- Q01Has Bubble ever pursued CMMC, FedRAMP, or GovCloud hosting?
- No. CMMC is not mentioned anywhere on bubble.io. FedRAMP is not mentioned. There is no GovCloud option even on Enterprise dedicated — Bubble's blog mentions more than twenty commercial AWS regions, but no DoD-eligible region. The position has been silent for the entire history of the product and there is no indication it will change.
- Q02Could a plugin or wrapper bring Bubble inside the CMMC boundary?
- No. The CMMC assessment evaluates the environment and its operating controls, not a JavaScript shim on top of it. Plugins run inside Bubble's browser runtime and Bubble's server runtime — neither is FedRAMP-authorised, neither can be brought inside the assessment boundary, and the C3PAO has no mechanism to accept either as evidence.
- Q03Is there any hybrid that keeps Bubble in the picture for CUI?
- No. CUI cannot be split through a commercial multi-tenant runtime. Even if the developer intends CUI to live elsewhere, Bubble's plugin runtime can read any page data, shared logs capture access events, and continuous backups retain data the developer thought was scoped out. The assessor cannot draw a defensible boundary around any of that.
- Q04How long does a CMMC-friendly rebuild take?
- Four to nine months for the rebuild on AWS GovCloud or Azure Government, with the Level 2 C3PAO assessment running in parallel toward the back half of that window. Roughly seven months end-to-end is typical for a well-scoped sub-contractor. Phase 2 of the rollout (Level 2 third-party) starts November 10, 2026, so the timing matters.
- Q05Does CMMC overlap with FedRAMP, HIPAA, or NIST CSF?
- The control libraries overlap heavily. CMMC Level 2 is built on NIST SP 800-171, which is itself a tailored subset of NIST SP 800-53 — the same control library FedRAMP uses. The DoD has signalled CMMC / FedRAMP reciprocity as a goal of the FedRAMP 20x programme. HIPAA shares the audit-logging and access-control families but has its own BAA chain on top.
- Q06Can you sign anything covering CUI on our behalf?
- Bubble will not — they have no CMMC or FedRAMP posture. AWS GovCloud signs the relevant federal contracts and inherits FedRAMP High; Azure Government does the same. As the engineering partner we sign the contractor agreements covering our access during the build and warranty period; the production C3PAO assessment is signed by the assessor against the rebuilt environment.