[6.34.1.0] 09-14-2026
Enhancements
Control Guidance, Assessments & Compliance
- Improved Control Guidance in Nova: Enhanced control guidance with clearer base guidance and supplemental profile guidance, helping users better understand control requirements during assessment and authoring.
- Improved SSP and Control Assessment Experience: Enhanced control assessment workflows with clearer control statuses, improved navigation, and usability improvements.
- Improved Assessment and Risk Management: Enhanced Risk Assessment Wizard behavior, Control-to-Requirement mapping, continuous monitoring assessments, and risk scoring workflows.
- Improved Control and Compliance Workflows: Improved control status information, assessment workflows, and compliance-related navigation for a more consistent authoring and review experience.
- Improved Inheritance Management: Enhanced the handling and configuration of inherited controls and inheritance models.
Report Builder & Compliance Reporting
- Improved Report Builder: Enhanced module selection and reporting capabilities, including support for tenant-specific module names and additional modules such as Control Implementations and Interconnections.
- Improved POA&M and Compliance Reporting: Enhanced filtering, drill-down behavior, exports, and large-data-set handling for POA&M and compliance reporting.
- Improved FedRAMP and eMASS Exports: Improved export accuracy for nested parameters, operational requirements, severity information, and POA&M data.
Workflow & Automation
- Improved Workflow Experience: Enhanced workflow authoring and execution for configuring branches, assignments, approvals, and workflow steps.
- Improved Webhook Reliability: Improved webhook management and event-subscription handling for a more reliable automation experience.
Vulnerability Management
- Improved Vulnerability Management: Enhanced vulnerability tracking and reporting, including vulnerability status information, asset counts, KEV reporting, vulnerability trends, and vulnerability ingestion behavior.
- Improved Vulnerability Data Reliability: Enhanced vulnerability synchronization and ingestion workflows to reduce duplicate or incomplete records and improve asset associations.
Artifact, Catalog & Import Workflows
- Improved Artifact and Catalog Workflows: Enhanced catalog updates, archive imports, artifact restoration, and profile/catalog display behavior.
- Improved Data Import and Integration Reliability: Improved reliability across vulnerability, checklist, OCSF, catalog, and other data-import workflows to reduce duplicate or incomplete records.
Form & Questionnaire Management
- Improved Form Builder: Enhanced validation and conditional-field behavior to provide more immediate and accurate feedback when building and completing forms.
- Improved Questionnaire Management: Enhanced questionnaire assignment, validation, access controls, and form behavior for a more consistent management experience.
Navigation & User Experience
- Improved Nova Navigation and User Experience: Refined Nova navigation, workspace tooltips, application headers, and other interface elements for a more consistent and intuitive experience.
- Improved Accessibility: Enhanced accessibility through improved table semantics, ARIA support, dark-mode color contrast, report tables, and form validation messaging.
Authentication & SSO
- Improved SSO and Authentication Experience: Enhanced authentication behavior across SAML, OIDC, and SSO environments, including clearer login diagnostics and more reliable handling of configured authentication settings.
Fixes
Authentication, SSO & Session Management
- Login and Authentication: Resolved multiple issues that could prevent users from logging in correctly, including incorrect errors for deactivated users and authentication configuration and validation issues.
- SSO Session Handling: Resolved issues affecting SAML session handoff and identity-provider session handling.
- Logout Behavior: Resolved an issue where logging out of RegScale did not terminate the associated identity-provider session, which could cause the next SSO login to reuse the previous identity.
- OIDC Configuration: Resolved issues involving OIDC audience comparisons and encryption-key configuration that could cause valid configurations to fail.
- Login Diagnostics: Improved authentication logging and diagnostics to make OIDC and other login failures easier to troubleshoot.
- Login Username Handling: Resolved an issue where usernames entered through an SSO login form were not consistently handled during authentication.
- Nova Login: Resolved an issue where Nova could remain indefinitely on Loading workspace data... after login.
Security
- Authentication & Authorization: Strengthened authorization controls across authentication, questionnaire, workflow, vulnerability, RBAC, GraphQL, and other API endpoints to prevent unauthorized access to protected functionality and data.
- Session & Credential Protection: Strengthened protection of authentication sessions and credentials, including session handoff handling and safeguards around externally managed credentials and SSO/LDAP administrators.
- Input & Log Handling: Improved sanitization and handling of user-provided input in logs and application content to prevent malformed log entries and unsafe content from being persisted or interpreted.
- AI Prompt Protection: Strengthened handling of untrusted content supplied to AI processing to reduce the risk of unintended prompt manipulation.
- Security Dependencies: Updated application dependencies and container components to address identified security vulnerabilities and improve the overall security posture of the platform.
POA&M & Compliance Reporting
- POA&M Export Reliability: Resolved issues that could cause POA&M exports to time out or consume excessive resources in environments with large volumes of POA&M records.
- POA&M Related Assets: Resolved an issue where adding a large number of Related Assets to a POA&M could cause the page to crash.
- POA&M Filtering: Resolved inconsistencies in Status Board filtering so results are displayed according to the selected criteria.
- FedRAMP DRF Export: Corrected Operational Requirement columns for OR and RA OR deviations that were incorrectly populated with .
- FedRAMP Appendix A Export: Resolved formatting and data-display issues affecting nested parameters.
- eMASS POA&M Export: Resolved issues affecting eMASS POA&M exports, including missing severity and Security Plan information on CVE-derived issues.
- Control Framework Gap Reports: Resolved an issue requiring users to run the Control Framework Gap Report twice before results were displayed.
- Compliance Rollup: Resolved errors that could occur when searching within Compliance Rollup drill-down results.
Report Builder
- Date Filters: Resolved issues where report date filters could return empty, stale, or unfiltered results.
- Related Fields: Resolved an issue where related or collection fields could display instead of the appropriate values.
- Module Selection: Resolved issues where tenant-renamed modules displayed their default names and where certain modules were missing from the module picker.
- Report Layout: Resolved issues causing report column headers and list columns to appear cramped or run together.
- Save Behavior: Resolved an issue where navigating or changing a Report Builder page could unexpectedly save report changes.
Workflow & Automation
- Workflow Loops: Resolved an issue that could cause workflows to enter an infinite loop.
- Workflow Assignment & Branching: Resolved issues affecting group assignments, branch defaults, rejection routes, and workflow-step configuration.
- Workflow Timestamps: Corrected workflow start times and negative elapsed times caused by timezone handling.
- Webhook Management: Resolved issues where updating or deleting webhooks could leave stale event subscriptions or unintentionally overwrite stored access keys.
Vulnerability Management
- Vulnerability Synchronization: Resolved an issue where vulnerability synchronization could create thousands of vulnerabilities without correctly associating them with assets.
- Vulnerability Status & Reporting: Resolved issues affecting KEV values, vulnerability status reporting, and vulnerability trend views.
- Security Plan Scoping: Corrected vulnerability information so it is properly scoped to the applicable Security Plan or parent record.
- Vulnerability Views: Resolved issues where vulnerability-related views were not correctly displayed within Security Plans.
- Rule Severity: Resolved issues where imported or CVE-derived issues could lose their Raw Severity information.
Assessments, SSPs & Controls
- SSP Risk Assessment Utility: Resolved an issue that prevented the SSP Risk Assessment Utility from functioning correctly.
- Control Owner Updates: Resolved an issue where updates to CI Control Owners were not saving the correct information.
- Control Inheritance: Resolved issues where inherited control changes were not propagated correctly after the source control was updated.
- Inheritance Model: Resolved inconsistencies in Inheritance Model configuration and available management options.
- Assessment Restore: Restored the ability to create a new SSP record through the applicable restore workflow.
- Assessment Authoring: Resolved an issue where plan authoring could complete with blank statements when an unreadable document was uploaded.
- Checklist Re-import: Resolved an issue where re-importing a checklist could update only one asset per rule and fail to create records for newly introduced rules.
- Requirements Mapping: Resolved an issue where attempting to remap an already-mapped control resulted in an error.
- Continuous Monitoring Assessments: Resolved an issue where Lightning Assessments launched from Continuous Monitoring Assessments did not display the Control Preview pane.
- Control Status Displays: Resolved issues affecting control status information in SSPs and dashboards.
- SSP Wizard: Resolved multiple issues affecting SSP wizard navigation, validation, and data handling.
- Control Framework Data: Resolved issues affecting control framework mappings, timestamps, parameters, and imported control data.
- Control Implementation Parameters: Resolved an issue where control implementations created through certain API paths did not persist associated parameter records.
- Component Type Display: Corrected Component Type dropdown options that were displayed in lowercase.
Catalogs, Artifacts & Evidence
- Catalog Update Navigation: Resolved an issue where selecting Update Catalog could redirect users to the wrong screen.
- Catalog Archive Import: Resolved an issue that prevented catalog archive imports from completing successfully.
- Profile Importer: Corrected the Profile Importer display so it shows the catalog title instead of a catalog UUID when the catalog is not installed.
- Artifact & Evidence Versioning: Improved artifact and evidence handling to ensure files and versions are associated with the appropriate audit cycle and record.
- Evidence & Audit-Cycle Display: Resolved issues affecting Evidence File Uploads and the display of evidence associated with audit cycles.
Forms & Questionnaires
- Form Validation: Resolved an issue where field validation messages were not displayed until a dropdown was opened.
- Conditional Fields: Resolved an issue where conditional fields remained hidden when a form was initially loaded until the triggering field was changed.
- Custom Checkbox Values: Corrected inconsistent rendering of custom checkbox fields when stored values used representations other than the expected string format.
- Custom Organization Fields: Resolved an issue where Custom Fields using the Organizations type did not display saved values in the user interface.
- Questionnaire Assignment: Resolved issues with questionnaire assignment and removal, including validation behavior and authorization handling.
- Questionnaire Access & Permissions: Improved permission enforcement for questionnaire operations and resolved issues that could allow unauthorized users to access questionnaire information.
- Self-Assignment URLs: Resolved an issue where opening the Self-Assign URL dialog for an already-enabled questionnaire could unexpectedly save the questionnaire and report success.
Navigation & User Interface
- Control & Module Navigation: Resolved issues with side navigation, workspace tooltips, module naming, and other navigation elements that could obscure or incorrectly display application controls.
- Dark Mode: Resolved visual issues affecting the Security Plan Control Bulk Editor and improved text contrast for dark-mode users.
- Calendar Navigation: Resolved an issue where navigating between months from dates near the end of a month could require an extra click.
- Newsfeed: Resolved an issue where an empty newsfeed incorrectly returned a 404 error and generated an unnecessary browser error.
- App Management: Corrected the App Management page header and administrator avatar rendering.
- Global Permissions: Resolved issues where Nova Group Permission updates were not displayed correctly after being saved.
- AI Administration: Corrected contradictory messaging on the AI administration page regarding AI availability.
- RegML AI Generator: Resolved an issue where the RegML AI Generator menu item was displayed for Components even though the functionality was unavailable.
- Licensing Display: Corrected inaccurate license information displayed in the application footer.
Data Integrity & Record Processing
- Issue and Batch Processing: Resolved issues affecting batch issue creation, validation messaging, batch identification, and concurrent updates.
- Concurrent Record Updates: Improved record update handling to prevent concurrent changes from unintentionally overwriting other users' edits.
- Assessment and Issue Data Integrity: Resolved issues that could result in incorrect assessment, issue, or vulnerability records being created or updated during batch and concurrent processing.
- Record Visibility: Resolved an issue that could prevent record-level visibility settings from being saved correctly for certain record types.
- Data Ordering & Pagination: Resolved inconsistent ordering in paginated service queries to provide predictable results across pages.
- Database Configuration: Resolved an issue where environments containing multiple RegScale databases could encounter failures due to database identification handling.
API & Integration Reliability
- API Error Responses: Improved API error handling so invalid requests provide more meaningful responses rather than generic server errors.
- API Data Validation: Resolved issues affecting batch creation, workflow actions, and other API operations when invalid or incomplete data was submitted.
- Control Implementation APIs: Corrected persistence of associated parameter records when control implementations are created through certain API paths.
Attachments, Records & Saving
- WYSIWYG Attachments: Resolved an issue where the WYSIWYG editor could report that an attachment was uploaded successfully even though the file was not added to the record.
- Unexpected Record Saves: Resolved issues where navigation or preview actions could unexpectedly save record changes.
- Artifact & Evidence Association: Corrected file and version associations to ensure content is linked to the appropriate audit cycle and record.
Accessibility & Application Behavior
- Accessibility & Reduced Motion: Resolved issues affecting animations and accessibility behavior for users with operating-system motion-reduction settings enabled.
- Application Startup: Resolved issues with configuration values containing accidental whitespace that could prevent an instance from starting correctly.
