty-four months to reach full alignment. That window closed in May 2024.

Article 2 sets the scope, and it's worth reading slowly:

  • The entire public sector as defined by Article 2 of Ley 40/2015: central government, autonomous communities, local entities, public universities and their dependent bodies.
  • Systems handling classified information, with possible additional measures.
  • Private sector entities that, under a contractual relationship, provide services or solutions to public sector entities for the exercise of their powers (Article 2.3). These companies must also have a security policy approved by their highest executive body.

That third point catches many suppliers off guard. If your company builds, hosts or maintains a service for a Spanish city council or ministry, the ENS applies to the information system you deliver that service with, and the tender documents will require it. The phones and laptops your engineers use to reach that system are in scope.

BÁSICA, MEDIA, ALTA: what changes for devices

The ENS doesn't ask the same of everyone. Under Article 40 and Anexo I, each system is categorized as BÁSICA, MEDIA or ALTA depending on the impact an incident would have on five dimensions: confidentiality, integrity, traceability, authenticity and availability. Anexo II then states, measure by measure, what applies in each category and which reinforcements (R1, R2 and so on) get added.

The category also decides how you prove conformity. Article 38 says BÁSICA systems only need a self-assessment to issue their declaration of conformity, while MEDIA and ALTA systems need a certification audit. Article 31 adds a regular audit at least every two years.

Here's how a measure scales. Protection of portable devices [mp.eq.3] applies from BÁSICA upward, but in the ALTA category Anexo II adds reinforcement R1 (disk encryption) and R2 (use outside the premises restricted to protected environments). Our opinion: encrypt everything from BÁSICA. Modern iOS and Android encrypt by default, and Windows and macOS need one BitLocker or FileVault policy.

The Anexo II measures that concern mobiles and endpoints

[mp.eq.3] Protección de dispositivos portátiles is the most direct one. It covers equipment "likely to leave the organization's premises" (the text names laptops and tablets) and asks for four things: an inventory naming the person responsible for each device, a procedure to report losses and thefts, services limited to the bare minimum when the device connects over networks you don't control, and no remote access keys on the device unless they're indispensable.

Next to it, [mp.eq.2] requires the workstation to lock after a period of inactivity, with re-authentication to resume. It applies from the MEDIO level on the authenticity dimension.

In the operational framework, the "explotación" block is where daily work lives. An up-to-date inventory of every system element with its owner [op.exp.1]. Security configuration before a device goes into operation, following the "minimum functionality" and "security by default" rules [op.exp.2]. Continuous management of that configuration [op.exp.3]. Maintenance and security updates, with a procedure to analyze, prioritize and decide when patches get applied [op.exp.4]. Add protection against malicious code [op.exp.6] and activity logging [op.exp.8].

Access control [op.acc] reaches the phone too. Measure [op.acc.6] requires, among other things, disabling credentials when loss is suspected or when the user's relationship with the system ends, and its reinforcement R8 asks for two-factor authentication for access from or through uncontrolled zones. A phone in a coffee shop is exactly that.

Then come the encryption and service measures: encrypted VPNs when traffic leaves the security domain [mp.com.2], cryptography on information media [mp.si.2], information classification [mp.info.2], email protection [mp.s.1] and web browsing protection [mp.s.3].

The CCN-STIC guides on mobile devices

CCN-CERT develops the ENS through its CCN-STIC guides (in Spanish). For mobility, the references are CCN-STIC 827, "Gestión y uso de dispositivos móviles", part of the 800 series dedicated to the ENS and covering both corporate devices and BYOD, CCN-STIC 457 on MDM tools, and CCN-STIC 450 on mobile device security, completed by practical guides per operating system (CCN-STIC 453 for Android, 454 and 455 for iPad and iPhone). One warning: several predate Real Decreto 311/2022. The principles hold, but the numbering that counts is the one in the current Anexo II.

Book a demo

See Appaloosa run on your fleet

A 20-minute call on your real setup. Enrollment, private apps, security.

Book a demo

Table: ENS measures mapped to MDM controls

An MDM doesn't "make you ENS compliant". It enforces specific technical controls and produces evidence for specific measures.

ENS measure (Anexo II)What it asks forMDM control that supports itWhat the MDM doesn't cover
[op.exp.1] and [mp.eq.3.1]Up-to-date inventory, with a named owner per deviceAutomatic inventory of enrolled devices (model, OS version, assigned user) and export for the auditorDevices that aren't enrolled
[op.exp.2] and [op.exp.3]Secure configuration before going into operation, minimum functionality, maintained over timeConfiguration profiles applied at enrollment (zero-touch, Apple Business Manager), restrictions, approved app catalog, compliance reportsDefining the baseline: that decision belongs to your organization
[op.exp.4]A procedure to prioritize and apply security updatesOS version visibility across the fleet, enforced or deferred updatesThe pre-production testing required by reinforcement R1
[mp.eq.2]Lock after inactivity, with re-authenticationPasscode policy and auto-lock timeout
[mp.eq.3.2]Procedure for loss or theftRemote lock and remote wipe, with a record of the actionThe written procedure and the report to the incident service
[mp.eq.3] R1 and [mp.si.2]Storage encryptionEncryption enforcement and status check on every deviceValidating CCN-authorized algorithms and parameters, which depends on the operating system
[op.acc.6]Disable compromised credentials, two factors from uncontrolled zonesConsole SSO through your identity provider, removal of managed accounts and apps when a user leavesThe second factor: it comes from the identity provider, not the MDM
[mp.com.2]Encrypted VPN outside the security domainDistribution of VPN and Wi-Fi configuration and certificatesThe VPN gateway itself
[op.exp.6]Protection against malicious codeBlocking unknown sources, private app store, detection of jailbroken or rooted devicesAntimalware or mobile threat defense, which is a separate product

On BYOD, separation matters for the ENS as much as for GDPR. On Android, the work profile keeps personal data invisible to IT. On iOS, Appaloosa handles BYOD through an enrollment link, with managed apps and accounts. We covered the wider question in how to separate work and personal data on BYOD.

Choosing an MDM in an ENS context (and where Appaloosa stands)

A SaaS MDM console is a cloud service delivered by a third party. Measure [op.nub.1.2] says that when third-party cloud services are used, the information systems supporting them must be ENS conformant or meet the measures set out in a CCN-STIC guide. So picking the vendor is part of your conformity file.

Time to be plain. Appaloosa is not ENS certified. ENS certification isn't granted to a product in the abstract: it applies to a specific information system and, for a supplier, to the service it delivers, with a defined scope and category. If your tender or your security officer requires a supplier holding an ENS certificate of conformity, the only valid source is the registry of certified entities maintained by the CCN, reachable from the ENS portal. Don't trust a badge on a vendor website.

What Appaloosa does bring is a different kind of assurance: a European vendor (a French company), hosting in France on infrastructure qualified SecNumCloud by ANSSI, and EU data residency. SecNumCloud is a French framework and is not equivalent to the ENS. Whether that assurance is enough for your system's category is for your organization to judge in its risk analysis.

A checklist for any MDM, ours included:

  1. Supplier conformity. Is the vendor in the CCN registry? With which scope, in which category? A BÁSICA certificate doesn't help an ALTA system.
  2. Hosting location. Country, infrastructure provider, and that infrastructure's certifications or qualifications, with the document in hand.
  3. Data residency and jurisdiction. Data in the EU, and exposure to non-EU legislation. A public sector fleet inventory holds personal data, so read our guide on GDPR compliance with MDM too.
  4. Audit evidence. Inventory export, per-device compliance reports, history of administrator actions.
  5. Console access. SSO with your identity provider (Microsoft 365, Google Workspace, Okta) so the console inherits your second factor, plus separated admin roles.
  6. Contract terms. Service levels (the subject of [op.ext.1]), incident notification and reversibility.
  7. Platform coverage. iOS, iPadOS, Android, Windows and macOS in one console. Two tools mean two inventories and twice the evidence to reconcile.

Recommended rollout sequence

Order matters more than speed. This sequence suits mid-sized administrations and suppliers.

  1. Categorize the system and draw the scope. Which devices reach information in the ENS system? The others can wait.
  2. Write the mobile device usage policy, using CCN-STIC 827 as a base: ownership, BYOD allowed or not, authorized uses.
  3. Define the configuration baseline per platform: passcode, auto-lock, encryption, minimum OS version, allowed apps.
  4. Make enrollment mandatory. Zero-touch and Samsung Knox Mobile Enrollment on Android, Apple Business Manager on Apple. A device that arrives enrolled never gets forgotten.
  5. Turn policies on for a pilot group of 20 to 30 users for two weeks before going wide.
  6. Connect the MDM to your incident process: who locks or wipes a lost device, how fast, and where it's recorded.
  7. Prepare the evidence. Archive a monthly inventory export and compliance report.

The same logic applies to other European frameworks, which we covered in NIS2, DORA and MDM compliance. The Appaloosa mobile device management page lists the available features. Pricing is public: from 3.49 EUR per device per month, with a 14-day free trial. To walk through the table above with your own fleet, book a demo.

This article is for information only and is not legal advice. For the interpretation that applies to your system, consult your security officer and the official text published in the BOE.

FAQ

Does the ENS require an MDM?

No. Spain's Real Decreto 311/2022 doesn't name any MDM tool. Its Anexo II does require an inventory of portable devices with a responsible person [mp.eq.3], a security configuration applied before devices go into operation [op.exp.2] and a security update procedure [op.exp.4]. Beyond a few dozen devices, an MDM is the most realistic way to apply those controls and prove it to an auditor.

Does the ENS apply to private companies?

Yes, in one specific case. Article 2.3 of Real Decreto 311/2022 extends the ENS to the information systems of private sector entities that, under a contractual relationship, provide services or solutions to Spanish public sector entities for the exercise of their powers. Those companies must also have a security policy approved by their highest executive body.

Is Appaloosa ENS certified?

No. Appaloosa does not hold an ENS certificate of conformity. ENS certification applies to an information system and to a supplier's service, with a defined scope and category, and the registry of certified entities is maintained by Spain's CCN. Appaloosa offers a different assurance: hosting in France on infrastructure qualified SecNumCloud by ANSSI, and EU data residency.

Which ENS measures apply to phones and tablets?

The main one is [mp.eq.3], protection of portable devices, in Anexo II of Real Decreto 311/2022: an inventory with a responsible person, a loss or theft procedure, limited access from uncontrolled networks and, in the ALTA category, disk encryption. Workstation lock [mp.eq.2], asset inventory [op.exp.1], security configuration [op.exp.2 and op.exp.3], security updates [op.exp.4] and access control [op.acc.6], which asks for two factors from uncontrolled zones, also apply.

Ready to try Appaloosa? Start free

Ready to deploy MDM?

Get started today with unrestricted access to our platform and help from our product experts.

Get Started

Alternatively, contact sales.

Free 14-day trial
Cancel anytime, no questions asked.
Expert Support
Get customized and expert onboarding to get started.