Skip to content
Foxx Cyberfoxxcyber/docs

What Is Bedrock GRC?

An introduction to Bedrock GRC, the governance, risk and compliance console Foxx Cyber hosts for its fractional-CISO practice and its partner assessment firms.

Bedrock GRC is a web console for running security programs on behalf of clients. Each client gets one record that holds the whole program: the business goals security has to serve, leadership's risk appetite, a risk register, framework assessments, the remediation roadmap (the POA&M), the policy and evidence library, vendor and asset registers, a calendar of what is planned with the client, the engagement log and a board-ready report.

Foxx Cyber built it as the console for its own fractional-CISO practice and hosts it. Partner assessment firms work in it by arrangement with Foxx Cyber: their assessors sign in to assess the clients they are assigned to and issue their results under their own name. There is no self-serve sign-up. For questions about access, write to support@foxxcyber.com.

Who signs in

WhoWhat they do
Foxx Cyber staffRun client programs: admins, consultants and read-only viewers. See Team and Roles.
Assessors from a partner firmAssess the frameworks their firm has been given on the clients they are assigned to, manage evidence, and issue the assessment. See Working as an Assessor.

People at the client never get an account. They read their own program through an expiring, read-only link (see The Client Portal).

What it does

AreaWhat you get
PortfolioEvery client you work, with primary-framework posture, open and above-appetite risks, overdue roadmap work, documents still to do, last contact, what is next on the calendar, and everything due in the next 30 days.
StrategyBusiness goals (horizon, priority, owner, how security supports them) and the client's risk appetite: a statement, a never-acceptable list, a 1 to 25 threshold, and an approval and review cycle.
RisksA scenario-based 5×5 register with inherent and residual scores, treatment, owner, review date, sign-off for accepted risks, and heat maps before and after treatment.
FrameworksAdopt any framework from the built-in catalog, assess each control (status, current and target maturity, narrative, where the evidence lives) or each of its objectives one by one, see roll-ups by group, carry answers across frameworks through crosswalks, and record quarterly snapshots with trend lines. CMMC Level 2 shows an SPRS score.
RoadmapThe POA&M in plain words: items by quarter with priority, owner, dates, cost and effort, linked to the risk, goal and controls they move.
Documents and evidencePolicies, standards, procedures, plans and evidence with a real lifecycle: versioned files, review, approval behind an explicit confirmation, periodic reviews, retirement and a full history.
Vendors and assetsA third-party register with dated reviews and contract dates, and an asset register with classification, criticality, impact ratings, recovery objectives, crown jewels and CMMC Level 2 asset categories.
CalendarKickoffs, on-site weeks, interviews, readouts, check-ins and deadlines for each client, with times in their own time zone.
Outside assessmentsHand a framework to a partner firm, let its assessors answer it, and receive the result as a frozen, numbered version with an assessment report PDF in the firm's name.
Client accessRead-only portal links for people at the client: no account, an expiry on every link, an optional passcode, instant revocation.
Board reportAn executive report as a page and as a PDF, which can be emailed from the console with a personal portal link per recipient.
MonitoringEverything that comes due across your clients in one list, the "loose ends" that have no schedule at all, and a personal calendar feed.
Import, export, backupThe whole client as one Excel workbook, any register as Excel or CSV, previewed imports, bulk document upload, a full per-client backup and restore, and CMMC Level 2 results in the DoD's assessment results template.

The framework catalog

The catalog is built into the application and shared by every client. It holds eight frameworks:

FrameworkAssessable
NIST Cybersecurity Framework 2.0106 subcategories
CMMC 2.0 Level 115 practices
CMMC 2.0 Level 2110 practices
NIST SP 800-171 Rev. 397 requirements
NIST SP 800-53 Rev. 5 (release 5.2.0)1,014 controls and enhancements
HIPAA Security Rule53 standards and implementation specifications
HIPAA Privacy Rule85 standards and implementation specifications
HIPAA Breach Notification Rule13 standards and implementation specifications

Crosswalks (1,618 links in all) connect them so an answer given once can inform or fill the others. Where each framework comes from, and what is not in the catalog, is on Frameworks Catalog and Sources.

Hosted by Foxx Cyber

Bedrock GRC is a hosted service. Foxx Cyber runs it, applies updates, and invites each person by email to the address they sign in at. There is nothing to install. Changes are listed in the Bedrock GRC release notes. Organizations that need to run it on their own infrastructure can ask about self-hosting.

Client records in Bedrock GRC can include sensitive material, such as a defense supplier's system security plan. How the service handles that data is described in Security Model.

What it is not

  • Not a certification or attestation tool. Bedrock GRC records an assessment of a client's program. It does not make anyone compliant, and a good score in it is not a certification. The board report and the client portal say so to the client, and every assessment report a partner firm issues carries "Not a certification" on every page.
  • Not a C3PAO assessment or an eMASS uploader. The CMMC Level 2 export fills in the DoD's results template as a head start for an assessor. Only a C3PAO uploads results to CMMC eMASS. See CMMC Level 2 Results for eMASS.
  • Not a client self-service portal. Clients read; Foxx Cyber staff and assigned assessors write.

Last updated October 9, 2026