Logo Teldat

• Cybersecurity Glossary

What is the CPSTIC catalogue (CCN-STIC) and why it matters in public tenders?

The CPSTIC catalogue is Spain’s official list of Cybersecurity products and services approved for public sector use, managed by the National Cryptologic Centre (CCN) and published in guide CCN-STIC 105. It lists Qualified products, for sensitive information under the National Security Framework (ENS), and Approved products, for Classified information. For public bodies and their suppliers, being in the CPSTIC is effectively a condition of access to the Spanish public procurement market, especially for high category ENS systems. This page explains what the CPSTIC is, the difference between qualified and approved products, how it links to the ENS, and why it matters in public tenders.

What the CPSTIC is?

The CPSTIC, the Catalogue of ICT Security Products and Services, is the official catalogue of cybersecurity products and services approved for use in the Spanish public sector. It is managed by the National Cryptologic Centre, the CCN, which forms part of Spain’s National Intelligence Centre, and is published in guide CCN-STIC 105 and updated every month.

Its role is to give public bodies, and the private companies that supply them, a trusted reference of security solutions that have passed CCN evaluation. Rather than a marketing directory, it is a compliance tool: when a public system needs a firewall, an encryption product or an access control solution, the sensible first step is to look for it in the CPSTIC.

The catalogue exists because the public sector handles information that ranges from sensitive to formally classified, and it needs assurance that the products protecting that information have been independently vetted. Understanding the CPSTIC matters to any vendor or public buyer working with Spanish administrations, because it shapes what can actually be deployed and, often, what can even be tendered.

Qualified vs approved products

The CPSTIC is not a single flat list. Its two main categories, qualified and approved, correspond to different kinds of information and different levels of scrutiny. The table makes the distinction clear.

Aspect Qualified products Approved products
Information type Sensitive information under the ENS Classified information
Scope ENS categories basic, medium and high Restricted up to Secret
Typical evaluation Common Criteria, LINCE or STIC evaluation against the RFS More demanding process, higher bar
Reference guide CCN-STIC 106 CCN-STIC 102

The simple way to remember it: qualified is for sensitive information within the ENS, covering the categories most public systems fall into, while approved is reserved for classified information and carries a higher level of scrutiny. The catalogue also includes a third listing for conformity and governance solutions that help meet security rules.

The CPSTIC does not exist in isolation. It is the practical companion to the ENS, the National Security Framework, and the two are best understood together.

The ENS is the regulation that obliges Spanish public bodies and their suppliers to protect their systems and data according to a security category. That category can be basic, medium or high, set by the impact a security incident would have on the information and services. The ENS then requires organizational, procedural and technical measures to match.

This is where the CPSTIC comes in. When the ENS requires a technical security measure, the catalogue provides the vetted products to fulfil it. For high category ENS systems in particular, choosing qualified products from the CPSTIC is the expected path. In effect, the ENS sets the obligation and the CPSTIC supplies the trusted means to meet it, which is why the first step in any project is to define the ENS category, and only then look for catalogued products.

Why it matters in public tenders?

For vendors and public buyers alike, the CPSTIC has a direct, practical impact on procurement. These are the main reasons it matters when a tender is on the table.

1
A condition of market access
For companies selling cybersecurity to the Spanish public sector, being catalogued is not a bonus but often a requirement. Tenders for ENS systems, especially at high category or involving classified information, frequently require or strongly favour catalogued products, so a listing can be the gateway to bidding at all.
2
A signal of vetted quality
Inclusion in the catalogue reflects that a product has passed independent CCN evaluation. For a public buyer, that is assurance of reliability and security without having to run their own deep technical assessment, which simplifies and speeds up procurement decisions.
3
A route to ENS compliance
Because the catalogue is tied to the ENS, choosing catalogued products helps a public body demonstrate that its security measures meet the framework. It turns a compliance obligation into a concrete, defensible procurement choice.
4
A factor to plan for early
Because evaluation and listing take time, vendors that want to reach the Spanish public sector need to plan for the CPSTIC well ahead of a tender. Waiting until a specific opportunity appears is usually too late, so the catalogue shapes product roadmaps, not just individual bids.

How to consult the catalogue?

The CPSTIC is public and can be consulted on the CCN website. A clear order of steps makes it far easier to find the right catalogued solution.

1
Define your ENS category first
Before looking at any product, establish whether your system is basic, medium or high category, and whether it handles classified information. This determines which part of the catalogue applies to you and prevents wasted effort.
2
Identify the product family
The catalogue is organized by taxonomies or families, such as firewalls, encryption or access control. Knowing the technology category you need lets you jump straight to the relevant listings rather than scanning everything.
3
Filter by catalogue category
Match the listing to your needs: qualified products for sensitive information under the ENS, or approved products if you handle classified information. This narrows the options to those valid for your specific situation.
4
Check the current listing
Because the CCN updates the catalogue monthly, always confirm the current status, category and exact product version directly in the official CPSTIC before relying on it for a project or tender. The live catalogue is the authoritative source.

The CPSTIC and Teldat

The CPSTIC is about trusted, vetted infrastructure for the Spanish public sector, and that is a natural fit for a European manufacturer. Teldat brings both catalogue presence and the sovereignty context the framework values.

1
Products in the catalogue
Teldat has products listed in the CPSTIC, supporting their use in Spanish public sector systems under the ENS. Because listings are updated monthly, the exact products, versions and categories should always be confirmed in the official CPSTIC before a tender.
2
Aligned with the ENS
Teldat’s network and security portfolio is built to support deployment in ENS environments. Catalogue presence helps public bodies adopt Teldat infrastructure while demonstrating that their security measures meet the framework.
3
European Sovereignty and trust
The CPSTIC and the ENS are, at heart, about trustworthy technology for critical public systems. As a European manufacturer operating under European jurisdiction, Teldat aligns naturally with that goal, offering an alternative rooted in European sovereignty.
4
A portfolio for the public sector
From resilient SD-WAN connectivity to security with be.Safe Pro and be.Safe XDR, Teldat provides infrastructure suited to public administrations, backed by the trust that catalogue evaluation and European manufacturing represent.

Trusted infrastructure for public systems: the CPSTIC exists to give the Spanish public sector confidence in the security products it deploys. Teldat, with products in the catalogue and a European manufacturing base under European jurisdiction, fits that purpose. The CCN manages the catalogue and decides all listings, and the official CPSTIC is always the authoritative source for a product’s current status.

FAQ’s about the CPSTIC

❯ What is the CPSTIC catalogue?

The CPSTIC, the Catalogue of ICT Security Products and Services, is the official list of cybersecurity products and services approved for use in the Spanish public sector. It is managed by the National Cryptologic Centre (CCN), which is part of Spain’s National Intelligence Centre, and is published in guide CCN-STIC 105 and updated monthly. Its purpose is to give public bodies, and the private entities that serve them, a trusted reference of security solutions that have passed CCN evaluation, so they can be deployed with confidence in systems under the National Security Framework (ENS) or systems handling classified information. In practice it works as a compliance tool rather than a commercial comparison site.

❯ What is the difference between Qualified and Approved products in the CPSTIC?

The CPSTIC distinguishes two main categories. Qualified products are intended for handling sensitive information within the scope of the National Security Framework (ENS), in its basic, medium or high categories. To be qualified, a product typically holds a Common Criteria functional certification, a LINCE functional certification, or has passed a STIC evaluation against the Fundamental Security Requirements set out in CCN-STIC 140, following the process in guide CCN-STIC 106. Approved products are intended for handling classified information, such as Restricted, Confidential, Reserved or Secret, and go through a more demanding process described in guide CCN-STIC 102. In short, qualified covers sensitive information under the ENS, while approved covers classified information with a higher bar.

❯ How does the CPSTIC relate to the ENS?

The ENS, the National Security Framework, is the regulation that obliges Spanish public bodies and their suppliers to protect their systems and data according to a security category, which can be basic, medium or high. The CPSTIC is the practical tool that supports it: when an ENS system needs a security component such as a firewall, an encryption solution or an access control system, the reasonable first step is to look for it in the CPSTIC. For high category ENS systems in particular, using qualified products from the catalogue is the expected route. The two work together, with the ENS setting the obligation and the CPSTIC providing the vetted products to meet it.

❯ Why does the CPSTIC matter in public tenders?

For any company that wants to sell cybersecurity solutions to the Spanish public sector, being in the CPSTIC is not a decoration, it is effectively a condition of access to the market. Public tenders for systems under the ENS, and especially those at the high category or handling classified information, frequently require or strongly favour catalogued products. A solution that is not listed can be excluded from consideration regardless of its technical merits. Being in the catalogue therefore both signals evaluated quality and reliability, and opens the door to public procurement that would otherwise be closed.

❯ Is Teldat in the CPSTIC catalogue?

Yes. Teldat, as a European manufacturer of networking and cybersecurity equipment, has products listed in the CPSTIC catalogue, which supports their use in Spanish public sector systems under the ENS. Because catalogue entries, categories and the specific products and versions listed are updated monthly by the CCN, the current, authoritative detail should always be checked directly in the official CPSTIC catalogue on the CCN website before relying on it for a tender. As a European manufacturer operating under European jurisdiction, Teldat aligns naturally with the sovereignty and trust goals that the CPSTIC and the ENS embody. Teldat does not manage the catalogue or decide listings, which are the responsibility of the CCN.

Trusted European infrastructure for the public sector

The CPSTIC gives the Spanish public sector confidence in the security products it deploys. Teldat, with products in the catalogue and a European manufacturing base under European jurisdiction, provides infrastructure built for ENS environments.