
Post-quantum cryptography: what CCN, ENISA, and NIST are actually saying
16 de July de 2026In any Spanish public procurement tender, or in any compliance conversation with a public-sector client, it’s common to hear ENS, LINCE, CPSTIC, and Common Criteria mentioned almost as if they were synonyms. They aren’t, and conflating them has practical consequences: it can lead a manufacturer to certify its product through the wrong route, or a public buyer to take a “we comply with ENS” claim at face value when what it actually means is being listed in a catalogue.
In one sentence: ENS sets the security level required of a system; CPSTIC is the catalogue listing the products that have already demonstrated that level; and LINCE and Common Criteria are the two evaluation methodologies — one national in scope, one international — through which a product gains entry to that catalogue.
This article breaks down what each one regulates, with official sources, and how they fit together.
What is ENS? The legal framework, not a product certification
The Esquema Nacional de Seguridad (ENS, National Security Framework) is the regulation that sets the security policy required of Spanish public-sector information systems and of the providers that deliver services to them. It is governed by Royal Decree 311/2022, and classifies each system into one of three categories (Basic, Medium, or High) based on the impact an incident would have across five security dimensions: authenticity, confidentiality, integrity, availability, and traceability.
One important nuance: ENS doesn’t certify products, it certifies systems. An organization obtains a Declaration of Conformity (Basic category, through self-assessment) or a Certification of Conformity (Medium and High categories, through accredited external audit) for its complete information system, not for a specific piece of software. When ENS requires or recommends the use of “certified products” (a criterion set out in security measure op.pl.5 of Annex II), that’s where CPSTIC, LINCE, and Common Criteria come into play.
Cosmikal’s take: in our experience working with public administrations, ENS stops being treated as a formality the moment it’s translated into architectural decisions rather than a checklist. The measures in Annex II don’t work as well when “fitted” onto a product that’s already been designed as they do when the product is designed with them in mind from the start — session encryption, privileged-access traceability, credential rotation. That’s the real difference between a vendor who “complies with ENS” on paper and one whose architecture was built from the ground up for the High category.
What is CPSTIC? The catalogue, not the certification itself
The Catálogo de Productos y Servicios de Seguridad TIC (CPSTIC, ICT Security Products and Services Catalogue) is the list of products that CCN considers fit for use in systems subject to ENS, maintained and published monthly by the CCN-PYTEC department under Guide CCN-STIC 105. Being listed in the catalogue isn’t, by itself, a certification: it’s the outcome of having passed one.
CPSTIC distinguishes two statuses:
- Qualified: the product has passed, at minimum, an evaluation against the Fundamental Security Requirements (RFS) defined by CCN for its product family.
- Certified: the product has additionally obtained formal recognition of its Security Target (the document that sets the technical scope of the evaluation) through LINCE or Common Criteria.
All certified products are qualified, but not all qualified products are certified.
Cosmikal’s take: in our view, this is the distinction the sector explains worst. It’s common to find marketing materials that say “we’re in the CPSTIC catalogue” without clarifying whether that means qualified or certified, when for an evaluator on a public tender that difference does affect scoring. We always recommend checking a product’s exact status directly in CCN’s catalogue before taking a vendor’s marketing sheet at face value.
What is LINCE? CCN’s reference methodology for the Spanish market
LINCE (Certificación Nacional Esencial de Seguridad, Essential National Security Certification) is the product evaluation methodology developed and operated by the Centro Criptológico Nacional itself, defined in the CCN-LINCE guide series (001 to 004) and carried out by independent laboratories accredited by ENAC (Entidad Nacional de Acreditación, Spain’s national accreditation body). Its design is based on the technical principles of Common Criteria — Security Target, analysis of the implemented security functions, Evaluation Technical Report — but bounds the evaluation’s effort and timeline to a scope defined in advance, calibrated for products aimed at medium and basic threat levels.
A bounded effort doesn’t mean bounded rigor: a LINCE evaluation requires an accredited laboratory (a technically qualified third party independent of the manufacturer) to audit the documentation, run functional tests on the product, and issue an ETR (Evaluation Technical Report), which CCN’s Certification Body then reviews and validates before granting the certificate. At SICUR 2026, CCN’s own head of CPSTIC, Estefanía Linares, described LINCE as the first and most recognized cybersecurity evaluation methodology developed in Spain, also noting its alignment with equivalent initiatives in other European countries — such as France’s CSPN scheme — and with the assurance levels promoted by the EU Cybersecurity Act.
Technical features that define it:
- A CCN-owned methodology, evaluated by independent third parties. The accredited laboratory belongs neither to the manufacturer nor to the Certification Body — an added guarantee of impartiality in the result.
- Bounded scope and timeline, not reduced rigor. The evaluation period has an indicative maximum of eight weeks: a tighter scope than Common Criteria’s, suited to the threat level it targets, not an abridged version of the same analysis.
- Two optional deep-dive modules. The Source Code Review Module (MCF) and the Cryptographic Evaluation Module (MEC) allow the technical analysis to be extended when the product or client requires it.
- Coverage of ENS’s Basic and Medium categories, with access to the High category too, without needing Common Criteria: if a product holds a current LINCE certification for Medium and its cryptography meets the requirements for High, a comparative analysis (a complementary STIC assessment) is carried out against the additional requirements and validated by the accredited laboratory — meaning LINCE on its own covers all three ENS categories.
- National recognition. LINCE’s recognition is limited to Spain; for markets or clients outside the country, Common Criteria remains the applicable route.
Cosmikal’s take: LINCE is today CCN’s national reference methodology, carried out by accredited laboratories under the same kind of technical scrutiny — Security Target, functional testing, an evaluation report validated by the Certification Body — that underpins Common Criteria, calibrated to the threat level of the vast majority of real-world deployments in Spanish public administration.
What is Common Criteria? The international standard
Common Criteria (ISO/IEC 15408) is the international standard for evaluating the security of IT products, with mutual recognition among the countries that have signed the Common Criteria Recognition Arrangement (CCRA). It certifies products across different Evaluation Assurance Levels (EAL), and is the most technically demanding of the four routes covered in this article, both in time and in cost.
Its advantage over LINCE isn’t the ENS category it can reach (both can reach the High category), but the scope of recognition: a Common Criteria certification is valid outside Spain, which matters for any manufacturer aiming to sell to administrations or clients in other countries, or that needs to reach the highest EAL levels within CPSTIC itself, typically required in defense or critical infrastructure.
Cosmikal’s take: the moment Common Criteria shifts from “nice to have” to “necessary” tends to coincide with the appearance of a specific client that requires it — defense, critical infrastructure, an international market — rather than with a fixed date on the product roadmap. It’s a certification worth planning around that identified client, precisely because the process is long and leaves no room for last-minute shortcuts once a tender deadline is on the table.
How the four pieces fit together
| What it is | What it certifies | Recognition | |
| ENS | Legal framework (RD 311/2022) | Complete information systems | Spanish public sector and its providers |
| CPSTIC | CCN’s catalogue | Nothing by itself; lists already-evaluated products | Reference for Spanish public procurement |
| LINCE | CCN certification methodology, run by accredited laboratories | Specific products, Basic, Medium, and High levels (High via a validated extension) | National — Spain’s reference methodology |
| Common Criteria | International standard (ISO/IEC 15408) | Specific products, by EAL level | International (CCRA) |
A practical example: choosing the certification route
Picture a manufacturer that has built a privileged access platform and wants to sell it to Spanish public bodies. If its immediate goal is to enter Basic or Medium category ENS systems and its market is essentially domestic, LINCE is the most direct route: a rigorous methodology, carried out by accredited laboratories, with access to CPSTIC within a bounded timeframe.
If that same manufacturer needs to reach ENS’s High category but its market remains essentially Spanish, it can do so by extending its LINCE certification — meeting High’s cryptographic requirements and passing the comparative assessment against that category — without needing to start a Common Criteria process. Only once defense bodies, critical infrastructure, or markets outside Spain enter the picture does Common Criteria become worth considering, either from the outset or as a step after LINCE. It’s worth keeping in mind that a LINCE certification doesn’t automatically convert into Common Criteria: if the latter is needed down the line, the process starts from scratch.
Frequently asked questions
Is it mandatory to certify a product under LINCE or Common Criteria to use it in a system subject to ENS?
Not always. ENS recommends the use of certified products, and requires it in certain cases depending on the system’s category. Outside those cases, non-certified products can be chosen if the risk analysis justifies it.
Is LINCE a less demanding certification than Common Criteria?
Not in technical rigor: both require evaluation by an independent laboratory, a Security Target, and a technical report validated by the corresponding certification body. LINCE also isn’t limited to the Basic and Medium levels — extended with the corresponding cryptographic and comparative analysis, it also grants access to ENS’s High category. What actually sets Common Criteria apart is its international recognition and access to the highest EAL levels, useful when the target market extends beyond Spain.
Can a product be in CPSTIC without LINCE or Common Criteria certification?
Yes, if it has passed an evaluation against the Fundamental Security Requirements defined by CCN for its product family; in that case it’s listed as “qualified,” not “certified.”
Does ENS only apply to public bodies?
It applies to the Spanish public sector and also to private entities that provide services or solutions to the administration when applicable regulation requires them to comply with ENS.
Conclusion
ENS, LINCE, CPSTIC, and Common Criteria don’t compete with one another: they answer different questions within the same compliance ecosystem. ENS sets the level of rigor a system needs; CPSTIC is the reference for finding products that have already proven they meet it; LINCE and Common Criteria are the two routes — national and international — through which a product reaches that catalogue. Choosing correctly between these last two depends on who you want to sell to and at what level of rigor, not on which one is “more” or “less” rigorous.
How Endurance fits into this framework
Endurance is listed in the CPSTIC Catalogue with a dual presence, under the VDI (ENS High level) and PAM taxonomies. Its PAM taxonomy has also passed CCN’s LINCE Certification process, granting it catalogue access as a certified product in that family; extending that same certification to the VDI taxonomy is in its final phase, with completion expected in the coming weeks. That same rigor underpins its addition, in June 2026, to the NATO Information Assurance Product Catalogue (NIAPC), as the first Spanish solution in the Access Control category.
Sources
- Royal Decree 311/2022, of May 3, regulating the Esquema Nacional de Seguridad — BOE
- Esquema Nacional de Seguridad portal — CCN-CERT
- Catálogo de Productos y Servicios de Seguridad TIC (CPSTIC) — CCN-CERT
- Guide CCN-STIC 105, ICT Security Products Catalogue — Certification Body, CCN
- Centro Criptológico Nacional publishes a guide on the LINCE evaluation methodology — CCN-CERT
- CCN at SICUR 2026: “LINCE is a Spanish certification…” — Seguritecnia
- How to reach ENS High Category, stay in the Catalogue, and add new versions of my product — jtsec





