ENS and AI: Medium vs High category for AI workloads in Spain
For anyone buying or auditing AI infrastructure in Spain's public sector or a regulated industry: how a system's ENS category is set, what the High category adds, what each certificate covers and what to ask for in a tender.
By Julio Sola Hernández-Rubio, founder of GPU SolutionsUpdated:
A system's ENS category is set by the worst possible impact of an incident across five security dimensions. Moving from Medium to High adds, among other things, formal risk analysis, supply-chain control, monitoring for advanced threats and cloud configuration following CCN guides. And every supplier must prove conformity for what it provides you.
I am writing this because almost every conversation with public-sector security officers raises the same doubt: if the datacenter is ENS High, is the service running inside it High too? No. And it is worth understanding why before drafting a tender for an AI workload.
ENS in five minutes
The Esquema Nacional de Seguridad (ENS, Spain's National Security Framework) is the mandatory information security framework for the entire Spanish public sector. It is governed by Royal Decree 311/2022 of 3 May and developed by the National Cryptologic Centre (CCN) through its CCN-STIC 800-series guides. It also reaches private companies that provide services or solutions to public bodies for the exercise of their powers (article 2.3), and tenders must require from them the corresponding Declarations or Certifications of Conformity, extended to their supply chain according to the risk analysis.
There are three categories: Basic, Medium and High. A Basic category system only needs a self-assessment, which produces a Declaration of Conformity. Medium and High category systems need a certification audit by an accredited body, which produces a Certification of Conformity (article 38). The ordinary audit is repeated at least every two years.
How a system's category is determined
Annex I of the Royal Decree is almost mechanical. First you assess the impact an incident would have on five security dimensions. Each affected dimension gets a level: Low if the harm would be limited, Medium if it would be serious and High if it would be very serious. Translated to an AI workload:
Confidentiality [C]
Nobody unauthorised can read the data. In AI: prompts, the documents feeding a semantic search (RAG), conversation logs.
Integrity [I]
Nobody can alter the data without permission. In AI: model weights, embedding indexes and training data.
Traceability [T]
Being able to reconstruct who did what and when. In AI: who asked what, which model answered and in which version.
Authenticity [A]
Every user or system is who it claims to be. In AI: API keys and agents acting on someone's behalf.
Availability [D]
The service works when it is needed. In AI: the assistant serving citizens or the model that classifies case files.
Then comes the rule: the system is High category if any dimension reaches High level; Medium if any reaches Medium and none goes above it; Basic otherwise. A single dimension decides. An assistant handling medical records may have Medium availability and High confidentiality, and then the system is High. The assessment belongs to the information and service owners, the category is set by the security officer (article 41), and it is reviewed at least once a year.
What changes in practice between Medium and High
Annex II gives each measure a set of base requirements plus reinforcements (R1, R2…) that are added depending on the system's category or on the level of a specific dimension. These are the differences that weigh most on an AI workload, as they appear in the Royal Decree:
| Measure | Medium | High | What it means for AI |
|---|---|---|---|
| op.pl.1 · Risk analysis | Semi-formal (R1) | Formal, with an internationally recognised mathematical basis (R2) | AI-specific risks, such as data leakage through prompts or data poisoning, assessed with a formal method |
| op.ext.3 · Supply chain | Not applicable | Applies: impact, risk and containment of incidents originating with suppliers | Your GPU, model and software suppliers enter your analysis |
| op.nub.1 · Cloud services | Certified service (R1) | R1 plus configuration following specific CCN-STIC guides (R2) | The cloud GPU platform is configured following CCN guides |
| op.mon.3 · Monitoring | Event correlation and exposure analysis (R1, R2) | Plus advanced threats, digital observatories, data-mining prevention and inspections including penetration tests (R3 to R6) | Limiting and watching query volume and frequency, very concrete for a model exposed through an API |
| op.exp.8 · Activity logging (by traceability) | Medium level: review, clock sync, retention and access control (R1 to R4) | High level: plus automatic review and event correlation (R5) | Prompt and response logs collected and correlated automatically |
| op.cont.2 · Continuity plan (by availability) | Medium level: not applicable | High level: mandatory | If the AI service is critical, you need alternative GPU capacity and a tested plan |
Note the nuance in the last two rows, which is often missed: not every measure depends on the category. Some depend on the level of one specific dimension. The continuity plan (op.cont.2), its periodic tests (op.cont.3) and alternative means (op.cont.4) are only mandatory when availability is at High level, even if the system is High because of confidentiality. If your assistant is High only because it handles very sensitive data, it may not need backup GPUs; if it is High because it cannot go down, it does.
Platform certification vs datacenter certification
This is where I see the most confusion, so let me explain it with our own case. Our GPU platform is certified under ENS Medium category and UNE-EN ISO/IEC 27001:2023 by EQA (certificates 13293-ENS and 13293-INF). The Tier III datacenter in Madrid where it is installed holds ENS High category, ISO/IEC 27001:2022, ISO 9001 and ISO 50001.
Three layers · three certificates · three owners
Models, data, users, logs and the ENS conformity of your own system. No supplier certificate replaces this layer.
NVIDIA HGX B200 servers, network, storage, tenant isolation, operations and support. Certified for Medium category systems.
Building, physical access, power, cooling and connectivity. Its certificate covers the facility, not the servers or the software running inside.
What it means: the datacenter's certificate covers the building, physical access, power, cooling and connectivity managed by its operator. Ours covers the servers, network, storage, tenant isolation and the operations we run. Each certificate covers its own layer and nothing else.
What it means for your tender: for Basic and Medium category systems, our platform certifies the layer that ENS requires from the infrastructure provider, and it does so on a datacenter that already meets the highest level. If your system is categorised High, compliance is built layer by layer and each provider certifies its own according to the scope of the service; in that case it is worth reviewing your specific scope before drafting the tender, which is exactly what we do with you in a first session.
And there is a third layer no supplier can take off your hands: your own system. Its categorisation, its risk analysis, its Statement of Applicability and its conformity are your organisation's responsibility. Your suppliers' certificates are pieces of that conformity; they do not replace it.
ENS, the AI Act and NIS2: how they overlap (as of 6 October 2026)
AI Act (Regulation (EU) 2024/1689). The simplification package known as the Digital Omnibus postponed the obligations for high-risk systems. According to the European Commission, the rules for high-risk systems in Annex III areas (biometrics, critical infrastructure, education, employment, migration, asylum and border control, among others) apply from 2 December 2027, and those for systems embedded in products from 2 August 2028. The amendment has been in force since 27 July 2026.
NIS2 (Directive (EU) 2022/2555). The transposition deadline expired on 17 October 2024. On 8 July 2026 the European Commission referred Spain, together with Ireland, France and the Netherlands, to the Court of Justice of the EU for failing to notify full transposition, and asked for financial penalties. Check the BOE (Spain's official gazette) before closing a tender, because the status can change at any time.
How they fit together: ENS is today the rule binding the administration and its suppliers; NIS2 extends risk-management and incident-reporting obligations to many essential and important entities; and the AI Act regulates the AI system itself, its use and its risk, not the infrastructure running it. The same system may have to comply with all three. The good news is that much of the work (risk analysis, logging, incident management, supplier control) serves all of them. If the NIS2 part lands on you, see our checklist for CTOs.
What to ask an AI infrastructure provider in a tender
| Question | What they should provide | Why it matters |
|---|---|---|
| What ENS category does your certificate have and what scope does it cover? | Certification of Conformity with category, scope and certifying body, plus the link to its published badge | The category must match your system and the scope must include the service you are buying |
| Who certifies each layer: datacenter, platform, service? | One certificate per layer, with its holder | The building's certificate does not cover the servers or the software |
| Where is data processed and stored, including logs and backups? | Specific locations and the list of subprocessors | Jurisdiction and GDPR, prompt logs included |
| Do you retain prompts, responses or data to train models? | Data processing agreement with a retention policy and a zero-retention option | Prompts reveal sensitive information |
| How do you isolate one customer from another on the GPU? | A concrete mechanism: dedicated GPU, hardware-isolated MIG partitions or virtualisation | Confidentiality and integrity on shared infrastructure |
| Which activity logs do you hand over, and in what format? | Events, retention, clock synchronisation and access control over the logs | Traceability (op.exp.8) and incident management |
| How, and how fast, do you report an incident? | Procedure, deadlines and point of contact | Incident management (op.exp.7) and reporting obligations |
| What happens if one of your critical suppliers fails? | Continuity plan and alternative means | Supply chain (op.ext.3) and continuity (op.cont) for High systems or High availability |
The application dates of these rules in Spain and the EU, each with its official source, are collected in our regulatory radar. To see how this applies to your sector, we have dedicated pages for the public sector and healthcare, with use cases, data flow and the applicable regulation.
Frequently asked questions
What is the difference between ENS Medium and High category?
High category applies to systems where an incident in any dimension (confidentiality, integrity, traceability, authenticity or availability) would cause very serious harm. It adds reinforcements such as formal risk analysis, supply-chain protection, monitoring for advanced threats and configuring cloud services according to CCN guides. Both require a certification audit.
If the datacenter is ENS High, is my AI service High too?
No. The datacenter's certificate covers the facilities its operator manages. The platform and the service running inside need their own certificate, and your system needs its own conformity.
Does a private company need ENS to sell AI to the Spanish public sector?
Yes, when it provides services or solutions to public bodies for the exercise of their powers. It must be able to show the Declaration of Conformity (Basic category) or the Certification of Conformity (Medium or High) of the systems supporting that service.
Can GPU Solutions host a High category AI system?
Our platform is certified under ENS Medium category, in a datacenter with ENS High, and covers Basic and Medium category systems. For systems categorised High, compliance depends on the scope of each service: tell us about your case and we will review it with you before you draft the tender.