Enterprise cybersecurity is no longer based on a single standard. Spanish organizations may be subject to ISO 27001, NIS2, and the National Security Scheme (ENS) simultaneously, whether due to legal obligations, contractual requirements, or the need to demonstrate an adequate level of protection to clients, government agencies, and insurers.
Although the three frameworks share principles such as risk management, the implementation of controls, incident response, and continuous improvement, they are not the same in nature nor are they aimed at exactly the same organizations. ISO 27001 establishes an international, certifiable management system; NIS2 introduces legal obligations for certain sectors and reinforces management’s accountability; and ENS regulates the security of systems in the Spanish public sector and those of its suppliers.
Therefore, it is not necessarily a matter of choosing one over the other. In many companies, the three frameworks coexist, complement one another, and can share controls, evidence, and processes. The following comparison summarizes their main differences, points of overlap, and areas of application, with information updated as of August 2026.

ISO – International
ISO/IEC 27001:2022 – International, voluntary, and certifiable standard
EU – Europe
NIS2 (EU Directive 2022/2555) – European Cybersecurity Directive, required by law
ES – Spain
ENS (RD 311/2022) – National Security Framework, Spain
ISO
ISO/IEC 27001:2022—An international, voluntary, and certifiable standard
EU
**NIS2 (EU Directive 2022/2555)**European cybersecurity directive, required by law
EN
**ENS (RD 311/2022)** National Security Framework, Spain
| CRITERIA | ISO 27001 | NIS2 | ENS |
|---|---|---|---|
| Nature | International Technical Standard (ISO/IEC) | European Union Directive Requires National Implementation | Spanish Royal Decree (separate regulatory framework) |
| Who is required to comply with it? | Any organization that chooses to do so, or that is required to do so by a client or contract | Essential and important entities in 18 critical sectors, generally with 50 or more employees or €10 million in revenue | Government agencies and any company that provides services to them or manages systems on their behalf |
| Mandatory | Voluntary, although increasingly required by contract by clients and insurers | Legal, with personal liability on the part of the governing bodies | Legal Matters for the Public Sector and Its Supply Chain |
| Focus | Risk-based Information Security Management System (ISMS) with 93 controls listed in Annex A | Risk Management + Incident Reporting + Governance and Executive Training | System categorization (basic / medium / high) and implementation of a catalog of approximately 75 security measures |
| Certification | Certifiable by an accredited body; certificate renewable every 3 years | It is not certifiable in and of itself; ISO 27001 or the ENS can serve as evidence of compliance | Certificate of Conformity issued by an ENAC-accredited body |
| Incident Reporting | It does not set legal deadlines; this is left to the SGSI’s internal procedures | Early warning within 24 hours, notification within 72 hours, final report within 1 month | Notify INCIBE-CERT or CCN-CERT, depending on the category of the affected system |
| Penalties | There is no direct legal penalty; the risk is losing certification or the contract | Up to 10 million euros or 2% of total annual revenue | Penalty system based on the regulations applicable to each agency or entity |
| Status in Spain (Aug. 2026) | Fully in force and effective; a stable regulation since its 2022 revision | Only partially implemented via RDL 7/2025; the Cybersecurity Coordination and Governance Act is still pending in Congress | Effective as of 2022 (RD 311/2022), fully implemented in the public sector |
They aren’t the same, but they have many controls in common. If you have ISO 27001 implemented, you’re closer to NIS2 or ENS than you think. The key is to avoid duplicating controls and documentation.
ithikios’ compliance solution helps demonstrate compliance in a simple way while minimizing the workload on the team.