Skip to content
Foxx Cyberfoxxcyber/docs

Bedrock CMMC Platform

Release notes for the hosted Bedrock CMMC platform — web application and API combined.

Release notes for the hosted platform, newest first. Each entry combines the web application and backend API releases that shipped together. Versions in parentheses are the deployed tags (application / API).

September 2, 2026 — Agent ISSO API, SPRS posture, and assessment prep

(web app v2 · v1.2.1 / API v1.6.1)

For contractors and MSPs. This release opens the platform to your own automation and puts the number a DoD contractor actually has to post — the SPRS score — front and center:

  • Agent ISSO — an organization-scoped API key for automation. An Owner enables it under Settings → Agent ISSO; Owners and Admins mint keys with a chosen expiry (30 to 365 days) and explicit scopes. Keys work only on the new /api/v1 API — read everything, plus the safe writes an ISSO makes (objective status and notes, evidence upload and linking, POA&M create and update). No deletes, no package, SSP-approval, team, or billing actions. Bring your own tooling — Claude Code, Codex, scripts — and pay your own model bill; Bedrock runs no model for you. See the Agent ISSO docs, the API reference, and the Claude Code quickstart.
  • SPRS posture on Controls — the Controls page for a Level 2 package now opens with your SPRS score (out of 110, with points at risk), a 14-family heat grid you can click to filter, family tabs with not-met counts, and a Next best actions list of the requirements that block certification because they cannot be POA&M'd. Level 1 packages show practices met (of 17). The score matches the SPRS summary in the XLSX export.
  • Assessment prep — the Assessment page becomes three tabs. Readiness checks every requirement against four gates (objectives met, evidence linked, implementation statement, policy or procedure reference) and lets you record examine / interview / test notes per objective. Affirmation lets an Owner record an SPRS self-affirmation with date, title, and scope; the history keeps score, affirmer, and expiry, and each affirmation downloads as an SPRS packet workbook. The existing C3PAO handoff moves to its own tab unchanged.
  • MSP: manage many — a Controls Matrix shows every requirement as a row and every client package as a column, with cells you can click straight into that package's control and a "most common gaps" strip; the Portfolio page gains a peek drawer with posture, SPRS, blockers, and POA&M counts without leaving the list; and a ConMon Calendar rolls every client's upcoming and overdue reviews into one 90-day view.

Also in this release: organization-wide MFA requirement. Under Settings → Users & Roles, an Owner or Admin can require multi-factor authentication for everyone in the organization. The page lists members who have not set MFA up yet, and they are guided through setup at their next sign-in (IA.L2-3.5.3).

August 28, 2026 — Your plan, visible in the portal

(web app v2 · v1.1.4 / API v1.5.3)

For contractors and MSPs. Plans are sold per system boundary with storage per boundary, and the platform has enforced those numbers since the August pricing release — but a refused request used to surface as a generic error with nowhere to go. Now the portal tells you where you stand and what to do about it:

  • Boundaries — the Packages page shows N of M boundaries. At the limit, New Package and Clone explain it and offer Add a boundary, which takes you straight to your plan on foxxcyber.com.
  • Storage — the upload dialog shows how much storage is left and won't send a file that doesn't fit (or exceeds the 100 MB per-file ceiling); bulk upload checks the whole batch. A banner appears at 90 % used with Add storage.
  • Seats — Contractor and MSP plans include your whole team, and the Users page now says so instead of counting against a cap.
  • Settings → Organization gains Manage plan and a boundaries meter that counts only purchased boundaries; an MSP's own compliance package is marked Own compliance and never counts.
  • Subscription status — a billing problem puts the workspace into a clearly labelled read-only mode (your data stays readable and exportable) until it's resolved; a cancelled subscription signs you out with an explanation and a link to manage it. The API now enforces both states.
  • Adding a boundary to an existing plan on foxxcyber.com is billed at the per-boundary price — never a second base fee.

August 26, 2026 — Assessors start their own engagements

(web app v2 · v1.1.3 / API v1.5.2)

For C3PAOs. Engagements no longer wait on a marketplace request — a lead assessor starts them from Start engagement on the Dashboard or Engagements page:

  • Import a package export — the contractor exports their boundary package (Assessment → Start & snapshot) and hands you the .tar through your own channel. Choose the file: you'll see when it was exported, which organization it came from, and what it contains before anything is created. Importing opens an Accepted engagement in Pre-assessment bound to that package. Only the manifest and table data are sent to the platform; evidence stays in the file because the package already lives here.
  • New external engagement — for a client that isn't on Bedrock. Enter the client, system, target level and catalog revision; the boundary is created under your firm's own compliance space, and you upload the evidence the client gives you from the Evidence tab.

Engagements now show where they came from — Imported or External — in the list and the engagement header.

August 26, 2026 — Assessor portal parity

(web app v2 · v1.1.2 / API v1.5.1)

For C3PAOs. The assessor workspace now covers everything the standalone assessment app did, so an engagement can run end to end on the platform:

  • Engagement lifecycle in one place — accept, start, submit for approval, complete with the CMMC status determination, and open a correction cycle; every completed determination is kept as an immutable snapshot.
  • QA reviews — request pre-assessment-form and final-report reviews from the engagement, with the independent-reviewer rule enforced and a lead self-attestation path.
  • Team and planning tabs — assign assessors and domains with a conflict-of-interest check, send proposals, keep the assessment plan, and watch progress by domain and by assessor.
  • Full objective assessment — the contractor's self-assessment beside your determination; examine, interview and test details; per-objective history; bulk determinations per control.
  • eMASS export wizard — the template v3.8 workbook (Assessment Results, Requirements, Objectives, OSC SSPs, Summary) plus Findings and POA&Ms, with a snapshot picker; JSON twin included.
  • Report — completion tracking over the required sections, a generated findings summary to edit from, preview and print.
  • Notes, discussion, and tags — append-only assessor notes, an @mention thread with an explicit customer-visible switch, and team-visible tags with a list filter.
  • Organization — manage assessors (temporary passwords, credentials, lead flag, skills), plus new Certificates and Calendar pages.
  • Quality of life — ⌘K / Ctrl+K command palette, spreadsheet previews in the evidence reader, dashboard throughput, and an "only engagements I lead" filter.

Certificates remain draft downloads for now, and the package export → upload hand-off to your C3PAO is unchanged.

August 26, 2026 — Two-factor authentication, redesigned

(web app v2 · v1.1.1 / API v1.4.0)

A patch release focused on one thing: making two-factor authentication easy to set up and use. It applies to every portal — contractor, MSP, RP, assessor, and administrator — and to both sign-in screens.

  • Guided setup — scan a QR code with your authenticator app (or reveal a setup key if you can't scan), confirm with a six-digit code, then save your backup codes. Three steps, each shown as you go.
  • Segmented code entry — codes are typed into six boxes and verified the moment the last digit lands; a wrong code clears and tells you what to do.
  • Backup codes done properly — numbered, grouped for readability, with copy and download, and an explicit "I've saved my codes" step before they disappear. At sign-in, choose Use a backup code to sign in with one; spacing and capitalization don't matter.
  • Clearer management — once on, the security page shows when two-factor was enabled, and regenerating codes or turning it off asks for a current code in a focused dialog instead of an always-visible field.

Existing enrolments are unaffected; no action is needed.

August 25, 2026 — Bedrock CMMC v2

(web app v2 · v1.1.0 / API v1.4.0)

The largest release since launch: Bedrock CMMC v2, a ground-up rebuild of the platform as six focused workspaces — for contractors, MSP and RP partners, assessors, guests, and administrators. v2 is a new application line, so its version numbering starts fresh at v1.x; it replaces the v1 web app while running on the same compliance data.

For contractors (OSCs):

  • Rebuilt compliance workspace — faster package, control, POA&M, asset, and SSP views across the board.
  • Evidence linked to controls and objectives — attach a single piece of evidence to the specific controls and assessment objectives it satisfies, and see linked-evidence counts throughout.
  • Self-service password reset — reset your own password by email, no support ticket required.
  • Help in reach — documentation and a support contact are one click away from every screen.

For partners (RP & MSP):

  • RP: your own compliance package is now fully workable — a partner firm's own "My Compliance" package is editable like any client's, with a guided onboarding start and clear context showing when you're acting on your own firm versus on behalf of a client.
  • RP: self-service multi-factor authentication — enrol, verify, manage backup codes, and disable MFA yourself.
  • MSP: portfolio operations — client portfolio management, evaluation sandbox entitlements, read-only guest oversight (including view-as-guest), and a team-activity view.

For assessors (C3PAOs):

  • A dedicated assessor workspace: review findings, add control notes and objective edit-locks, edit QA reviews, record conflict-of-interest disclosures, view customer readiness, and manage your organization profile and MFA backup codes.

Compliance & security:

  • NIST 800-171 Revision 3 — a multi-revision control catalog and a consent-first migration wizard, so you move from Revision 2 to Revision 3 deliberately rather than being switched over automatically.
  • Expanded audit trail (AU-2) — a defined security-event catalog with an administrator audit console, five-year retention, and administrative session revocation that takes effect immediately.
  • Multi-factor authentication across every portal — OSC, MSP, RP, assessor, and administrator accounts.
  • Security hardening — all known reachable dependency vulnerabilities cleared, a full source-level injection-scan remediation, and per-viewer sandboxed document previews.

August 2, 2026 — Partner platform groundwork

(web app v1.2.8 / API v1.3.0)

A backend release. The v1 web application was unchanged; the shared API gained MSP evaluation-sandbox entitlements (per-organization controls over sandbox capabilities) and Registered Practitioner partner API parity, the foundation the v2 partner workspaces build on.

June 10, 2026 — Continuous monitoring accuracy

(app v1.2.8 / API v1.2.7)

  • Per-requirement monitoring frequencies — continuous-monitoring schedules now honor the frequency set on each individual requirement instead of a single package-wide cadence.
  • Review-anchored schedules — next-review dates are computed from the last completed review, and the web app and API now use identical date semantics, so day counts match everywhere they're shown.

May 28 – 31, 2026 — Partner administration and invitations

(app v1.2.4 – v1.2.7 / API v1.2.3 – v1.2.6)

  • Full organization administration for RP partner firms — partner admins can now edit their organization profile, manage team members, transfer ownership, and perform account recovery (password reset, MFA reset, account unlock) without contacting support.
  • Team-member invitations — RP partners can invite team members by email; invitees get a working activation page and clear status feedback throughout the flow. Fixed an email-encoding bug that could corrupt activation links in some mail clients.
  • Evidence upload hardening — uploads to evaluation sandboxes are correctly signed for server-side encryption, upload failures now surface the real error instead of a generic message, and long filenames no longer break the upload dialog.

May 11 – 20, 2026 — RP workspace and seamless sandbox conversion

(app v1.2.0 – v1.2.3 / API v1.2.0 – v1.2.2)

  • Sandbox-to-paid conversion is automatic — when a sandbox evaluator purchases a subscription, their sandbox organization converts in place: dedicated encrypted storage is provisioned, quotas lift to the purchased tier, and existing work carries over. No re-entry, no lost data.
  • RP owner role — every partner organization now has a designated owner with the ability to transfer ownership; owners can't be removed until ownership is transferred, preventing orphaned organizations.
  • RP workspace improvements — partner-shaped account settings, an observation dashboard for client engagements, and fixes for MFA status display and notification permissions for partner users.
  • Reliability — deleting a compliance package that had partner consultant access no longer fails.

April 8, 2026 — v1.1.0: CAP v2.0 assessment lifecycle

The largest release since launch, aligning the platform with the CMMC Assessment Process (CAP) v2.0.

For contractors (OSCs):

  • Assessment phase visibility — see exactly where your assessment is in the four-phase CAP lifecycle (Pre-Assessment → Assessment → Report → Close-Out), with days-in-phase and appeals/re-evaluation windows.
  • Readiness checklist — an interactive pre-assessment checklist (level-aware: 8 items for Level 2, 4 for Level 1) you work through with your assessment team.
  • Assessor messages — read comments your assessor team chooses to share with you, directly in the engagement view.
  • Certificate card — view your certificate status, dates, and POA&M close-out countdown once issued.
  • Richer controls table — SPRS point values, objectives-met counts, linked-evidence counts, and last-change dates on every control.
  • SSP evidence rendering — the System Security Plan view now renders linked policy and procedure evidence inline.

For assessors (C3PAOs):

  • Portfolio dashboard — KPI rollups across all engagements: at-risk engagements, QA reviews due, certificates expiring, POA&M close-outs due.
  • Conflict-of-interest register — disclosed conflicts block team assignment on affected engagements automatically.
  • Independent QA gates — assessments can't advance past pre-assessment until an independent reviewer (enforced: not on the assessment team) approves; final reports carry the same gate.
  • In-app notifications — phase advances, QA assignments, @mentions, and certificate issuance.

Platform: dependency security patches (including high-severity advisories in XML and utility libraries), Node.js 22 runtime, serialized deployments for safer rollouts.

March 25 – April 2, 2026 — v1.0.x: Initial release

  • v1.0.0 (March 25) — first production release of the Bedrock CMMC platform: compliance packages, the full CMMC Level 1/Level 2 controls catalog with 321 assessment objectives, evidence management, POA&Ms, asset inventory, SSP generation, and assessment engagements.
  • v1.0.1 – v1.0.4 — launch hardening: admin session timeout with idle detection, per-organization storage provisioning, evidence upload fixes, and SSP evidence mapping.

Last updated September 2, 2026