Contact us

comparativanis2-ens-iso

ISO 27001, NIS2, and ENS: Three Different Frameworks, One Common Goal

Enterprise cybersecurity is no longer based on a single standard. Spanish organizations may be subject to ISO 27001, NIS2, and the National Security Scheme (ENS) simultaneously, whether due to legal obligations, contractual requirements, or the need to demonstrate an adequate level of protection to clients, government agencies, and insurers.

Although the three frameworks share principles such as risk management, the implementation of controls, incident response, and continuous improvement, they are not the same in nature nor are they aimed at exactly the same organizations. ISO 27001 establishes an international, certifiable management system; NIS2 introduces legal obligations for certain sectors and reinforces management’s accountability; and ENS regulates the security of systems in the Spanish public sector and those of its suppliers.

Therefore, it is not necessarily a matter of choosing one over the other. In many companies, the three frameworks coexist, complement one another, and can share controls, evidence, and processes. The following comparison summarizes their main differences, points of overlap, and areas of application, with information updated as of August 2026.

Comparison of NIS2, ISO 27001, and ENS

ISO – International

ISO/IEC 27001:2022 – International, voluntary, and certifiable standard

EU – Europe

NIS2 (EU Directive 2022/2555) – European Cybersecurity Directive, required by law

ES – Spain

ENS (RD 311/2022) – National Security Framework, Spain

ISO

ISO/IEC 27001:2022—An international, voluntary, and certifiable standard

EU

**NIS2 (EU Directive 2022/2555)**European cybersecurity directive, required by law

EN

**ENS (RD 311/2022)** National Security Framework, Spain

CRITERIAISO 27001NIS2ENS
NatureInternational Technical Standard (ISO/IEC)European Union Directive Requires National ImplementationSpanish Royal Decree (separate regulatory framework)
Who is required to comply with it?Any organization that chooses to do so, or that is required to do so by a client or contractEssential and important entities in 18 critical sectors, generally with 50 or more employees or €10 million in revenueGovernment agencies and any company that provides services to them or manages systems on their behalf
MandatoryVoluntary, although increasingly required by contract by clients and insurersLegal, with personal liability on the part of the governing bodiesLegal Matters for the Public Sector and Its Supply Chain
FocusRisk-based Information Security Management System (ISMS) with 93 controls listed in Annex ARisk Management + Incident Reporting + Governance and Executive TrainingSystem categorization (basic / medium / high) and implementation of a catalog of approximately 75 security measures
CertificationCertifiable by an accredited body; certificate renewable every 3 yearsIt is not certifiable in and of itself; ISO 27001 or the ENS can serve as evidence of complianceCertificate of Conformity issued by an ENAC-accredited body
Incident ReportingIt does not set legal deadlines; this is left to the SGSI’s internal proceduresEarly warning within 24 hours, notification within 72 hours, final report within 1 monthNotify INCIBE-CERT or CCN-CERT, depending on the category of the affected system
PenaltiesThere is no direct legal penalty; the risk is losing certification or the contractUp to 10 million euros or 2% of total annual revenuePenalty system based on the regulations applicable to each agency or entity
Status in Spain (Aug. 2026)Fully in force and effective; a stable regulation since its 2022 revisionOnly partially implemented via RDL 7/2025; the Cybersecurity Coordination and Governance Act is still pending in CongressEffective as of 2022 (RD 311/2022), fully implemented in the public sector

They aren’t the same, but they have many controls in common. If you have ISO 27001 implemented, you’re closer to NIS2 or ENS than you think. The key is to avoid duplicating controls and documentation.

ithikios’ compliance solution helps demonstrate compliance in a simple way while minimizing the workload on the team.

Related articles

For years, regulatory compliance had a very clear goal: to avoid penalties. Companies would identify which laws applied to them, implement the necessary measures, and prepare documentation in case of...

For years, organizations have evaluated their suppliers primarily from an economic perspective: price, quality, delivery times, and technical capabilities. The Corporate Sustainability Due Diligence Directive (CSDDD) significantly changes this approach....

Do you want to try our whistleblower channel?

Do it from here for 15 days, without commitment, without cards,…

Want to see how ithikios can help you?

Get started today. Be compliant within hours. And when you grow up, ithikiosis with you.