Royal Decree 311/2022, of 3 May, regulates Spain’s National Security Framework (Esquema Nacional de Seguridad, ENS) and set a twenty-four-month window for pre-existing systems to reach full conformity. That window closed in May 2024. ENS conformity stopped being a horizon and became an enforceable state, verifiable through audit for systems in the medium and high categories.
Within that framework, staff awareness and training are not an optional extra. The ENS lists them as security measures with their own name and number, and treats them like any technical control: they have to be applied, and they have to be demonstrable.
This piece does not explain what e-government is or how the ENS is implemented end to end. It assumes that ground is covered. It focuses on something narrower: what the National Security Framework requires on staff awareness and training, how that requirement scales with the system’s category, and what evidence an entity has to be able to put on the table once the auditor starts asking.
Who is bound by the National Security Framework?
The National Security Framework is the framework that sets the security policy for the use of electronic means by Spanish public-sector entities. It binds the whole administration, whether central, regional or local, and the public-law bodies linked to or dependent on it.
The relevant boundary for the private sector lies in the supply chain. Royal Decree 311/2022 extends its scope to private entities when they provide services or supply solutions to public bodies for the exercise of their competences. In practice, that obligation enters through procurement clauses: a technology provider that wants to work with a public administration has to demonstrate ENS conformity for the part of its systems that supports the service. The obligation stops being a public-sector matter alone and reaches its ecosystem of providers.
What does the ENS require on awareness and training?
The ENS separates two measures within the personnel management group of Annex II. Measure mp.per.3, «Awareness», requires keeping staff alert to their role in information security through periodic reminders and awareness actions. Measure mp.per.4, «Training», requires regular training for all staff in the subjects they need to perform their role securely, proportional to that role.
The distinction is not cosmetic. Raising awareness means sustaining attention on risks day to day; training means giving each person the concrete knowledge their position requires. The ENS asks for both, and it asks for them continuously, not as a single event at onboarding.
The decree reinforces this from its first additional provision, which tasks the National Cryptologic Centre (CCN) and the National Institute of Public Administration (INAP) with developing awareness and training programmes for public-sector staff. The rule does not just require the activity; it recognizes that sustaining it needs a programme behind it.
Requirements scale with the system’s category
The ENS does not apply a single yardstick. It classifies each system into one of three security categories, basic, medium or high, according to the impact an incident would have on the dimensions of confidentiality, integrity, traceability, authenticity and availability. The higher the category, the stricter the measures and, with them, the expected depth of the awareness and training programme.
| Category | How conformity is accredited | Requirement on staff |
|---|---|---|
| Basic | Self-assessment and declaration of conformity | Awareness and training proportional to the role |
| Medium | Certification audit | Greater formalization and traceability of the programme |
| High | Certification audit | Reinforced programme, reviewed and evidenced in depth |
The most important operational difference lies in how it is verified. Systems in the medium or high category need an audit to certify their conformity; in the basic category, a self-assessment with a declaration of conformity is enough. For anyone running a medium- or high-category system, that means awareness will have to withstand the scrutiny of a third party that asks for proof, not just internal goodwill.
The gap between the stated policy and actual behaviour
The point where most programmes break is not a lack of activity but the gap between what the policy states and what staff actually do. An entity can have an impeccable security policy approved, an annual course and a sign-in sheet, and still be unable to demonstrate that the training changed anything in everyday conduct.
That is where an ENS audit finds the critical point. The auditor does not assess good intentions; it contrasts declared knowledge with actual behaviour. A programme that only accredits attendance answers the wrong question. The question that matters is whether staff recognize a phishing attempt when it is in front of them, whether they know who to report an incident to, and whether that reaction improves over time. That is the ground the ENS shares with other frameworks, as we broke down when analysing control 6.3 of ISO 27001:2022 and the awareness requirements of the NIS2 Directive.
How is compliance evidenced in an ENS audit?
For measures mp.per.3 and mp.per.4, the evidence that supports conformity usually rests on these elements:
- A record of who received awareness and training, when and on what, covering the whole workforce.
- Content tied to the entity’s policies and to the real risks of each role, not a generic syllabus.
- Defined, sustained periodicity, with reminders and awareness actions throughout the year.
- Proof of comprehension and behaviour, such as assessments or simulation results, that goes beyond attendance.
- Traceability proportional to the system’s category, stricter in medium and high.
The fragile point is almost always the same: the entity has the activity but not the trail in order on the day the auditor asks for it. Designing the programme from the start around what data will be recorded is what separates complying from being able to prove it.
SMARTFENSE, as a security awareness platform with presence in Spain and Latin America, is built around that idea. Every awareness action, every piece of content delivered, every phishing simulation and every assessment is recorded and available as evidence, so the responsible team does not have to rebuild the trail by hand before an ENS audit. You can see how it comes together in the SMARTFENSE security awareness platform.
The adaptation deadline has passed, and with it ended the room to treat awareness as internal communication. The ENS set it as a security measure with evidence attached, and the scale of that evidence grows with the system’s category. What decides an audit is not how many training hours were delivered, but what trail the entity can show that its staff act differently.
Leave a Reply