Decoding the world of cybersecurity

· ·

Spain makes ENS controls machine-readable

Spain has published National Security Framework controls as structured JSON using NIST’s OSCAL specification, enabling greater automation across compliance, monitoring, audit, and risk-management workflows.

Spain makes ENS controls machine-readable
Summary
  • Spain has converted Annex II of the ENS into structured JSON using NIST’s OSCAL specification.
  • The format is intended to support automated implementation, monitoring, verification, audit, and cyber-risk workflows.
  • The CCN sees machine-readable controls as a route towards greater interoperability with future European security schemes.

Spain has converted the security measures in its National Security Framework into machine-readable code, allowing compliance, audit, monitoring, development, and risk-management systems to work directly with structured versions of regulatory controls.

The Centro Criptológico Nacional said on 17 September that Annex II of the Esquema Nacional de Seguridad, or ENS, is now available as structured JSON produced by the State Agency for Digital Administration.

The implementation uses the Open Security Controls Assessment Language, or OSCAL, developed by the US National Institute of Standards and Technology. OSCAL provides machine-readable formats for expressing security controls and related compliance information.

The first Spanish release focuses on the ENS catalogue of security measures. The CCN says the structured representation allows software to identify, recognise, and extract individual requirements together with identifiers, metadata, internal structure, and relationships.

A supporting design document explains how the regulatory text was converted into code, including the conventions used for identifiers, metadata, naming, and other technical decisions.

The change reduces the amount of compliance work that begins with people manually translating regulatory text into spreadsheets, governance platforms, tickets, control libraries, or technical checks. A structured representation can instead be consumed by software and mapped directly to implementation, assessment, or evidence workflows.

The CCN identifies automation of control implementation, continuous monitoring, verification, development tooling, auditing, and cybersecurity risk management among the intended uses. It also sees potential for artificial intelligence techniques in risk and vulnerability analysis, control selection, anomaly detection, and recommendations for adjustments.

Machine-readable regulation does not determine whether a security control has been implemented effectively. That assessment still depends on technical evidence, system context, and judgement. It does, however, change the mechanics through which requirements are distributed, mapped, maintained, and checked.

That becomes increasingly relevant as cybersecurity obligations overlap. Public-sector bodies, regulated operators, technology suppliers, and contractors can face national frameworks alongside EU legislation, sector rules, procurement standards, contractual controls, and internal governance requirements.

When those obligations exist only as prose, organisations and software providers repeatedly translate similar requirements into proprietary control descriptions. Structured controls make it easier to build mappings and maintain relationships between requirements without recreating the source material each time.

The approach also creates possibilities for more continuous assurance. Technical monitoring can be linked to explicit controls, while governance platforms can exchange structured information about implementation and evidence without relying entirely on manually maintained documents.

The CCN says the same method could later be extended to specific compliance profiles and statements of applicability associated with the ENS.

Spain is also presenting the work as part of a broader European direction. The CCN argues that machine-readable ENS content can strengthen the framework’s role as a reference point for future European schemes and support greater cybersecurity harmonisation and interoperability.

That does not make ENS an EU standard, nor does it remove differences between national and European legal requirements. It does provide a technical model for expressing security obligations in a form that software can process consistently — an increasingly useful property as compliance moves closer to engineering, operational monitoring, and automated evidence collection.

×