Enterprise GRC Platform
Tyndora for NIST 800-171 / CMMC
Defense contractors must protect Controlled Unclassified Information (CUI). NIST 800-171 sets the security requirements; CMMC certification proves it. Tyndora implements all 14 security requirements and automates CMMC assessment readiness.
NIST 800-171 & CMMC Framework
Contractors handling Controlled Unclassified Information (CUI) must implement the 110 controls of NIST SP 800-171, which form the basis of CMMC Level 2. CMMC 2.0 has three levels, and most CUI contracts require Level 2.
14 NIST 800-171 Domains
- Access Control β User identification, authentication, least privilege
- Identification & Authentication β Multi-factor authentication
- System & Communications Protection β Encryption, network segmentation
- Incident Response β CUI breach detection and reporting
Relationship to CMMC
CMMC 2.0 defines three levels. NIST SP 800-171 is the control basis for CMMC Level 2 β the level most DoD contractors handling CUI must meet.
- β Level 1 (Foundational): 17 practices, FCI, annual self-assessment
- β Level 2 (Advanced): 110 NIST SP 800-171 controls, CUI
- β Level 3 (Expert): adds 24 selected NIST SP 800-172 requirements
- β Tyndora maps your controls to the NIST 800-171 baseline behind Level 2
The 14 NIST 800-171 Families
The 14 control families (3.1β3.14) that make up the 110 requirements behind CMMC Level 2. Select any family to expand it and see what each requirement asks for.
Requirements shown are a faithful plain-language working summary of NIST SP 800-171 Rev 2 β not the full verbatim control text. Refer to the official NIST publication for authoritative wording.
NIST 800-171 / CMMC Implementation in Tyndora
From CUI identification to CMMC certification audit readiness.
CUI Protection & 14 Domains
NIST 800-171 requires protection of Controlled Unclassified Information (CUI). Tyndora implements all 14 security domains to prevent CUI disclosure.
- β AC: Access Control (4 controls)
- β AT: Awareness and Training (2 controls)
- β AU: Audit and Accountability (5 controls)
- β CA: Security Assessment (2 controls)
- β CM: Configuration Management (4 controls)
- β CP: Contingency Planning (3 controls)
- β IA: Identification and Authentication (3 controls)
- β IR: Incident Response (3 controls)
- β MA: Maintenance (2 controls)
- β PE: Physical Environment (3 controls)
- β PL: Planning (3 controls)
- β PS: Personnel Security (3 controls)
- β RA: Risk Assessment (3 controls)
- β SC: System and Communications (7 controls)
NIST 800-171 / CMMC STATUS
Target CMMC Level
Level 2 (Advanced)
NIST 800-171 Controls Required
110
Implemented & Tested
64 / 110 (58%)
Assessment Readiness
Targeting C3PAO assessment in ~12 months
CONTROL TESTING
Controls Tested
58 / 110 (53%)
Effective
46 / 58 tested
In Remediation
46 gaps on the POA&M
CUI Identification & Protection
CUI (Controlled Unclassified Information) requires handling per DoD standards. Tyndora tracks all CUI data flows and ensures protection controls are in place.
- CUI data inventory (what CUI do you have?)
- CUI flow mapping (collection, storage, access, transmission)
- Encryption of CUI (at rest and in transit)
- Access controls and audit logging for CUI systems
CMMC Certification Assessment
CMMC Level 2 assessments are performed by a C3PAO (CMMC Third-Party Assessment Organization); Level 3 is assessed by the DoD's DIBCAC. Tyndora prepares evidence and remediation plans for your target level.
Assessment Preparation
- β Authorized Assessor selection
- β Practice-level evidence collection
- β Pre-assessment readiness evaluation
- β Gap remediation and validation
DoD Compliance & Reporting
- β Cybersecurity Maturity Model Certification (CMMC)
- β Certification scope and validity (3 years)
- β DoD CMMC reporting and tracking
- β Continuous compliance monitoring
See CMMC Certification Ready
Book a discovery and we'll show you CUI protection, NIST 800-171 control implementation, and CMMC assessment preparation.
Book a discovery