Once the decision has been made to certify one or more Managed Security Services, a process begins involving self-assessment, auditing, and, if the result is favorable, the application for the corresponding certificate from the National Cryptologic Center.
Knowing this process beforehand allows you to understand what happens at each stage and, above all, what the organization needs to move from one phase to the next.
The National Security Registry (RNS) itself outlines the procedure and answers some of the most common questions in its section dedicated to SSG certification.
The process begins by requesting a self-assessment
The first step is to request the self-assessment tool from the CCN (National Cryptologic Center) using the CCN-STIC 896 Guide and complete the sections corresponding to the services you wish to certify.
The self-assessment determines the degree of compliance with the applicable requirements and also establishes the first condition for continuing with the process: obtaining a score higher than 50% in all applicable sections.
Once this threshold is met, the organization can request a free audit from the CCN.
There is an important distinction for organizations that already hold certification in accordance with the National Security Scheme at the MEDIUM or higher level. Having it does not eliminate the need to carry out the self-assessment, although it modifies the information that must be completed. As specified by the CCN, in these cases the tabs corresponding to the applicable services must be completed and, with regard to the ENS, only the box provided to accredit that certification.
From Audit to Certificate Application
Currently, the National Cryptologic Center (CCN) itself conducts these audits, as there are still no Certification Bodies (CBs) or Technical Audit Bodies (TABs) accredited for this procedure.
The audit assesses the service's compliance with the requirements established in CCN-STIC 896. If the result is favorable, the entity can then apply to the CCN for the corresponding certificate for the evaluated service(s).
It is therefore important to distinguish between passing the self-assessment and obtaining certification. Achieving the required 50% allows an entity to apply for an audit, but does not in itself guarantee that the service is certified. A favorable outcome from this audit will open the possibility of formally requesting the certificate.
The process can be summarized simply as follows:
Request and completion of the self-assessment → meeting the required threshold → requesting an audit → favorable resolution → requesting the certificate from the CCN.
Currently, there is no set deadline for Managed Security Service providers to complete this process. Certification is currently voluntary.
However, the CCN itself recommends moving forward with the adaptation process. Information published by the RNS indicates that, in the future, certification may become a requirement to provide Managed Security Services to public entities, critical or essential infrastructure, as well as to become part of the National Network of SOCs.
This introduces a factor that should be considered when planning the process. Although there is currently no deadline, addressing certification in advance allows for distributing the adaptation work and prevents a future requirement from catching the SOC still in the early stages.
Having seen throughout this series what preparing for CCN-STIC 896 entails, how maturity levels work, and what a service must be able to certify, this final step allows us to place each of these elements within the formal procedure.
Certification thus ceases to be seen as a single milestone and becomes a journey with clearly differentiated phases, each with its own requirements and outcomes.