Skip to content
Foxx Cyberfoxxcyber/docs

CMMC Alignment

Our own compliance posture, stated plainly — what we claim and what we don't.

Foxx Cyber builds CMMC software, so we hold ourselves to the standard of saying exactly what our posture is — no more.

What we claim

  • The Bedrock platform's security program is built on NIST SP 800-171, with an internal System Security Plan maintained at assessment-objective granularity across all 14 domains.
  • Physical and infrastructure controls are inherited from AWS's FedRAMP-authorized services; application and configuration controls are implemented by Foxx Cyber as described throughout this section.
  • Our current CMMC Level 2 posture is self-assessment. Compliance state — including our POA&M — is tracked in a dedicated internal compliance repository with change history.

What we don't claim

  • We do not claim CMMC certification, FedRAMP authorization, or FedRAMP equivalency today.
  • We do not claim that using Bedrock makes your organization compliant. Bedrock manages your compliance program; your controls, policies, and evidence are still yours to implement.

Where a capability is optional or in progress — for example, per-user MFA enrollment versus organization-enforced MFA — the pages in this section say so explicitly. If you find a statement here that doesn't match what you see in the product, tell us; accuracy of this public SSP is itself part of our security program.

How this affects your assessment scope

If you use the Bedrock platform, it holds compliance working data for your program, so you should account for it in your own assessment scoping — see Bedrock as Your ESP for exactly how to document it, and the Shared Responsibility Matrix for the control-by-control split.

Last updated July 29, 2026