Technical controls enforce TLS version and cipher standards across all services and flag non-compliant endpoints
Requiring TLS 1.2 or later with modern ciphers on every service enforces the encrypted-transit expectation that is part of A.8.20's network protection.
The technical facet configures every service to accept only TLS 1.2 or later with modern ciphers and reject legacy protocol fallback.