Market perspective

ISO/IEC 42001 and SOC 2 implementation for Spain

Spanish technology teams may need AI governance, an independent service assurance report for customers, and a security program compatible with public-sector expectations. ISO/IEC 42001, SOC 2, and the Spanish Esquema Nacional de Seguridad answer different questions and need separately defined scopes.

Build AI governance around data and impact decisions

ISO/IEC 42001 implementation starts with an inventory of AI systems and a way to decide which systems require deeper risk or impact review. The Spanish data protection authority, AEPD, publishes guidance on AI and personal-data questions. Where personal data is involved, the AI lifecycle record should identify the purpose, data source, affected people, security choices, and review owner.

The management system should make it possible to reconstruct a decision after a model or use case changes. It does not replace GDPR or EU AI Act legal analysis, and an ISO certificate is not a statement that every AI product complies with those laws.

Assess ENS at the right boundary

Spain's Esquema Nacional de Seguridad is set out in Royal Decree 311/2022. Its security measures are organized in organizational, operational, and protection groups. A supplier responding to an ENS request should establish whether the request is about its own system, a public-sector customer's system, or a contracted service component.

Map the real system category, responsibilities, measures, and evidence with the buyer. Existing ISO/IEC 27001 controls may help, but do not claim that ISO certification automatically fulfills every ENS measure or assessment requirement.

Plan SOC 2 for the service customers actually use

SOC 2 can be useful to a Spanish service organization whose buyers ask for AICPA-style assurance. Identify the product or managed service, its technical and organizational components, relevant Trust Services Criteria, and the users of the report. Evidence needs to be generated by the operating team over the relevant period.

A SOC 2 report does not establish ENS conformity, GDPR compliance, or ISO/IEC 42001 certification. It gives independent assurance about the controls in the described system and selected criteria.

Keep the response to buyers evidence-led

A single control register can connect access reviews, secure development, incident handling, and supplier oversight to ISO/IEC 27001, SOC 2, and applicable ENS measures. AI-specific impact assessment, testing, human review, and monitoring should sit visibly alongside those security controls.

For a procurement response, provide a concise scope statement for each artifact and a responsibility matrix. This helps prevent an attractive but inaccurate answer such as describing a corporate certificate as if it covered a buyer's entire service.

Plan for Spanish NIS2 while the national text develops

Spain's 2026 Annual Normative Plan identifies a proposed Cybersecurity Coordination and Governance Law as the measure intended to transpose NIS2. A provider should not treat provisions of a proposal as enacted Spanish obligations. Existing Spanish security requirements, including any applicable ENS or current network-security duties, also need their own scope assessment.

For a potentially in-scope organization, document the services and entities that could be covered, identify accountable management and incident contacts, review supplier and continuity dependencies, and build a risk-based remediation plan. Recheck the final Spanish law and regulator guidance before making legal or reporting claims. A SOC 2 report, ISO/IEC 27001 certificate, or ENS outcome should be described on its own terms rather than as a universal NIS2 certificate.

Common questions

Clarify the outcome before the work.

Is ENS the same as ISO/IEC 27001?

No. ENS has its own Spanish legal and technical scope. ISO/IEC 27001 can support a security management system and mapping work.

Does a SOC 2 report demonstrate ENS conformity?

No. It concerns the described service and selected AICPA Trust Services Criteria.

Does ISO/IEC 42001 replace Spanish data protection duties?

No. AI management system work and applicable data protection requirements need separate analysis.

Does an ENS or ISO/IEC 27001 outcome automatically satisfy Spanish NIS2?

No. Each has a different scope, and any Spanish NIS2 duties must be assessed against the enacted national text.

Work with Normstone

Make the next assurance decision clear.

Tell us your service, AI use, and customer requirements. We’ll help shape the scope.

Start a conversation