Skip to content
Foxx Cyberfoxxcyber/docs

Import and Export

Take a client's program out as an Excel workbook or CSVs, bring spreadsheets back in through a row-by-row preview, and bulk-upload documents and evidence.

A client's Import / export page (the button in the client header) moves data in and out in bulk. Every import is previewed row by row, nothing changes until you confirm, it is applied in one transaction, and an import never deletes anything.

Everyone on the client's team can download the exports, including people who only read it. Importing, bulk uploads and the full backup need edit access to the client (admins, and consultants whose access there is Edits). On an archived client, exports and the backup still download, but nothing can be imported or uploaded. Assessors from a partner firm have no access to this page. See Team and Roles.

Export

ExportWhat you get
Whole clientOne Excel workbook with a sheet for every register and every adopted framework's assessment. Edit it and import it back, or keep it as a record. Uploaded files stay in the app; the document sheets list their names.
One registerAny sheet on its own, as Excel or CSV: profile, contacts, goals, risks, roadmap, vendors, assets, documents, evidence, agreements, engagement log, and each adopted framework's assessment. The same columns import back.
Full backupA ZIP with every record, the full document history and every file. Shown to people with edit access. See Client Backup and Restore.
A framework's catalogFrom the Frameworks page in the sidebar: the reference catalog with its crosswalks, as Excel or CSV.

Exports are written to be safe to open: CSV cells that could be read as spreadsheet formulas are neutralized, and Excel exports contain values only, never formulas.

Import a spreadsheet

Under Import a spreadsheet, upload an Excel workbook or a CSV (up to 10 MB, and at most 500,000 cells for a CSV). It can be:

  • a workbook or sheet you exported from Bedrock GRC and edited; or
  • a spreadsheet from anywhere else: a risk register, a POA&M, a policy list, a meeting log.

Choose What it holds (or let Bedrock GRC work it out from the sheet names and headers) and, for assessment answers, the Framework. Then Upload and preview. The Review the import page lists every row and what it changes: for an updated value, the value now struck through and the value it becomes (for a long text, the part around the change). Choose Import n changes to apply them, or Discard.

How rows are matched

  • A row with a reference (R-012, RM-004, DOC-007, V-004, A-017) updates that record, or creates it with that number.
  • Without a reference, a row whose title matches an existing goal, risk, roadmap item or document updates it; a row whose name matches a vendor or asset updates it; a contact matches by email or name. Anything else is added.
  • Roadmap rows can name a risk (R-012) and controls, for example CSF 2.0 PR.AA-01; CMMC L2 AC.L2-3.1.1.
  • An asset's Vendor column names a vendor, including one added on the Vendors sheet of the same file.
  • A vendor's Last reviewed date records a new review only when it is later than the latest one on record.

How values are applied

  • A column you leave out is not touched.
  • A blank cell clears an optional field. Required fields and choice lists keep their value when blank.
  • Rows with problems are listed and left out; the rest apply together or not at all.
  • The plan is rebuilt against the live data when you confirm, so what is applied reflects any change made since you opened the preview.

Documents in a spreadsheet

Version columns on the document sheets only seed documents that the import creates. New versions of existing documents come from the document page or from a bulk upload.

Pending imports you have not confirmed are listed at the top of the page under Waiting for your review. Each person sees only their own. A preview waits up to two hours for a decision; Discard throws one away sooner.

Upload documents and evidence in bulk

Under Upload documents and evidence in bulk, upload many files at once, or one ZIP with folders. The page shows the size limit for one upload: by default 200 MB in all and 25 MB per file.

  1. Say what they are. Choose a type for every file, or let Bedrock GRC work it out from folders and file names (a Policies or Screenshots folder, a name like Access Control Policy v2.1.pdf). Choose a status (draft, in review, or approved and in effect; approved needs approved by and approved on), a version, a review cycle and an owner for new documents.
  2. Or include a manifest. Put manifest.xlsx or manifest.csv with the files (or at the top of the ZIP) to give each file its own title, type, version and approval. Download a manifest template from the page.
  3. Review the preview. The Review the upload page shows what will happen to each file: a new document, or the next version of a document already in the library (a file whose name matches a library document joins it). Change or skip any file, and choose Update preview to see the result.
  4. Confirm with Import n files, or Discard the upload.

One upload stages at most 500 files, and a ZIP that lists more than 5,000 files and folders is refused before anything is read. When there are more than 500 files, the first 500 are staged, the page names the first file left out, and the status, approval and version you chose still apply to the staged files.

A bulk upload can also attach a signed final to a draft that is already open, and approve it. An approved file older than the version in effect is recorded as history and changes nothing in effect.

Files are encrypted and stored as soon as they are uploaded, but stay staged until you confirm. Unconfirmed uploads are deleted after about two and a half hours. Executable and script files are refused.

Folder names map to types, and a Contracts folder is read as engagement agreements (your own paperwork, kept off the portal). If the folder holds the client's vendor contracts, change their type to evidence on the preview.

Assessment answers and eMASS workbooks

  • Assessment answers import from a framework's exported sheet, or from another tool's sheet whose headers name the control (for example "Control ID", "Requirement" or "Practice") and its status. Use Import answers on the framework's assessment page to pick the framework up front.
  • A row that marks a control not applicable needs a reason in its narrative column, or it is listed as a problem and left out.
  • Rows for a framework a partner firm is assessing are skipped, and the preview says how many; the rest of the import applies. See Assigning a Firm.
  • CMMC Level 2 Assessment Results workbooks (the DoD eMASS template) import through the same preview. See CMMC Level 2 Results for eMASS.

Last updated October 9, 2026