Skip to content
Foxx Cyberfoxxcyber/docs

Bedrock C3PAO

Release notes for the Bedrock C3PAO assessor container.

Bedrock C3PAO is distributed to partners as a container image, so its releases are image generations rather than semver tags. Partners pull the image from the Foxx Cyber registry; each entry below describes what changed between image generations.

July 2026 — Fully air-gapped architecture

This generation completes the transition to a fully air-gapped assessor application: the container makes no network calls and needs no connectivity to operate. Assessment data enters only through package import.

  • Direct package import with a guided wizard — the app now imports the Bedrock CMMC package export (.tar bundle) directly, the format the platform actually produces. The wizard validates checksums, previews the package contents (tables, evidence, size) before anything is written, and finishes with a direct link to the new assessment. Importing the same package twice creates two independent engagements — a re-import can never overwrite recorded assessor results.
  • Evidence Reader — a full-screen, side-by-side reading workspace: evidence rendered on the left (PDFs and images inline), the control's objectives and determination forms on the right. Navigate all 110 controls without leaving the reader; the split is drag-resizable.
  • External assessments at full parity — engagements created outside a Bedrock package import now ride the same data plane as imported ones: the full seeded catalog (110 requirements, 321 NIST 800-171A objectives), the same determination forms, findings, phase workflow, progress and SPRS statistics, eMASS export, and the Evidence Reader. Any assessor on the team can record findings and upload evidence.
  • Offline parity sweep — every assessor flow now works air-gapped: readiness sign-off, phase transitions and Start Assessment, recording and submitting results, control detail pages, the SSP long-form view, the evidence repository, certificates, team and workload views, and the conflict-of-interest guard during team assignment.
  • Connection-era UI retired — the connection page, sync actions, and license plumbing are gone; local admin user management works fully offline with fail-closed deactivated accounts.

Earlier in 2026 — Assessment workspace foundations

  • Pre-assessment readiness workspace — a fully manual, artifact-backed 8-item checklist with lead-assessor sign-off, written waivers, and a complete audit trail; readiness artifacts are stored locally and export as an audit bundle (manifest, checklist, audit log, notes, artifacts).
  • Living notes — assessors keep working notes on the Review tab; every edit is preserved as an immutable revision log for non-repudiation.
  • Schedule & logistics — kickoff date, on-site window, phase targets, and location notes per engagement.
  • eMASS workbook export and report generation — export findings as an eMASS-compatible Excel workbook and generate assessment report PDFs.

Because the app is air-gapped, updates are pulled deliberately by the partner — nothing updates itself. See Installation for how image updates are applied, and Where CUI Lives for why the air-gapped design matters.

Last updated July 29, 2026