Article 2.3 of RD 311/2022 leaves no room for interpretation: the Esquema Nacional de Seguridad (ENS) also applies to private entities that, under a contractual relationship, provide services or supply solutions to public-sector bodies for the exercise by the latter of their competences and administrative powers. In Seville that reaches suppliers of the Junta de Andalucía — whose Presidency is seated at the Palacio de San Telmo — the Diputación de Sevilla, the Ayuntamiento de Sevilla, the Universidad de Sevilla and the Universidad Pablo de Olavide. The transitional provision set 5 May 2024 as the compliance deadline for systems already in operation; new systems must comply from the moment they go into production, and failing to do so can exclude a company from public procurement with any of these bodies.
Summum Sistemas handles the area that is its own: the genuine technical implementation of the security controls in Annex II of RD 311/2022. That Annex organises 73 controls into three frameworks — organisational, operational and protection — spread across 16 families, seven of them within the operational block, which includes the op.nub family for cloud services, particularly relevant for SaaS suppliers serving Andalusian public bodies over cloud infrastructure. Writing a security policy is not enough: systems must be configured, services hardened, monitoring deployed, vulnerabilities managed, and verifiable technical evidence produced that every control is genuinely in place.
The starting point of any serious implementation is risk analysis. The ENS requires that the selection of Annex II controls be grounded in a formal analysis proportional to the system's category. Summum Sistemas applies the CCN's MAGERIT methodology — the official reference for risk analysis within Spain's public administration — and executes it with the PILAR tool, which models assets, threats and safeguards in a traceable way and produces the residual-risk report that conformity auditors expect to see. To verify implementation status control by control, we also use INES (Informe Nacional del Estado de la Seguridad), the CCN's self-assessment platform, which produces the status scorecard by family and underpins the declaration of conformity. One point is worth making because it is often repeated wrongly: RD 311/2022 names neither MAGERIT, nor PILAR, nor ENAC anywhere in its articles. They are the Centro Criptológico Nacional’s methodology and tool and Spain’s national accreditation body; we use them because they are the de facto reference in the public sector, not because the regulation imposes them.