Politeia Soft achieves ENS Medium category certification

AENOR certifies Politeia Soft under Spain’s National Security Framework (ENS) Medium category (ENS-2026/0141). What it means, which systems are in scope, and why it matters for public-sector procurement.
Politeia Soft, S.L. has obtained the Certificate of Conformity with Spain’s National Security Framework (Esquema Nacional de Seguridad) issued by AENOR CONFIA S.A.U. The certificate number is ENS-2026/0141, category MEDIUM (MEDIA), with an initial certification date of 1 October 2026 and validity until 1 October 2028.
This certification confirms, after independent audit, that the evaluated information systems meet the requirements of Royal Decree 311/2022, which regulates the ENS for electronic administration.
What the National Security Framework is
The ENS sets principles, requirements and security measures for public administrations and, increasingly, for vendors that deliver digital services to them. It is not a marketing badge: it demands security governance, access control, encryption, continuity, auditability and continuous improvement.
Categories (BASIC, MEDIUM, HIGH) reflect the required assurance level based on potential impact on confidentiality, integrity, availability, authenticity and traceability. MEDIUM implies a broad set of technical and organisational controls — in our case 68 measures assessed at medium level across all dimensions — plus a formal external audit.
Why Medium category matters
For a municipality, agency or company buying critical software, ENS Medium certification provides:
- Verifiable evidence for tenders, DPOs and auditors: the AENOR certificate is public and traceable.
- Operational trust in the platform (authentication, SaaS products and payments) that underpins services with sensitive data.
- Alignment with the Spanish public sector, where ENS is the reference security framework.
- Transparent scope: publication of which systems are covered and under which categorisation.
Scope of certificate ENS-2026/0141
The audited scope covers the information systems that support a microservices-based software platform for:
- API gateway,
- authentication,
- Anonimatum,
- Facturatum,
- incident management,
- payment services,
according to the system categorisation document v.2 dated 21/09/2026, in force at the audit of 24 September 2026.
Locations listed on the certificate include the headquarters in Jerez de la Frontera (Cádiz) and external OVH Cloud data centres in Gravelines (France) and Warsaw (Poland).
What it means for Anonimatum and Facturatum customers
If you use Anonimatum or Facturatum, those products are within the certified perimeter. That strengthens supplier-assurance narratives for GDPR, public tenders and vendor assessments.
See the dedicated ENS certification landing page and download the official document.
Official document
The full AENOR certificate is published on politeiasoft.com:
Download ENS-2026/0141 certificate (PDF)
Continuous improvement commitment
Validity until 2028 is not an endpoint. ENS requires risk review, control monitoring and periodic audit readiness. Our Information Security Policy describes the internal framework (roles, principles and applicable regulation) aligned with Medium category.
Summary
Politeia Soft holds ENS Medium category certification (ENS-2026/0141) from AENOR, with an explicit scope covering gateway, authentication, Anonimatum, Facturatum, incidents and payments. It is objective evidence of security maturity for public and private organisations that require audited vendors.