Skip to content
Foxx Cyberfoxxcyber/docs

Bedrock GRC

What's new in Bedrock GRC, the governance, risk and compliance console for Foxx Cyber's fractional-CISO practice and its partner assessment firms.

Bedrock GRC is hosted by Foxx Cyber and is updated continuously: each change is deployed after it passes the automated tests and security scans, so on the hosted service there is nothing to install and no version number to upgrade to. Self-hosted deployments run released image tags (see Self-Hosting); entries here are dated rather than numbered, so read every entry dated after the release you run. This page summarizes what changed, newest first. The Bedrock GRC documentation describes how everything works today.

October 2026

October 9 — Enterprise release: accounts, sign-in and client access

For practice owners, staff and partner assessors. The last list says what you need to do.

Passwords and sign-in

  • A password policy for the whole team, set by admins on the Team page following NIST SP 800-171 requirements 3.5.7 and 3.5.8: a minimum length (14 characters by default, never fewer than 12), an uppercase letter, a lowercase letter, a digit and a symbol or a space, at least 4 characters changed from the current password, and the last 5 passwords remembered. Commonly used passwords, and passwords containing the person's name, email or the firm's name, are always refused. See Password Policy.
  • A live checklist under every new-password field ticks off each rule as you type, and a refused password lists every rule it breaks.
  • Existing passwords are checked at sign-in. A password that falls short of the policy still signs in, but only as far as Account, where the person chooses a new one and is told why. Team shows Below password policy until they do. See Password Policy.
  • Temporary passwords: admins can generate one that meets the policy, from Reset password… in the person's row menu on Team. A reset is checked against the person's own earlier passwords, each admin can try 8 resets (refused ones included) in any 15 minutes, and a refused reuse is recorded in the audit log. See Team and Roles.
  • Lockout: 10 failed attempts in a row lock an account for 15 minutes, with an email to the person and Unlock now for admins. The lock holds for single sign-on too, and a refused single sign-on never ends it. A browser the person has signed in from before is not held by the lock. See Your Account and First Sign-In.
  • Sessions: admins set an inactivity timeout and a total length (30 minutes and 12 hours by default), and everyone can see and sign out their own sessions on Account. See Sessions.
  • Single sign-on with Microsoft Entra ID, Google Workspace or another OpenID Connect provider, set up per firm. Each person links their own account; a firm can require single sign-on for the people who have linked, and admins always keep their password. See Single Sign-On.
  • Two-step sign-in: move to a new phone yourself, with a current code or a recovery code. Setup is fixed: pressing Enter (or a phone keyboard's Go key) in the code box used to make a new QR code behind the one just scanned, so no code could match; Enter now confirms the code. Start over with a new code is its own button and asks first. Authenticator apps that showed a "+" in the account name now show a space. Six-digit codes may be typed with spaces or hyphens, and recovery codes with or without their hyphen. New recovery codes are shown for 10 minutes after they are made, and Make new codes asks first. See Two-Step Sign-In.

People and clients

  • Per-client access: an admin sets each consultant to edit or only read each client they are on. See Team and Roles.
  • Invitations by email, with a one-time link valid for 7 days, and offboarding in one step: the account is disabled, its sessions end, it leaves every client, its calendar feed stops, and the invitations it sent and the client access links it made are revoked. See Team and Roles.
  • Archiving closes a client: read-only for everyone, admins included, hidden from assessors, and its client access links revoked for good. Restoring the client does not bring the links back. Clients archived before this release have their live links revoked when it is installed, each recorded in the audit log. An admin can then delete an archived client permanently. See Clients and the Portfolio and Deleting a Client.
  • Search across clients for staff. See Search.

Records and the console

  • The audit log: every change, sign-in and download across the practice, with every action in words, filters by person, client, action and date, numbered pages with a count, and a CSV export. Refused sign-ins are recorded too: a password refused because the firm requires single sign-on, an assessor refused because two-step sign-in is unavailable, an account disabled or locked at the code step, and single sign-on sign-ins that failed or were refused. A single sign-on that relies on the provider's multi-factor sign-in is recorded as mfa:idp. Each client's Engagement tab shows its own trail. See Audit Log.
  • Times in the practice's time zone on every page and in emails, and "today" for due and overdue dates follows it too. The audit log's CSV export keeps UTC.
  • A refreshed look: each form field shows its own message when something needs fixing, a refused form keeps what you typed (never passwords), confirmations open inside the page rather than as browser pop-ups, and long lists page. See Finding Your Way Around.
  • Pages that say what they do: every action on a person is in one menu on their Team row; Account opens with a How you sign in card; the Frameworks tab keeps its less common actions in a row menu; registers have views with their own headings (Live risks, Vendors due a review), and each heat-map cell lists its risks; the overview, report, portal and email say Live risks; a new client's overview lists its first steps; Monitoring and the portfolio page past 50; and assessors get a read-only Documents tab of the policies in effect.
  • Partner firms keep their work to themselves: evidence an assessor adds belongs to their firm, so another firm's assessors on the same client never see it and its issued versions leave it out. Assessors no longer see the practice's internal notes on vendors, assets and calendar events, vendor contract dates, or a client's status, service tier and review date. See Working as an Assessor.
  • Issued versions say where they came from: a version restored from a backup is marked Restored, and a version issued within 30 days after an admin reset the issuing assessor's password, two-step sign-in or single sign-on link says so on its page and in its PDF. See Issuing an Assessment.
  • Safer uploads and backups: ZIPs listing more than 5,000 entries and CSVs over 500,000 cells are refused before they are read; client backups leave out the audit log's IP addresses; a restore lists its first five warnings and never shows raw database errors.
  • A sign-in notice admins can show above the sign-in form. See Branding.
  • Self-hosting is available on request. See Self-Hosting.

What to do

  • Admins: review the password policy on the Team page. The defaults apply until you save it.
  • Everyone: under the default policy, if your password is shorter than 14 characters, lacks one of the required kinds of character, is a commonly used password or contains your name, email or the firm's name, you will be asked to choose a new one at your next sign-in. No admin needs to do anything.
  • Staff who archive clients: archiving now revokes the client's access links for good. If the client comes back, make new links for the people who need them.
  • Admins who offboard someone: their client access links are always revoked. Make new links for any client contacts who still need one.
  • Partner assessors: two-step sign-in is required for you whatever Foxx Cyber's own team policy is. If your firm uses single sign-on, link your account from Account → Single sign-on before your firm turns on Require single sign-on.

October 8 — Client calendar

  • A Calendar tab for each client: kickoffs, on-site weeks, interviews, readouts, program reviews, monthly or quarterly check-ins, deliverables and milestones, all day or at a time in its own time zone, with the place and how to join. See The Client Calendar.
  • Next up on the client overview and the portfolio. Events also appear on Monitoring and in your calendar feed, repeating ones as repeating events.
  • Events marked for the client appear on their portal's home page (title, dates, time and place, never your notes). Log it in the engagement log turns a past event into an engagement log entry.

October 8 — Move a CMMC Level 2 client to NIST SP 800-171 Rev 3

  • From the CMMC Level 2 row, Compare with SP 800-171 Rev 3 lays NIST's own Rev 2 to Rev 3 change analysis against the client's answers, with a suggested action for each practice that you can change.
  • Move to Rev 3 copies the answers across in one step. CMMC Level 2 answers are never changed, existing Rev 3 answers are never overwritten, withdrawn practices merge into the requirements that absorbed them, and every carried answer says where it came from and asks for a review. Linked documents and open roadmap items follow. See Moving to NIST SP 800-171 Rev. 3.

October 8 — Assess objectives one by one

  • On CMMC Level 1 and Level 2 and NIST SP 800-171 Rev 3, answer each assessment objective, determination statement or organization-defined parameter as met, not met or not applicable, with a note.
  • Saving can set the control's status from its objectives. The framework page shows how many objectives each control has answered, and issued assessments list the objectives not met under each finding. See Assessing Controls.

October 8 — HIPAA Privacy and Breach Notification Rules

  • Two new frameworks from the text of 45 CFR Part 164 on the eCFR: the Privacy Rule (164.502 to 164.530, 85 standards and implementation specifications) and the Breach Notification Rule (164.404 to 164.414, 13). See Frameworks Catalog and Sources.

October 8 — Outside assessment firms

  • Assessor accounts for a partner firm. An admin adds the firm on the Team page, adds its assessors, and assigns each one to a client from the client's profile. Assessors see only those clients, and there only the frameworks their firm is assessing, the evidence library, the program documents in effect, the calendar, and goals, assets and vendors for context. Two-step sign-in is always required for them. See Working as an Assessor.
  • Hand a framework to a firm. On a client's Frameworks page, Assessed by in the framework's row menu gives it to the firm. Only its assessors can change the answers; Foxx Cyber staff read them, and crosswalk fills and imports leave them alone until the framework is handed back. See Assigning a Firm.
  • Issued assessments. When the work is done, the assessor issues it: every answer, who gave it and the evidence linked at that moment are frozen as version 1, 2, 3 and so on. A version is never edited; a correction is the next version. Issuing waits until every control in scope has been answered by the firm and every "not applicable" has a reason. See Issuing an Assessment.
  • An assessment report PDF in the firm's own name, logo and colours, with results by group, findings, not-applicable reasons and evidence references. Every page says "Not a certification", and the firm's own disclaimer closes the report.
  • Plan from a finding. Staff open a finding and choose Plan this to start a roadmap item that keeps its link to the issued version.
  • Branding per firm on the Branding page, and the firm's name on every audit log entry.
  • Backups now carry firm assignments, issued versions and their roadmap links. A restored client never brings an assessor's access back with it.
  • Server logs no longer record the private part of portal links and calendar feed addresses.

October 8 — "Not applicable" needs a reason

  • Marking a control not applicable needs a reason in its narrative, on the page and in spreadsheet and eMASS imports.
  • The crosswalk never copies a "not applicable" answer to another framework.
  • Not-applicable controls no longer count in maturity averages, so a client is scored only on the controls in its scope. Older answers without a reason are flagged.

September 2026

September 25 — Bedrock GRC first release

  • One record per client: business goals and risk appetite, a 5×5 risk register with heat maps before and after treatment, framework assessments, the remediation roadmap, and the engagement log.
  • Frameworks: NIST CSF 2.0, CMMC Level 1 and Level 2 (with an SPRS score), NIST SP 800-171 Rev 3, NIST SP 800-53 Rev 5 scoped to a Low, Moderate or High baseline (with or without privacy), and the HIPAA Security Rule. Crosswalks carry answers between them, and quarterly snapshots draw trend lines.
  • Documents and evidence with versions, client review, approval, periodic reviews and retirement, plus starter sets linked to controls.
  • Vendor and asset registers with dated vendor reviews, contract dates, crown jewels and CMMC asset categories.
  • Client portal: read-only links that expire, with an optional passcode and instant revocation; every open and download is recorded.
  • Board report as a page and a PDF, under the practice's branding, which can be emailed from the console with a personal portal link per recipient.
  • Monitoring of everything that comes due across your clients, "loose ends" with no schedule, and a personal calendar feed for Outlook, Google or Apple Calendar.
  • Import, export and backup: the whole client as an Excel workbook, any register as Excel or CSV, previewed imports, bulk document upload, full per-client backup and restore, and CMMC Level 2 results in the DoD's assessment results template.
  • Two-step sign-in with an authenticator app and recovery codes, which an admin can require for the whole team.

Last updated October 9, 2026