Why Spanish Public-Sector and Financial Clients Ask for More Than a SOC 2 Report

Explore Spain's SaaS compliance requirements, including ENS, Pinakes, DORA, ISO 27001, and SOC 2 for public and financial sector deals.

Accorp Compliance Team

Accorp Compliance Team

Our team of compliance experts specializes in PCI DSS, SOC 2, and other security frameworks to help businesses achieve and maintain compliance.

Follow meLinkedIn

A SaaS vendor gets deep into a promising deal with a regional Spanish government agency, or a mid-size bank in Madrid, sends over its SOC 2 Type 2 report as the answer to the security section of the RFP, and then hits a wall. The procurement team comes back asking about ENS certification level, or whether the vendor holds a Pinakes rating, or how the platform handles CCN-STIC guide requirements — none of which appeared anywhere in the vendor's usual enterprise security questionnaire playbook built around the US and UK markets.

This is an increasingly common experience for SaaS companies expanding into Spain, and it's worth understanding clearly why a strong SOC 2 auditor certification, on its own, doesn't close deals in this specific market the way it might elsewhere.

Spain Runs Its Own National Security Framework — And It Isn't Optional

The single biggest gap for vendors unfamiliar with the Spanish market is the Esquema Nacional de Seguridad, or ENS — Spain's mandatory national security framework, established under Royal Decree 3/2010 and substantially updated by Royal Decree 311/2022. ENS compliance applies to any organization involved in processing public sector information or delivering digital services to Spanish public entities, and this obligation extends regardless of where the vendor itself is located. Public tenders increasingly list ENS certification as a hard prerequisite rather than a nice-to-have, and any subcontractor whose systems touch a public sector contract is expected to meet the same requirement — a detail that catches infrastructure and platform vendors off guard when they assume the obligation only applies to their direct client.

ENS operates across three certification levels — Básico, Medio, and Alto — determined by an impact assessment across five dimensions: confidentiality, integrity, availability, authenticity, and traceability, with the highest value across any single dimension setting the overall category. Health records systems, tax administration platforms, and regional government ERP systems typically require ENS Medio or Alto specifically, which involves considerably more stringent controls and continuous oversight than the baseline level.

It's worth being precise about how ENS relates to certifications a SaaS company likely already holds. ISO 27001 provides significant structural alignment with ENS on risk management and general security controls, and having it genuinely accelerates the path to ENS readiness — but it does not substitute for ENS certification itself. ENS layers in Spain-specific requirements that no international framework covers on its own: national cryptology requirements, specific incident reporting obligations, and adherence to CCN-STIC technical guides published by Spain's National Cryptologic Center. A SOC 2 Type 2 audit, similarly, demonstrates operating effectiveness of security controls generally, but says nothing about these Spain-specific obligations that a public sector buyer is contractually required to enforce.

For Financial Sector Clients: Pinakes Is the Certification Most Non-Spanish Vendors Have Never Heard Of

If ENS is the public sector's requirement, Pinakes is its financial sector equivalent, and it's arguably even less known among SaaS vendors entering Spain for the first time. Pinakes is a security rating framework developed by the Centro de Cooperación Interbancaria (CCI), Spain's banking association, which reports to the Bank of Spain. It exists specifically to help Spanish financial entities manage and monitor the cybersecurity posture of the technology providers they depend on, in direct response to European Banking Authority guidelines (EBA/GL/2019/02) requiring financial institutions to audit any technology provider handling outsourced operational or control functions.

The practical value proposition of Pinakes is genuinely elegant, and worth understanding because it's exactly the argument a Spanish bank's procurement team will make: rather than requiring every individual bank to run its own separate security audit of a vendor, Pinakes lets a provider undergo one independent, third-party-verified assessment covering 1,315 requirements across four categories — confidentiality, integrity, availability, and general requirements — spanning fourteen domains including access control, incident management, encryption, secure development, and resilience. The result is a letter-grade rating from D up to A+ in each category, rolling up to an overall score. A vendor holding a strong Pinakes rating can present that single certification to any Spanish bank in its pipeline instead of undergoing a bespoke security audit for each one — which is precisely why Spanish financial institutions increasingly ask for it directly rather than treating a SOC 2 report as sufficient evidence on its own.

For a SaaS vendor without any existing footprint in the Spanish financial sector, an unprepared answer to a Pinakes question mid-RFP is a strong signal to the buyer that the vendor hasn't actually operated in this market before — which is not the impression a vendor wants to create in the middle of a competitive procurement process.

DORA: The EU-Wide Layer That Applies Even When Spain Isn't Named Directly

Separate from Spain-specific frameworks, any SaaS vendor selling to EU banks, insurers, payment institutions, or investment firms — including Spanish ones — falls under the Digital Operational Resilience Act, DORA, which has been in direct force across the EU since January 2025. DORA doesn't typically regulate SaaS vendors directly, but its Article 30 contractual requirements flow down through the financial institution's own legal obligations: a Spanish bank subject to DORA is required by law to embed specific clauses into its contracts with technology suppliers, covering audit rights, exit strategies, and data location disclosure among other things. A vendor unable to meet these contractual requirements simply cannot close the deal, regardless of how strong its SOC 2 reporting otherwise is.

SOC 2 and ISO 27001 provide a genuinely strong foundation for DORA readiness, but they are not substitutes for it. Vendors serving Spanish financial clients need to be prepared to negotiate and accept DORA-aligned contractual language specifically, which is a different conversation from a standard SOC 2 audit report review.

Spain's Dual-Authority Cybersecurity Model

Spain transposed the EU's NIS2 Directive through its own Ley de Coordinación y Gobernanza de la Ciberseguridad, and structured it around a dual-authority model that's somewhat unusual within the EU: INCIBE-CERT handles private sector entities, while CCN-CERT governs public administration. For a SaaS vendor trying to understand which regulatory channel actually applies to a given deal, this split matters — a vendor selling into a private Spanish enterprise engages a different incident-reporting and compliance pathway than one selling into a public administration body, even though both ultimately sit under the same national cybersecurity law.

What This Means Practically for Go-to-Market Preparation

Vendors that treat their existing SOC 2 Type 2 report and ISO 27001 certification as the complete Spanish market entry story consistently lose time mid-deal discovering these Spain-specific requirements reactively. The more effective approach is mapping the target buyer segment before entering serious procurement conversations: public sector and public-adjacent deals require ENS at the appropriate level for the systems involved, financial sector deals increasingly expect a Pinakes rating or at minimum a credible answer about pursuing one, and any deal touching an EU-regulated financial entity needs DORA-aligned contractual terms ready to negotiate rather than discovered for the first time in legal review.

Spanish-language documentation matters here too, in much the same way it does across other major EU markets — Spanish public sector and financial procurement teams generally expect security documentation, incident response summaries, and contractual terms available natively in Spanish, not simply an English original with minimal localization.

Where Accorp Fits In

Accorp Partners helps SaaS companies preparing for Spanish public-sector and financial-sector sales cycles map exactly which additional frameworks — ENS, Pinakes, or DORA-aligned contract terms — actually apply to a given buyer segment, so a strong SOC 2 compliance foundation translates into a closed deal instead of stalling on a certification question the sales team never saw coming.

Frequently Asked Questions

1. Does ISO 27001 certification satisfy ENS requirements for Spanish public sector deals?

No, though it significantly accelerates readiness. ENS includes Spain-specific requirements — national cryptology rules, specific incident reporting, and CCN-STIC guide adherence — that ISO 27001 alone doesn't cover.

2. Is Pinakes mandatory for every SaaS vendor selling to Spanish banks?

Not formally mandatory in the way ENS is for public sector deals, but Spanish financial institutions increasingly expect it as evidence of security maturity, since it lets them satisfy their own EBA/GL/2019/02 audit obligations without running a bespoke assessment per vendor.

3. Does DORA apply to non-EU SaaS vendors serving Spanish financial clients?

Yes. DORA's contractual obligations apply based on whether the vendor serves an EU-regulated financial entity, regardless of where the vendor itself is headquartered or where its servers are located.

4. Is a SOC 2 Type 2 audit still worth having for the Spanish market?

Yes. It remains a strong general indicator of security maturity and is often a prerequisite for even being considered, but Spanish public-sector and financial buyers layer ENS, Pinakes, or DORA-specific requirements on top of it rather than treating it as sufficient by itself.

Also Read

Over 500+ clients have chosen Accorp for their compliance, tax, and risk assurance needs.

SOC 2 vs APRA CPS 234: What Australian Financial Institutions Actually Expect From Their Vendors
Blog

SOC 2 vs APRA CPS 234: What Australian Financial Institutions Actually Expect From Their Vendors

Read More about SOC 2 vs APRA CPS 234: What Australian Financial Institutions Actually Expect From Their Vendors
Does Your SOC 2 Report Actually Satisfy Australia's APP 8? What Cross-Border Data Rules Really Require
Blog

Does Your SOC 2 Report Actually Satisfy Australia's APP 8? What Cross-Border Data Rules Really Require

Read More about Does Your SOC 2 Report Actually Satisfy Australia's APP 8? What Cross-Border Data Rules Really Require
SOC 2 Isn't Enough for Japan: What APPI's Cross-Border Transfer Rules Actually Require
Blog

SOC 2 Isn't Enough for Japan: What APPI's Cross-Border Transfer Rules Actually Require

Read More about SOC 2 Isn't Enough for Japan: What APPI's Cross-Border Transfer Rules Actually Require
Selling SaaS Into Japan: How SOC 2 Reporting and ISMAP Actually Fit Together
Blog

Selling SaaS Into Japan: How SOC 2 Reporting and ISMAP Actually Fit Together

Read More about Selling SaaS Into Japan: How SOC 2 Reporting and ISMAP Actually Fit Together
Do You Need SOC 2 and BSI C5? A Decision Framework for Companies Selling Into Germany
Blog

Do You Need SOC 2 and BSI C5? A Decision Framework for Companies Selling Into Germany

Read More about Do You Need SOC 2 and BSI C5? A Decision Framework for Companies Selling Into Germany
SOC 2 for German Financial Clients: Where DORA and NIS2 Actually Fit In
Blog

SOC 2 for German Financial Clients: Where DORA and NIS2 Actually Fit In

Read More about SOC 2 for German Financial Clients: Where DORA and NIS2 Actually Fit In