
The National Security Scheme and your outsourcing provider: a declaration is not a certification
Corpshore Spain editorial team · · 7 min read
In summary: Spain's National Security Scheme, regulated by Royal Decree 311/2022, binds the Spanish public sector and the suppliers that serve it, including foreign ones. Basic category systems are evidenced by a declaration of conformity; medium and high category systems require certification by an accredited body, with an audit every two years.
If you provide, or want to provide, services to a Spanish administration, the National Security Scheme will appear in the tender documents. It is one of the first clauses that filters suppliers, and the one most often misread.
The common confusion treats a declaration of conformity and a certification as synonyms. They are not, and whether a bid is admissible can turn on that difference.
Who does the National Security Scheme bind?
Royal Decree 311/2022 of 3 May regulates the National Security Scheme and applies to the Spanish public sector and also to the suppliers that provide services to it and handle its information.
That second part surprises many private companies: the scheme is not only an obligation on the administration, it reaches whoever operates its systems or processes its information. It also reaches foreign suppliers, so locating the service outside Spain does not avoid the obligation.
In practice the tender carries the requirement across: public sector tenders must include the requirements needed to ensure the systems supporting the contracted service comply with the scheme.
How is a system's category determined?
There are three categories: basic, medium and high. They are determined by the impact an incident would have on the confidentiality, integrity, availability, authenticity and traceability of the information and services.
The point worth holding on to is that the category is not chosen, it is deduced. It is not a supplier's commercial decision nor a preference of the contracting body: it follows from analysing the information handled and the service provided.
For a citizen service handling identifying and case-processing data, the category is usually medium. For a service handling information with high impact in the event of an incident, it rises. And the category determines the remaining obligations.
What is the difference between a declaration and a certification?
For basic category systems, a declaration of conformity is sufficient, which is a self-declaration by the organisation itself.
For medium and high category systems, a certification of conformity issued by an accredited certification body is required, together with a compliance audit every two years.
The commercial consequence is direct. A supplier that says it is aligned with the National Security Scheme, without accredited certification, can bid for what requires basic category and cannot bid for what requires medium or high. Where a tender asks for certification, a self-declaration does not substitute for it.
What should you ask a supplier?
Ask for the document, not the assertion. If the supplier is certified, a certificate exists with an issuing body, a scope and a date, and they can show it.
Ask about the scope, which is where the surprises hide. A certification may cover part of an organisation or one specific service and not cover the service you are about to contract.
And ask about the date of the last audit, given that for medium and high categories the audit is biennial. A certificate without a current audit is a problem waiting to surface.
We apply controls aligned with the scheme's requirements and do not hold accredited certification today, so for a tender requiring medium or high category we would not be an admissible supplier on that ground. We say so here because it is better known before anyone invests time in a commercial conversation.
What if the service is delivered from outside Spain?
The obligation stands. The National Security Scheme applies to any supplier handling Spanish public sector information, regardless of where it is located.
On top of that sits the data protection layer, which is separate: a tender can require scheme compliance and also restrict processing outside the European Economic Area. They are two distinct requirements and both have to be met.
For public sector work, an onshore model within Spain or a hub inside the European Union therefore simplifies the conversation considerably, even before certification enters the picture.
This article is general information, not legal advice. We work alongside your legal advisors, not in their place.