Moving from basic to medium category under the ENS is not just about adding the 16 Annex II measures that were “not applicable” at basic: several measures you already had implemented at basic require an extra reinforcement at medium. Simply adding the 16 new measures and assuming you are done is the myth this article corrects, measure by measure.
Moving from BASIC to MEDIUM category under the ENS is not just a matter of adding the 16 Annex II measures that were "not applicable" at basic. There is a second layer of effort that is often overlooked: several measures you already had implemented at basic require an extra reinforcement at medium, meaning more rigour in how they are carried out. Simply adding the 16 new measures and assuming you are done is exactly the myth this article corrects.
Two ways to move up a level: entirely new measures and reinforcements on measures you already had
Before planning the jump in category, confirm how yours is calculated: the step-by-step procedure is available here (in Spanish), based on Annex I of Royal Decree 311/2022. And if your system is basic category today, here is the full list of what you already have in place: the 52 basic-category measures, one by one.
We already counted how many measures apply per category (in Spanish) and left a question open — is it enough to add the 16 new measures to move from basic to medium? — here we answer it with the measure-by-measure detail that piece could not give, by format. The concept of reinforcement and the full structure of Annex II — organisational, operational, protective — is already explained here.
The 16 measures that only start applying at MEDIUM
By family, here is exactly what gets activated when moving to medium category:
- op.pl.5 Certified components: requires the products used to hold security certification.
- op.acc.3 Segregation of duties and tasks: formal separation of responsibilities that was not mandatory at basic.
- op.exp.5 Change management: a formal change-control procedure for the system.
- op.ext.1 Contracting and service-level agreements: requires a formal SLA with external providers.
- op.ext.2 Day-to-day management: routine measurement of SLA compliance and maintenance-coordination procedures with the provider.
- op.ext.4 System interconnection: reinforced control of the connection point with other systems.
- op.cont.1 Impact analysis: the first formal step of business continuity.
- mp.if.6 Flood protection: a physical facilities measure.
- mp.per.1 Job position characterisation: security requirements defined by role.
- mp.eq.2 Workstation locking: automatic screen locking, which many assume is mandatory from basic onwards, is in fact not required under Annex II until medium.
- mp.com.4 Separation of information flows on the network: network segmentation required from medium onwards.
- mp.si.1 Media labelling: formal classification and labelling of information media.
- mp.si.2 Media cryptography: encryption of media is not required under Annex II until medium, not from basic.
- mp.sw.1 Application development: security requirements throughout the software development lifecycle, with up to four reinforcements already from medium.
- mp.info.2 Information classification: formal classification of the information handled.
- mp.s.4 Denial-of-service protection: a specific anti-DoS/DDoS measure.
A practical example: two new measures with very different levels of effort
Not all 16 new measures cost the same to implement, and confusing "new measure" with "uniform effort" is another common mistake when planning the jump. Compare two cases: mp.eq.2, workstation locking, is almost always solved with a group policy or centralised configuration that locks the screen after a period of inactivity; it is a technical measure, quick to roll out and low cost. op.ext.1, on the other hand, requires negotiating and signing a formal Service Level Agreement with every relevant external provider, which means reviewing existing contracts, negotiating clauses the provider may not have offered before, and setting up a procedure to continuously measure compliance with that SLA. These are two measures at the same category tier, but one is solved in an afternoon of configuration and the other can take weeks of contract negotiation with several providers at once.
This asymmetry is why it is worth planning the jump from basic to medium with enough time built in for measures of a contractual or organisational nature, not just technical ones: a project that only budgets configuration time finds itself, halfway through, with SLA negotiations for three or four providers that have not even started yet.
Why "external resources" (op.ext) gets almost fully activated at medium
Of the four op.ext family measures, three get activated at medium (op.ext.1, op.ext.2 and op.ext.4), and only one is left for high: op.ext.3, protection of the supply chain. This is an important nuance so as not to promise too much: the family gets almost entirely activated at medium, but precisely the measure whose title is "supply chain" is still not mandatory until high category. That does not mean the supply chain is irrelevant at medium, or even at basic: Article 2.3 of the Royal Decree can require contractual precautions regarding providers earlier than that, if the risk analysis justifies it, regardless of whether the formal Annex II measure is active. We cover this relationship in full, with the specific clauses that follow from each obligation, in this guide on the ENS and providers.
If the external resource you are contracting is cloud infrastructure — the most common case in practice for op.ext.1 and op.ext.2 — this connects directly with our cloud infrastructure and migration service, and you should also check what the ENS specifically requires from that provider: we cover it in this guide on the ENS in the cloud. And to understand what type of cloud provider you are contracting, this guide to AWS, Azure and Google Cloud helps put it in context before negotiating the SLA that op.ext.1 requires in writing.
The reinforcements added to measures that already applied at basic
This is the part that a simple count of "16 new measures" fails to capture. It is not an exhaustive list — that would be redundant with the full Annex II — but the examples with the most practical impact:
- op.pl.1 Risk analysis: goes from "applies" to "+R1" at medium.
- op.acc.5 / op.acc.6 Authentication mechanisms: these already carried a mandatory reinforcement at basic; at medium, reinforcement R5 is added. We already resolved the nuance of when each reinforcement is required for basic in this guide (in Spanish), and the same type of condition applies to the additional reinforcement at medium.
- mp.com.2 / mp.com.3 Communications: go from "applies" to "+R1" and "+R1+R2" respectively. The in-transit encryption reinforcements this family requires rest on the same TLS fundamentals we already explained here.
- op.mon.2 / op.mon.3 Monitoring: move to "+R1+R2" at medium. These reinforcements require a more mature monitoring foundation than at basic, not just more alerts configured.
What does NOT change between basic and medium
Not everything increases in requirement. A clear example: mp.eq.3, protection of portable devices, applies at basic with no reinforcement and keeps applying at medium with no new reinforcement. Confirming which measures stay the same is just as important as knowing which ones go up, because it avoids duplicating effort where it is not needed: it is common for a poorly planned compliance project to review, "just in case", measures that were already correctly implemented at basic and that Annex II does not require reinforcing at medium, while leaving others that do need review unchecked.
The most reliable way not to confuse the two groups is to work with the full Annex II table in front of you, column by column — basic, medium, high — rather than relying on memory of what was implemented the first time. A change of security officer between the basic-category project and the medium-category one is, in practice, the moment when this traceability gets lost most often: whoever plans the jump is not always the person who documented the original implementation.
How to plan the jump without losing what is already implemented
The recommended order is: first confirm through risk analysis that the system actually moves to medium category (the category is determined by the security officer based on the impact assessment, not by organisational preference); then review, measure by measure, which of the ones you already have implemented at basic need an extra reinforcement; and only then implement the 16 measures that were previously "not applicable". Doing it the other way round — implementing the new ones first and reviewing reinforcements at the end — is the most common way to leave gaps in a Statement of Applicability. Before planning the jump, check with our ENS self-assessment tool (in Spanish) whether your system is still basic or should already be medium.
Planning this jump without leaving gaps — neither in new measures nor in reinforcements on the ones you already had — is the work we do in our ENS technical implementation service.
Frequently asked questions
Is it enough to add the 16 new measures to move from basic to medium?
No. Besides the 16 measures that go from "not applicable" to required, there are additional reinforcements on several measures that already applied at basic — authentication, communications, monitoring, risk analysis, among others. The real jump in effort is bigger than the simple count of new measures.
Why doesn't supply chain protection (op.ext.3) apply yet at medium?
Because that is what Annex II's applicability table sets out: op.ext.3 is "not applicable" at basic and medium, and only becomes active as a formal measure at high category. That does not exempt you from contractual precautions regarding providers before high category if the risk analysis under Article 2.3 of the Royal Decree justifies it.
Who decides that a system moves from basic to medium?
The category is not a business decision made by the company: it is determined by the security officer based on the impact assessment across the five security dimensions, in accordance with Articles 40 and 41 and Annex I of Royal Decree 311/2022.
This content is for general information purposes only. It does not constitute legal advice and does not replace the analysis of a qualified professional for your specific case.