Skip to main content
Corpshore España
A geometric terracotta and steel structure under raking light

IT outsourcing

Managed cybersecurity

Monitoring, vulnerability management and documentary support, with a clear distinction between alignment and certification.

In summary: security monitoring, vulnerability management and compliance support. We work aligned with Spain's National Security Scheme, and it is worth saying plainly that alignment is not certification: Corpshore does not currently hold ENS certification from an accredited body.

In security, the imprecise claim is the provider's own principal risk. A public sector client who assumes a certification that does not exist discovers the problem at the worst possible moment, during a tender.

So this page separates explicitly what we do from what we do not attest.

What is included

According to the agreed scope.

  • Security monitoring and alert management
  • Vulnerability management: detection, prioritisation and remediation tracking
  • Configuration hardening on in-scope systems
  • Identity management and periodic permission review
  • Incident response within the agreed scope
  • Documentary support for your compliance and audit processes

What is not included

This list is the important part of the page.

  • Issuing security certifications of any kind
  • ENS certification, which only an accredited certification body can issue
  • A declaration of conformity on your behalf, which belongs to your organisation
  • Independent audit of your systems, incompatible with providing the operational service
  • A guarantee of no security incidents, which no provider can honestly offer

Where it is delivered from

From Poland, inside the European Economic Area, which is usual for this service given the nature of the information handled and the shared time zone with mainland Spain.

For services to Spanish public sector bodies, team location and information handling form part of the system's category analysis and are worth settling before defining scope.

National Security Scheme: alignment versus certification

Royal Decree 311/2022 regulates Spain's National Security Scheme and binds the Spanish public sector and also the suppliers that serve it, including foreign ones.

Systems fall into three categories, basic, medium and high, deduced from potential impact rather than chosen. Basic category systems are evidenced by a declaration of conformity. Medium and high category systems require certification issued by an accredited certification body, with an audit every two years.

That difference decides tenders, which is why we state it here without hedging: Corpshore does not currently hold ENS certification from an accredited body. We work aligned with the framework and support your process documentarily, but if your system is medium or high category and the tender requires certification, you will need a certified provider for that part of the scope.

This is general information about the rules and not legal advice.

Frequently asked questions

Are you certified under the National Security Scheme?

No. We work aligned with the framework, which is not the same as certification. ENS certification can only be issued by an accredited certification body, and it is mandatory for medium and high category systems.

What about ISO 27001?

We publish no certification we cannot evidence with a current certificate. If you need a certified provider for a specific requirement, we will say so in the first conversation rather than after the proposal.

Can you help us prepare for certification?

We can support your process documentarily and operationally. Certification is issued by an accredited body and the declaration of conformity belongs to your organisation, not to us.

Can you audit us?

Not if we provide the operational service. Auditing the system you operate compromises the audit's independence, and an auditor who accepts that engagement should worry you.

Need managed security capacity?

Tell us the scope and, if a tender is involved, its specific certification requirements.