NIS 2 Protection Controls (PR): Technical and Organizational Measures in Execution

The NIS 2 Protection (PR) domain translates risk decisions into safeguards over identities, data, platforms, and infrastructure. Practical guide to PR controls: access, training, backup, platform security, and resilience.

February 03, 2026 2 min read

Printed policy document open on a desk with a pen and a stamp Made with AI
Contents
  1. Key takeaways
  2. PR control model in practice
  3. Minimum evidence set for PR readiness
  4. 90-day execution checklist
  5. FAQ
  6. Related reading
  7. Official sources

The NIS baseline Protection domain (PR) translates risk decisions into concrete safeguards over identities, data, platforms, and infrastructure. For compliance teams, the goal is to implement protection controls that are risk-based, consistently enforced, and supported by operational evidence.

Sources: ACN baseline obligations determination, ACN baseline reading guide

Key takeaways

  • PR controls are the main execution layer for reducing likelihood and impact of cyber incidents.
  • Baseline requirements cover identity and access, training, data security, platform security, and infrastructure resilience.
  • Several controls are explicitly risk-conditioned and must be justified through risk-assessment outputs.
  • Documentary evidence is required for implementation, monitoring, and periodic review.

Sources: ACN baseline obligations determination

PR control model in practice

1. Identity, authentication, and access control (PR.AA)

Define and manage identities, credentials, permissions, and physical/logical access controls, including stronger authentication where risk requires it.

2. Awareness and training (PR.AT)

Adopt an approved training plan, execute recurring awareness programs, and maintain completion evidence for relevant personnel.

3. Data security and backup (PR.DS)

Protect confidentiality, integrity, and availability of data at rest/in transit, and implement protected backups with restoration testing.

4. Platform security (PR.PS)

Manage software lifecycle, log generation and retention, and secure development practices aligned to organizational risk.

5. Infrastructure resilience (PR.IR)

Protect networks and environments from unauthorized use and maintain resilience-focused safeguards for critical services.

Sources: ACN baseline obligations determination, ACN baseline reading guide

Minimum evidence set for PR readiness

PR area Practical objective Typical evidence
PR.AAControlled access lifecycle and authentication governanceAccess policy, account lifecycle records, privilege reviews
PR.ATDemonstrable security awareness executionApproved training plan, attendance/completion logs
PR.DSData protection and recoverabilityData-protection procedures, backup records, restore test logs
PR.PSSecure platform operation and traceabilityPatch/change records, logging configuration, secure-dev procedures
PR.IRProtected and resilient infrastructureNetwork protection procedures, segmentation/access records

Sources: ACN baseline obligations determination

90-day execution checklist

  1. Reconcile access-control policies with identity lifecycle and privileged-access governance.
  2. Confirm risk-based authentication requirements and document exceptions where justified.
  3. Validate backup strategy and schedule restoration tests with documented outcomes.
  4. Review logging, retention, and secure software maintenance practices.
  5. Consolidate PR evidence packs by control family for audit readiness.

FAQ

Are PR controls purely technical?

No. The PR domain combines technical safeguards with organizational controls such as training, policy enforcement, and governance-approved procedures. Source: ACN baseline obligations determination

Is multifactor authentication always mandatory everywhere?

Implementation is risk-conditioned in the baseline model. Scope and modality should be aligned to risk assessment outcomes and documented rationale. Sources: ACN baseline reading guide, ACN baseline obligations determination

What is the minimum backup evidence expected?

At minimum, organizations should maintain backup protection records and periodic restore-test outputs demonstrating recoverability. Source: ACN baseline obligations determination

Official sources

This article was reviewed with AI tools for proofreading and error checking. Despite these checks it may contain inaccuracies: for compliance decisions, always refer to the official texts.

Self-assessment · NIST CSF 2.0 · ISO 27001

Cyber Check-up

A self-assessment that returns your company's cyber profile: its security posture and the recommendations to mitigate risks and start your cybersecurity journey.

Our service

NIS 2

We guide you to compliance with the NIS 2 Directive: requirements analysis, security measures, incident notification and documentation audit.

Learn more
Share this post:

Related news

February 07, 2026

NIS 2 Recovery Controls (RC): Operational Resilience and Service Restoration

The NIS 2 Recovery (RC) domain defines how entities restore operations after incidents and sustain resilience. Practical guide to restoration procedu…

February 10, 2026

NIS 2 operational registers for logs, backups, and recovery: practical guide to auditable evidence

NIS 2 baseline requires operational evidence beyond policies. This guide covers how to build auditable registers for logs, backups, restore tests, an…

February 06, 2026

NIS 2 disaster recovery plan: practical guide for an approvable ID.IM-04 document

The disaster recovery plan is mandatory under NIS 2 Appendix C (ID.IM-04). This guide covers what an approvable DR plan must contain, a practical tem…