The CCN's ENS Navegable: what it is and how to consult it

·

The ENS Navegable is the CCN's tool for consulting Royal Decree 311/2022 measure by measure, without reading the full BOE. It lives on the National Cybersecurity Governance platform (ens.ccn.cni.es and gobernanza.ccn-cert.cni.es/ens-navegable): the regulatory lookup is publicly accessible, but the threat identifier and GRC functions require prior registration. It does not replace the Royal Decree as the legal source, and it does not certify or audit systems.

Information security concept on a computer

The ENS Navegable ("navigable ENS") is the tool built by Spain's National Cryptologic Centre (CCN) that lets you consult the National Security Framework (ENS) article by article, measure by measure, without reading the entire Royal Decree 311/2022 every time a question comes up. It lives inside the CCN's National Cybersecurity Governance platform, at ens.ccn.cni.es, and it is not the same thing as PILAR, INES or AMPARO: those are tools for executing the compliance process; the navigable tool is the entry point for understanding what the law requires before touching any of them.

What is the ENS Navegable and who maintains it?

The ENS Navegable is a CCN development that reorganises the content of Royal Decree 311/2022, of 3 May (BOE-A-2022-7191) into a browsable format: instead of scrolling through a PDF hundreds of pages long, you select a security dimension, a category or a family of measures and get the exact fragment of the regulation that applies to you. It belongs to the same family as the CCN-STIC 800-series guides, but with one key difference: it does not replace the Official State Gazette (BOE) as the legal source, it just makes it easier to consult. If you need to cite the ENS in a public tender, in a Statement of Applicability or before an auditor, the citation is still Royal Decree 311/2022; the navigable tool is where you go first to understand what you need to cite.

If what you are after is not consulting the regulation yourself but having someone interpret the navigable tool for you and turn it into a work plan, our ENS technical implementation service starts from exactly the same measures the navigable tool organises, with the interpretation work already done.

Where it is and how it differs from reading Royal Decree 311/2022 directly on the BOE

The navigable tool lives at ens.ccn.cni.es, the CCN's informational ENS portal, with sections for Home, What is the ENS, Certification, Regulations, Conformity, Local Entities and Training. The difference from the BOE is not in the content — the legal text is the same — but in how you access it. The BOE presents the Royal Decree as a linear document: you read the articles, then Annex I (categories), then Annex II (measures), and cross-reference them yourself. The navigable tool has already done that cross-referencing: when you look up a measure, it shows you directly which categories it applies to and at what reinforcement level, without you having to hunt through the Annex II table on your own.

This does not turn the navigable tool into an alternative legal source. If there is ever a discrepancy between what the tool shows and the text of Royal Decree 311/2022 published in the BOE, the BOE prevails. It is a difference of form, not of substance, but it is worth being clear about before citing the navigable tool as if it were the regulation itself.

What can you consult: basic principles, minimum requirements and measures by category or dimension

The navigation structure mirrors the ENS's own architecture: the basic principles of Article 5, the minimum security requirements of Chapter III and, above all, the Annex II measures organised by category (basic, medium, high) and by security dimension (confidentiality, integrity, traceability, authenticity, availability). Before filtering by category it is worth knowing how many of those 73 measures will actually apply to you: we already covered that here (available in Spanish), and it is a figure worth having to hand before opening the navigable tool, so you do not waste time reviewing sheets that do not apply to you. The navigable tool organises the same 73 measures in Annex II that we already broke down in our Annex II guide, grouped into the three frameworks — organisational, operational and protective — with the reinforcement level (R1, R2, R3…) that applies to each one depending on the system's category.

For anyone who already knows which family of measures they need to review — for example, the ones covering op.mon (surveillance, metrics system, intrusion detection) — the navigable tool lets you jump straight to that sheet instead of searching the full table. Those op.mon.1 to op.mon.3 sheets connect with monitoring, logs and observability, the real technical foundation that family of measures rests on: the navigable tool tells you what the regulation requires, but building a monitoring system that actually complies is a separate technical project.

How to use it step by step (finding a specific measure, filtering by category)

The usual consultation flow looks like this:

  1. Confirm your category first. The navigable tool filters by BASIC, MEDIUM or HIGH category, but it does not tell you which one is yours: that depends on the impact assessment of your system across the five security dimensions, as we explain step by step in this guide (available in Spanish). Consulting the navigable tool without knowing your category means reading a list of measures you do not know apply to you.
  2. Select the category or family of measures you want to review (organisational, operational or protective, and within each, the specific family: op.acc, op.mon, mp.com…).
  3. Read the full measure sheet, not just its code. Annex II itself includes nuances — reinforcements conditional on remote access existing, on the data being especially sensitive, on the service being critical — that only show up if you open the entire sheet. A real example of why this matters: the user authentication sheet spawned, for a while, the myth that two-factor authentication is mandatory for everyone at basic category (available in Spanish), when in reality the reinforcement depends on whether access happens from an uncontrolled zone.
  4. Cross-reference the measure with your real system. The navigable tool tells you what the regulation requires in the abstract; deciding how that requirement translates into your specific infrastructure requires technical judgement, not just reading.

A common mistake in this flow is stopping at step 3 and taking a single, isolated sheet as the final word, without checking whether that measure relates to others in the same family. Annex II is designed as a whole: an access control measure rarely stands on its own without the corresponding activity-logging measure, for example. The navigable tool makes it easy to jump from one sheet to another within the same family precisely to avoid that fragmented reading.

The threat identifier and the GRC functions: what they are for and what they do NOT replace

The National Cybersecurity Governance platform, at gobernanza.ccn-cert.cni.es/ens-navegable, adds on top of the basic navigable tool a threat identifier and governance, risk and compliance (GRC) functions designed for an organisation to manage its compliance process on an ongoing basis: tracking implemented measures, linking specific threats to the measures that mitigate them, and status dashboards for the process. These are management functions, not pure regulatory lookup, and they do not replace the formal risk analysis using the MAGERIT methodology that the Royal Decree itself requires: they are a monitoring complement, built on the same CCN tools, such as PILAR, INES and AMPARO, not a substitute for them. In practice, the "incident management" sheet (op.exp.7) that the threat identifier links to its alerts connects directly with incident response and forensic analysis, covered in detail in that guide: the navigable tool tells you what the regulation requires in the event of an incident, but the actual capacity to respond and investigate what happened is a process you have to build separately.

Access: what is public and what requires registration on the CCN's governance platform

It is worth being precise here, because it is easy to get the wrong idea: consulting the basic regulatory content of the ENS Navegable — which measures exist, which categories require them, what each sheet says — is publicly accessible, no registration needed. What does require authentication is access to the Governance platform's advanced functions: the threat identifier and the GRC dashboards mentioned above require signing up on the CCN's platform. It is not "full, free access with no registration whatsoever": it is free access to the regulatory lookup, and access with prior sign-up to the ongoing management functions.

If what you need is a result already filtered for your specific case, without having to use the navigable tool yourself or sign up to any platform, our ENS self-assessment tool (available in Spanish) does that filtering for you: you enter the assessment of your five security dimensions and instantly get your category and the Annex II measures that apply to you, free and with no registration required.

ENS Navegable versus PILAR, INES and AMPARO: which one to use for what

These are four tools from the same body with different purposes, and it is worth not confusing them:

It is worth noting that all four share the same regulatory basis — the same Royal Decree 311/2022, the same Annex II — so there can be no contradiction between what the navigable tool shows and what PILAR calculates or AMPARO manages: they are different views of the same content, adapted to a different purpose at each stage of the compliance process.

The navigable tool is the logical starting point: first you understand what the regulation requires, then you use PILAR to prioritise risks, and finally INES or AMPARO, depending on your category, to manage and declare conformity. Treating them as interchangeable is the most common mistake for anyone facing the compliance process for the first time.

Frequently asked questions

Does the ENS Navegable replace reading Royal Decree 311/2022?

No. The navigable tool reorganises the same regulatory content so it is faster to consult, but the legal source remains Royal Decree 311/2022 as published in the BOE. To cite a requirement in a tender, a contract or before an auditor, the correct citation is the Royal Decree, not the lookup tool.

Is it useful for private companies, or only for public administrations?

It is useful for any organisation subject to the ENS, including private companies that provide services to public administrations and that, because of that contractual relationship, must bring their systems into line with the National Security Framework. The navigable tool's content does not distinguish between the public sector and private providers: the regulation it reorganises is the same for both.

Does the ENS Navegable certify or audit my system?

No. The navigable tool is a lookup resource, not a certification body or an audit mechanism. Certification of medium and high category systems falls to bodies accredited by ENAC, and basic category self-assessment is declared through INES, not through the navigable tool.

This content is for general information purposes only. It does not constitute legal advice and does not replace the analysis of a qualified professional for your specific case.