About These Release Notes
What this changelog covers, how Bedrock is versioned, and what's coming.
This changelog covers production releases of the Bedrock platform. It's curated: each entry describes what changed for you as a user, not every internal commit. The engineering-level changelogs live with the source and are available to assessors and partners on request.
How Bedrock is versioned
- Releases follow semantic versioning (
v1.2.0). The hosted platform's backend and web application version independently but ship together as one product — entries on the Bedrock CMMC Platform page are grouped by release date and describe the combined change. - Every release deploys to a staging environment first and reaches production only through a tagged, reviewed release. Database changes are additive — upgrades don't break in-flight work.
- Bedrock C3PAO is distributed as a container image to partners; its release notes describe image generations rather than semver tags.
Security fixes
Dependency and security patches are included in these notes when they affect the shipped product. If you believe you've found a vulnerability, see our vulnerability disclosure policy.
What's next
The next generation of the platform (Bedrock CMMC v2) is in active development, with a focus on CMMC Level 2 self-assessment workflows and MSP/MSSP partner operations. Features appear in this changelog when they ship to production — we don't document unreleased work here.