The BASIC-category ENS measures, one by one

·

BASIC category under the ENS requires 52 of the 73 Annex II measures in Royal Decree 311/2022: all 4 organisational-framework measures without exception, and most of the operational and protective ones, with or without mandatory authentication reinforcement. It is not the category with no real requirements: it has the fewest measures, but more than two thirds of the catalogue already applies from the first tier.

Checklist on a clipboard

Of the 73 security measures in Annex II of Royal Decree 311/2022, a BASIC category system has to implement 52. It is not the category "with no real requirements": it is the category with the fewest measures, but more than two thirds of the full catalogue already applies from the very first tier. This article lists them all, family by family, with what each one requires in practice.

What "BASIC category" means before you read the list

Before going through the list, it is worth confirming that your system really is basic category: the category is set by the highest level reached by any of the five security dimensions — confidentiality, integrity, traceability, authenticity and availability — not by a general estimate. We explain step by step how the category is calculated (available in Spanish), based on Annex I of Royal Decree 311/2022. If any of your five dimensions rises to MEDIUM or HIGH, the list in this article is not the one that applies to you.

We already counted how many measures each category requires (available in Spanish) in overall terms (52 at basic, 68 at medium, 73 at high) (available in Spanish); here we go measure by measure, with the practical detail that count could not give, by format. The full structure of Annex II — organisational, operational, protective — is explained in detail here.

Organisational framework: the 4 measures that always apply (org.1 to org.4)

The four measures in the organisational framework apply across all three categories with no exceptions, because they are the documentary backbone everything else rests on. In basic category, the four are:

Operational framework — planning and operation (op.pl and op.exp at basic)

In planning, basic requires four of the five op.pl family measures:

(op.pl.5, certified components, does not yet apply at basic: it starts at medium.)

In operation, basic requires nine of the ten op.exp measures:

(op.exp.5, change management, does not apply at basic: it starts at medium.)

Operational framework — access control, monitoring and cloud (op.acc, op.mon, op.nub at basic)

In access control, the following apply: op.acc.1 (identification), op.acc.2 (access requirements), op.acc.4 (access rights management), op.acc.5 (authentication of external users) and op.acc.6 (authentication of the organisation's own users). The last two already carry a mandatory reinforcement from basic category onwards, and op.acc.6 specifically requires two-factor authentication when access happens from or through an uncontrolled zone: we already resolved the full nuance, including reinforcements R8 and R9, in this guide (available in Spanish); we will not repeat it here to avoid confusion. (op.acc.3, segregation of duties, does not yet apply at basic.)

In monitoring, all three op.mon measures apply already at basic: op.mon.1 (intrusion detection), op.mon.2 (metrics system) and op.mon.3 (surveillance), with growing reinforcements at medium and high. Intrusion detection, metrics and surveillance depend on a real monitoring foundation, not an isolated tool that gets installed and forgotten.

For cloud services, op.nub.1 (protection of cloud services) is the only measure in that family and it already applies at basic, with no reinforcement. That is a relevant fact: many organisations assume the cloud "does not count" until higher categories, and that is not the case.

For external resources (op.ext), none of the family's four measures apply at basic: all four start at medium or high.

Protective measures — facilities, personnel and equipment (mp.if, mp.per, mp.eq)

For facilities (mp.if), six of the seven measures apply: mp.if.1 (separate, access-controlled areas), mp.if.2 (identification of people), mp.if.3 (conditioning of premises), mp.if.4 (electrical power), mp.if.5 (fire protection) and mp.if.7 (equipment entry and exit logging). (mp.if.6, flood protection, does not apply until medium.)

For personnel (mp.per), three of the four apply: mp.per.2 (duties and obligations), mp.per.3 (awareness) and mp.per.4 (training). (mp.per.1, job position characterisation, does not apply until medium.)

For equipment (mp.eq), three of the four apply: mp.eq.1 (clear desk policy), mp.eq.3 (protection of portable devices) and mp.eq.4 (other devices connected to the network). The counter-intuitive fact here is that mp.eq.2, automatic workstation locking, is not mandatory under Annex II until medium category: many organisations implement it at basic anyway as good practice, but Annex II does not yet require it.

Protective measures — communications, media, applications, information and services

For communications (mp.com), three of the four apply: mp.com.1 (secure perimeter), mp.com.2 (confidentiality protection) and mp.com.3 (integrity and authenticity protection, with no reinforcement at basic). The secure perimeter the ENS requires rests on correctly configured firewall rules, not just on having a firewall installed. (mp.com.4, separation of information flows on the network, does not apply until medium.)

For media (mp.si), three of the five apply: mp.si.3 (custody), mp.si.4 (transport) and mp.si.5 (erasure and destruction). The relevant fact here: neither media labelling (mp.si.1) nor media cryptography (mp.si.2) are mandatory under Annex II at basic, although encrypting media may still be advisable under GDPR if it contains personal data.

For applications (mp.sw), only mp.sw.2 applies (acceptance and commissioning); mp.sw.1, application development, does not yet apply at basic.

For information (mp.info), four of the six apply: mp.info.1 (personal data), mp.info.3 (electronic signature), mp.info.5 (document cleaning) and mp.info.6 (backups). The latter requires backups; how to build a backup plan that actually restores is the technical part behind this measure, not just having a copy saved somewhere.

For services (mp.s), three of the four apply: mp.s.1 (email protection), mp.s.2 (protection of web services and applications, with a mandatory reinforcement from basic onwards) and mp.s.3 (web browsing protection). mp.s.2 shares the same type of conditional reinforcement nuance as op.acc.6, so the same advice applies: check the dedicated guide (available in Spanish) before assuming the reinforcement. (mp.s.4, denial-of-service protection, does not apply until medium.)

A pattern that repeats: almost every family has at least one measure that "does not apply" at basic

Going through the list above family by family, you will notice a pattern: almost no family of Annex II measures applies at one hundred percent at basic. Organisational is the exception (all four always apply); in the rest, there is always at least one measure — sometimes several — that only starts at medium. This is not a design flaw in the regulation: it reflects the fact that the measures left for higher categories are, generally, the ones that require greater organisational maturity (segregation of duties, formal change management) or higher implementation cost (media encryption, component certification), while basic keeps the core of measures that any system, regardless of size, can and should implement.

The measures that do NOT apply at basic (and at which category they start)

In total, 21 measures do not yet apply at basic: op.pl.5, op.acc.3, op.exp.5, the four op.ext measures, mp.if.6, mp.per.1, mp.eq.2, mp.com.4, mp.si.1, mp.si.2, mp.sw.1, mp.info.2, mp.info.4, mp.s.4, and the service continuity measures (op.cont). Most of them start at medium category; the full breakdown of exactly what is added when moving from basic to medium — including the reinforcements that get added to measures you already had, which is not the same as just adding new measures — is covered in detail in our guide on what medium category adds over basic.

How compliance is demonstrated at basic: self-assessment, not third-party audit

The conformity route for basic category is self-assessment: the organisation itself declares compliance, with no need for a certification audit by an ENAC-accredited body, which is mandatory at medium and high. That does not mean it is enough to fill in a checklist from memory: CCN-STIC Guide 808 (verification of ENS measure compliance) requires real evidence for every measure implemented, and both the Royal Decree and that guide provide for periodic review, not a permanent exemption regime. Self-assessment does not mean "no requirements"; it means "no mandatory external auditor".

If you want to see this list already filtered for your own system, instead of going through the 52 measures one by one, use our ENS self-assessment tool (available in Spanish), free and with no registration required.

Frequently asked questions

Can I implement additional measures even if my category is basic?

Yes. A measure not being required at your category does not mean it is forbidden: voluntarily implementing additional measures — for example, on continuity or external resources — is common when the organisation's operations justify it, even if it is not needed for conformity.

Do all basic measures require the same effort?

No. The four organisational measures are mostly documentary; access control and monitoring measures require ongoing technical development; and facilities or personnel measures depend more on procedure than on technology. The implementation effort varies a great deal between families even though Annex II presents them in a single list.

What happens if my system has security dimensions at different levels?

The category of the whole system is set by the highest dimension, not the average: if four dimensions are LOW and one is MEDIUM, the system is medium category and this basic-category list is not the one that applies to you. Review how the category is calculated (available in Spanish) before taking this article's list as final.

This content is for general information purposes only. It does not constitute legal advice and does not replace the analysis of a qualified professional for your specific case.