RegScale 6.28.0.0
January 15th, 2026
[6.28.0.0] - 2026-01-15
Added
- New drag-and-drop Workflow Designer experience
- Workflow Template Library
- Digital Signatures workflow action
- Ability to preview a questionnaire without assigning it
- New questionnaire question types including Yes/No, True/False, Number, Rating Scale, Likert Scale, URL, and Currency
- Filters on the Report Builder listing page
- Ability to assign questionnaire reviews to a group
Changed
- Assessment Scorecard enhanced with five new views
- Added Risk Assessment help text in the Risks module
- Ability to delete fields in Form Builder
- Condensed Statusboard designs for improved scannability
- Restricted questionnaire reopening to questionnaire administrators only
- Ability to reassign questionnaires
- Improved visibility of question-level user assignment
- Renamed Questionnaire Response Managed Uploads button to Upload File
- Prevented question-level assignees from submitting questionnaires
- Modernized and streamlined Newsfeed, Look Ahead, and Workbench experiences
- Improved dashboard widgets and reporting experience
- Ability to import and export Assessment Plans in bulk
- Streamlined Line of Inquiry experience
Fixed
- Improved button contrast in the unsaved changes modal
- Fixed saving of custom fields
- Corrected SPRS Scorecard behavior with CMMC Compliance Settings
- Auto-Summarize now includes Inherited, Cloud Implementation, and Customer Responsibility fields
- Ensured workflow emails send consistently
- Enabled default Implementation Status and Control Origin selection for Catalog Templates
- Allowed security plans to be children of other security plans when edited via API
- Enabled hiding of the Maturity and Quality tab in Control Implementations via Form Builder
- Updated Report Builder to reflect Form Builder field name changes
- Removed need to refresh when switching RegScale instances
- Corrected System Implementation export order in Appendix A
- Fixed Security Plan scorecard calculation for Parts
- Corrected Compliance Rollup mappings for CMMC settings
- Fixed Response Automation exports
- Displayed human-readable questionnaire response statuses in Report Builder
- Prevented required checkbox fields in Form Builder
- Fixed Export Builder template uploads
- Enabled automatic scaling of Form Section Headers
- Fixed Vulnerabilities selection in the navigation panel
- Corrected sorting by asset count on the vulnerability scorecard
- Prevented null values and slashes in Form Builder section names
- Fixed Vulnerability Statusboard filtering across full data sets
- Displayed empty custom fields correctly in Report Builder
- Fixed RegML Policy Generator behavior
- Allowed commas in questionnaire prompt list values
- Enabled target risk scores greater than 1 in the Risk module
- Corrected export options shown in the Catalog export modal
- Allowed saving of hidden fields that contain data
- Cleaned up required fields in the Assessment module
- Improved Organization status toggle behavior
- Fixed typo in the RegML Rich Text Editor
- Corrected questionnaire response export alignment
- Fixed Catalog import for NRC RG 5.71 Rev. 1
- Enabled Update Assigned Instances in the Questionnaires module
- Fixed api/scanHistory/getAllByParentRecursive endpoint
- Corrected Configuration Check Status badging in the Assets module
- Added support for special characters in usernames
- Fixed questionnaire email delivery
- Corrected questionnaire endpoints in Swagger documentation
- Fixed Policy Template Editor display after saving
- Removed need to refresh after adding Control Implementations to Security Plans
- Fixed Catalog count display on the Security Profiles Mappings tab
- Enabled adding Risk Treatments in the Risk module
- Corrected help text display in the Security Plan Cockpit
- Enforced sequential Catalog imports
- Fixed selecting existing options for Component Control Implementations
- Corrected Other Compliance Rollup value behavior
- Fixed unsaved changes detection in the Data Subsystem
- Improved eMASS POA&M export handling for missing Security Checks
- Ensured associated Wayfinders are deleted with Security Plans
- Corrected Workbench counts
- Enabled cursor focus anywhere within Rich Text fields
- Updated Evidence Forms after backend changes
- Fixed Security Plan Evidence report data
- Enabled search for terms shorter than four characters
- Fixed account confirmation email links
- Improved export warning messages for invalid file types
- Enforced Control ID uniqueness in the Security Controls module
- Ensured Organization endpoint returns Organization ID
- Fixed /api/evidence/getEvidenceSecurityPlan/{intID} endpoint
- Fixed /api/evidence/getEvidenceByDate/{intDays} endpoint
- Corrected required field handling on CAP Tasks Boards
- Hid CMMC fields in the Policy module when CMMC is disabled
- Fixed /api/config/purgeLogs endpoint behavior
- Applied various security updates and patches
- Applied various application performance improvements
