Jul 2026 CMMC Phase 2 suspended — what it actually changes

Prove every control. Keep the proof.

Bedrock CMMC keeps one chain of custody from control narrative to evidence to the affirmation you sign in SPRS — so the day anyone asks you to prove it, you can.

How it works

One package, from first draft to final determination.

Two products carry your package through the whole lifecycle. The package your assessor reviews is the package you built — it never leaves the system.

  1. 1

    Build & mature

    Bedrock CMMC

    Author the SSP, work every NIST 800-171 objective, manage POA&Ms, and build the evidence package — for one organization or a whole client portfolio.

  2. 2

    Assess

    C3PAO Assessor Client

    Your assessor imports the finished package and runs the assessment inside their own environment. Nothing is exported, emailed, or rebuilt.

  3. 3

    Monitor & renew

    Bedrock CMMC

    Continuous monitoring keeps the certified package current every day, and feeds the next assessment cycle without starting over.

The assessed package becomes the baseline for the next cycle.

Bedrock CMMC

Everything the assessor will ask for, already in one place.

Author your SSP, work every control and objective, manage POA&Ms, and mature the evidence package your assessor will receive — with continuous monitoring built in, not bolted on.

Bedrock CMMC dashboard for Acme Defense: 110 requirements tracked, 24 evidence items, 17 assets inventoried, the Defense Contract Manufacturing System package at Level 2, upcoming continuous-monitoring tasks with due dates, and assessment history.
One view per packageRequirements tracked, evidence on file, and the ConMon tasks coming due.
Objectives

110of 110

Control-by-control work

Every NIST 800-171 objective, with assessment guidance beside it — not a checklist you fill in blind.

ConMon

Continuous monitoring

Health score, review schedules, and overdue alerts keep the certified package current between assessments.

package health94

SSP

SSP authoring

Generated from your live compliance data, so the document your assessor reads matches the package they open.

Evidence

An evidence library that reviews well

Every file hashed, dated, and linked to the objectives it satisfies. Review dates and owners on each one.

POA&M

POA&Ms tied to requirements

Each plan of action links to the controls it remediates and closes them when the work lands.

C3PAO Assessor Client

The assessor's side of the same chain. In use with assessment partners

A certified assessor imports the finished package and conducts the whole assessment inside their own environment. The data stays under the C3PAO's control, with no cross-boundary transfer to explain away.

An assessor's engagement for Acme Defense Corp in the Bedrock CMMC assessor portal, Controls tab: 110 requirements with the assessor's determination (Met, Not Met, Not Assessed, objectives assessed) beside the OSC's own package status for each control, plus tabs for Team, Planning, Findings, Evidence, SSP, Assets, POA&Ms, Providers, Notes, and Report.
Mid-assessment: the assessor's determination on every objective, side by side with what the contractor claimed — on the imported package, no re-entry.
  • Import the finished package from Bedrock CMMC — evidence pre-staged, SSP included
  • Walk all 110 objectives with MET / NOT MET / NOT APPLICABLE determinations
  • Structured findings aligned to the CAP, linked to specific controls
  • eMASS export and assessment report generation for delivery to the OSC

Runs in your environment

Deployed as a container inside the assessor's own VDI or private infrastructure. Assessment data never leaves your control.

Built for CAP v2.0 §3.19–3.20

The CAP requires assessment data to stay under the C3PAO's direct control. Self-hosted deployment is the architecture, not an option.

Who it's for

Wherever you sit in the lifecycle.

Defense contractors

Start in the same system that will carry you through assessment. One package, built once — no evidence handoffs, no rebuilding for your assessor.

Bedrock CMMC

Registered Practitioners

Guide every client in one platform. Manage client packages side by side, and hand each one to its assessor without leaving the system.

Partner program

MSPs & MSSPs

Run CMMC compliance as a managed service — a portfolio under one roof, shared process, per-client isolation, continuous monitoring across all of it.

MSP plan

Assessors & C3PAOs

Import the finished package and conduct the whole assessment inside your own environment. In use with assessment partners today.

Assessor client

Why we can build this

Practitioner-built, and checkable.

Foxx Cyber is a practitioner shop, not a marketing one. The proof we offer is the kind you can verify.

CISSP / CISM credentials

Founded by an active CMMC-domain practitioner with DoD and Air National Guard background.

Pursuing our own Level 2

We run Foxx Cyber on Bedrock CMMC. The platform assesses itself.

STIG-hardened deployment

FedRAMP-Moderate-aligned AWS controls, and a security posture we publish.

Practitioner guides

Written by the people building the platform.

All CMMC guides

See the whole lifecycle in one demo.

Thirty minutes. We walk a package from first control narrative to final determination, show you where your organization plugs in, and scope pricing on the spot.