The first practical consequence of the island structure is that there is no single province-wide counterpart. A supplier wanting to work in the province of Las Palmas finds cabildos that procure separately, town councils that are often small, and the regional and health administration above them. All are public-sector entities within the meaning of Article 2.1 of RD 311/2022, which refers to Article 2 of Law 40/2015, and all are required to include in their tender specifications the requirements needed to ensure ENS conformity of the systems underpinning contractors' services: Article 2.3 imposes this, expressly mentioning the presentation of Conformity Declarations or Certificates and extending that caution to the supply chain. More counterparts means more tenders, but it does not mean more regulations: there is only one ENS.
The second consequence is technical and has to do with where the service lives. In an archipelago, the infrastructure supporting applications is often hosted off the island or directly on public cloud. That takes the project squarely into two Annex II families. The first is op.nub, «Cloud services», whose op.nub.1 control, «Protection of cloud services», applies from basic category and is reinforced in medium and high: you have to demonstrate how the cloud service is protected, not just state it. The second is op.cont, service continuity, with its impact-analysis, continuity-plan, periodic-testing and alternative-means controls. It is worth being precise: Annex II grades those controls by category, and in the lower categories several of them are not required. What determines applicability is not geography, it is the category and the risk analysis.
The third point is the most overlooked and it is not about infrastructure. Article 2.3 of RD 311/2022 requires the private entity to hold the security policy required by Article 12, and specifies that for these entities it «shall be approved […] by the body holding the highest executive authority». Alongside that, Article 38.2 requires those responsible to publish, on their websites or electronic sites, their ENS conformity declarations and certificates: in other words, the conformity status of the administrations you want to work with is public and can be checked. Summum Sistemas' job is to get your side of that equation technically resolved: categorisation under Annex I, risk analysis with MAGERIT and PILAR, the methodology and tool of the Centro Criptológico Nacional, and verifiable implementation of the Annex II controls.