Skip to content
CertENS
ES
Service · Documentation

ENS documentation

Complete documentary evidence

We draft and maintain the full documentary corpus the auditor will request: from the Security Policy approved by top management to every STIC procedure, plus the Statement of Applicability and formal Risk Analysis.

Request free assessment

Add-on to Implementation or standalone service

What's included

Scope, deliverables and timeline are fixed upfront. No surprise costs.

  • Security Policy aligned with RD 311/2022
  • User regulations and operational procedures
  • Statement of Applicability with per-control justification
  • Risk analysis in PILAR or equivalent
  • STIC procedures: incidents, access, continuity, traceability…
  • Integrated data-protection policy (GDPR/LOPDGDD)
  • Business continuity plan and incident response plan
  • Security RACI matrix with committee, responsible party, operators and users

Deliverables

Everything delivered in editable format. If tomorrow you change providers, your work stays with you.

  • Complete editable document pack
  • Signed and filed versions
  • Version control and review plan
  • Optional English translation of key documents
FAQ

FAQ for this service

Do you provide a generic Statement of Applicability or one tailored to my organisation?
100% tailored. The SoA must justify each control — whether it applies, with what scope and, if not, why. A copy-paste SoA guarantees a non-conformity at audit.
Is documentation ENS-only or does it cover GDPR too?
We can integrate both. It's common to share the Security Policy, Access Policy and incident management procedure across ENS and GDPR, avoiding duplication.
In what format do you deliver documents?
Editable Word (with change tracking), signed PDF and, optionally, into your GRC platform. Everything numbered, versioned and with a signature matrix.

Ready to get ENS certified?

Free, no-commitment initial assessment. We reply within 24 business hours.