Telefónica Tech achieves dual accreditation for SandaS GRC: ENS high category and inclusion in the CPSTIC catalogue

We have strengthened our position in the field of Cyber Security with SandaS GRC, our comprehensive platform for security governance, risk management, and regulatory compliance assessment, developed by Govertis, part of Telefónica Tech.

Our tool has recently been included in the Catalogue of ICT Security Products and Services (CPSTIC) of the National Cryptologic Centre (CCN), under the Security Governance and Compliance category. Additionally, we have renewed the high-categoy certification of the National Security Framework (ENS), which was already in place for the platform’s provision, maintenance, and support processes.

These recognitions position SandaS GRC as a benchmark solution for organizations required to comply with the highest security standards, particularly in the public sector, where contracting certified solutions is a mandatory requirement.

The platform offers comprehensive and efficient management of risk and regulatory compliance, tailored to multiple regulatory frameworks and aligned with the strictest requirements of the updated 2022 ENS.

The key features of SandaS GRC include:

  • Comprehensive multi-standard risk and compliance management, with support for assessing and automating maturity levels in line with the ENS at low, medium, and high levels.
  • Automatic application and verification of enhanced controls required by regulation, with traceable and documented justification for non-applicable controls (N/A).
  • Advanced security for data storage and access, aligned with Telefónica Tech’s international standards and guidelines.
  • Rigorous risk and control assessments based on international standards and independent audits.
  • Specialized modules for GDPR, business continuity, and other critical security management requirements.

Inclusion in the CPSTIC confirms that SandaS GRC has passed a rigorous technical and security evaluation by the CCN, ensuring trust, quality, and regulatory compliance.

This dual certification, inclusion in the CPSTIC and accreditation for the high category of the ENS, positions SandaS GRC as the only private solution that meets both requirements within the ‘Risk Analysis and Management’ service family, under the Security Governance and Compliance category of the CPSTIC catalogue. This distinction sets our solution apart from the rest of the market.

With this certification, we reinforce our commitment to delivering robust and innovative solutions that ensure the protection and efficient management of our clients’ information systems.