It is worth keeping the two circuits separate, because the technical answer is not the same for both. In the regional circuit, the supplier integrates with Junta systems that in some cases are certified in the medium category, and that pulls the conformity route with it: Article 38.1 of RD 311/2022 establishes that medium- or high-category systems require an audit for certification of their conformity, as against the self-assessment that suffices for basic category — without prejudice to a basic-category system also undergoing a certification audit if it chooses to. In the local circuit, by contrast, the counterparty is usually a small town council with no systems team of its own, supported by regional programmes for municipal e-government; there the system is normally basic category, and what is needed is a solution that can be replicated across many entities without redoing the case file each time.
What does not change between the two circuits is the regulation itself. Article 2.1 of RD 311/2022 applies the royal decree to the whole public sector in the terms of Article 2 of Law 40/2015, and Article 2.3 extends it to the systems of private-sector entities — including the obligation to hold the security policy required by Article 12 — when they provide services or supply solutions to those entities, under a contractual relationship, for the exercise by the latter of their administrative competences and powers. The same article requires tender specifications to include the requirements needed to ensure conformity, «such as the presentation of the corresponding ENS Conformity Declarations or Certificates», and extends that caution to the contractor's supply chain. And Article 38.2 requires those declarations and certificates to be published on the relevant websites or electronic sites: that is why the Junta's certificates can be consulted.
Technically, a product that is going to be deployed across many local entities stakes the whole project on the op.exp family of the operational framework: asset inventory, security configuration, change management, protection against malicious code and activity logging. If those measures are solved once and reproducibly, deployment at the fortieth entity costs the same as at the first; if they are solved by hand, there is no margin left. On top of that sits categorisation under Annex I, assessing impact across the five dimensions of Article 40.2, risk analysis with MAGERIT modelled in PILAR — the methodology and tool of the Centro Criptológico Nacional (CCN) — and cryptographic configuration under CCN-STIC-807. Annex II brings together 73 controls across 16 families and three frameworks; which ones apply, and with what reinforcements, is decided by the category, not by the size of the client.