Security documentation is usually born of necessity: a tender demanding conformity with Spain's National Security Framework (ENS), a NIS2-regulated client sending a sixty-question questionnaire, an audit by an industrial partner. In a rush, the temptation is to fill in a generic template, and it shows at once: procedures citing a server that does not exist, roles assigned to people who have left and rules nobody in the company could follow. We write yours from interviews with management, IT and HR and from what we see in your systems, so each document describes what really happens or what could start happening tomorrow without heroics. It helps you prepare for ENS certification, answer a demanding client and, above all, give the organisation clear rules instead of habits.
What goes in depends on the purpose: ENS conformity at basic or medium category, requirements from a client subject to NIS2 or DORA, the terms of a public tender, or simply writing down how a small town council does things.
The main document, approved by management or, in a local authority, by its governing body: what is protected, against what, which roles are involved (information, service, security and system owners, as the ENS requires) and who answers for each area.
Risk analysis
A readable table of threats and consequences, using MAGERIT as the reference method where the ENS applies. It produces the measures you must have and the ones you deliberately set aside, each with a written reason.
Statement of applicability
For the ENS, the list of Annex II measures that apply to your category, which are in place and which are replaced by compensating measures. It is the first document an auditor opens.
Operating procedures
Access management, passwords and multi-factor authentication, remote work in line with Law 10/2021 and your remote-work agreement, personal devices, backups, suppliers and incident handling, with the reporting route to INCIBE-CERT or CCN-CERT as appropriate.
Rules for staff
One or two pages in plain language. Nobody reads thirty pages about passwords; two pages with examples from their own working day stick.
Records and evidence
Templates for the incident log, periodic permission reviews and training records. These are often what the auditor really asks for, more than the policy itself.
How the engagement unfolds, one stage at a time
A procedure passes the test if it can be followed on an ordinary Tuesday. A rule that fights real work gets bypassed within a week.
01
Interviews
Video calls with management, the IT lead and HR about how a new starter arrives, how access is granted, how suppliers are handled and what happens when something breaks.
02
Drafting
We write the texts and go through them with you line by line, so no rule is impossible to keep with the resources you have.
03
Approval and rollout
Management signs off, staff attend a short online session and read receipts are filed with date and version number.
04
Upkeep
The annual review goes into the calendar and documents are updated whenever systems or the organisation change.
An ENS auditor reads the policy in ten minutes and then spends an hour asking for evidence. Minutes of permission reviews, the incident log, training records, the date of the last restore test. So every procedure we write states what evidence it produces, who keeps it and where, turning the audit into a matter of opening folders rather than piecing events together from memory.
Common questions
For a thirty-person SME, the policy fits in four or five pages, the risk analysis in a single table and each procedure in one or two. Volume grows with the ENS category or with client demands, not out of habit. A short document that gets read is worth more than a long one nobody opens.
Not by itself, and nobody can honestly promise that: both certificates are issued by an accredited body after an audit. We work to the principles of ISO 27001 and help you prepare for ENS certification, so you reach the audit with documents and evidence in order.
Yes. A small local authority has few technical staff, often relies on support from the provincial council and carries obligations under the ENS, the GDPR and its e-government portal (sede electrónica). We write short documents a small team can apply and match the system category to the services actually delivered: registry, census, local taxes. If the provincial council already provides shared services, we coordinate with it.
Management or, in a local authority, the relevant governing body. The ENS also requires named owners for information, service, security and system, which in a small organisation can fall to just a few people provided security and system operation are not in the same hands. We help you share out those roles realistically.
Hours Monday to Friday, 9:00-18:00 Spanish time (CET), answers within a working day
Meetings Video calls via Google Meet or Teams
Your request is with us
Expect an answer within one working day. A reported fault that has halted your team is handled first.
We clarify the brief. If a detail is missing before we can price the work, we email you or suggest a quick Google Meet or Teams session.
We draft a proposal. The scope of work, a price in euros with VAT shown separately and a realistic start date, with no small print.
The choice is yours. The proposal arrives by email. Read it at leisure, query any line you like and only then decide.
Choose a location
No match found. Try another spelling, or go with the closest provincial capital: every job is done remotely, so the location makes no difference to what we deliver anywhere in Spain.
This site only stores the cookies it needs to work and to remember your chosen city. No advertising or tracking cookies are set. See our privacy policy for the details.