RegScale 6.33.0.1
[6.33.0.1] 08-10-2026
Bug Fixes
- Minor bug fixes made to the POA&M Status Board.
[6.33.0.0] 08-10-2026
App Builder Enhancements
-
The App Management page now provides the option to define a hierarchy of applications.
-
Within the application's Advanced Security tab, you can now enable global visibility for the parent-level application.
-
Users with access to multiple applications and Report Mode are provided with a dropdown containing all available applications and a toggle to switch to Report Mode.
- Report Mode provides users with view-only access to all selected applications.
- Users can select data from the applications they want to include, generate reports, and view dashboards containing data across multiple applications.
eMASS Export Templates
- eMASS export templates are now supported in additional formats.
Evidence Module Enhancements
- The Evidence Locker and Evidence Module have been consolidated into a single, updated Evidence Module view.
- Evidence records can now be automatically mapped to controls using catalog-based relationships.
General Usability Improvements
- Evidence Versioning: A new per-user setting determines whether uploading a file with the same name defaults to creating a new version or adding to the current version. The default remains New Version, and users can still override the choice for individual uploads.
- The Grid UI element now allows users to customize which columns are displayed.
- Related-record forms across the application now remain open and display an error when a save fails. The form closes only after a save is confirmed as successful.
- Pick Lists and Lookups: Components that have not yet been assigned to a compliance framework now appear in Security Plan component mapping lists instead of being hidden.
RegML Updates
-
A new RegML Agents page lists all available RegML agents, describes what each agent does, and identifies where each agent can be used.
- Agent runs are recorded, and the time and cost savings from AI-assisted work roll up into the Administrator Cost Savings view.
-
Use RegML to generate lines of inquiry for an Assessment Plan based on the relevant control and assessment context, eliminating the need to manually write each question.
-
The new Corrective Action Plan Generator analyzes an issue and proposes a set of remediation tasks, including a suggested owner and due date. Users can adjust the proposed tasks before creating them.
-
The new Risk Control Mapper recommends existing security controls that can mitigate a risk, providing a confidence score and rationale for each recommendation.
-
The Risk Mitigation Plan Generator drafts standalone treatment plans for risks based on user-provided direction.
-
RegML can now draft per-question scores and reviewer feedback for completed questionnaires. Reviewers can edit and approve the results rather than manually grading every response.
-
RegML can draft assessment tests for a control in the Lightning Assessment wizard.
-
Users can draft catalog-level Security Control Test Plans from a control's Test Plans tab, with options for high-level, standard, or detailed test granularity.
SSP Imports Action
Security Plans now support a new Imports action for uploading supported files directly to a Security Plan.
The following file types are supported:
- FedRAMP Inventory Workbook: Upload the standard Excel workbook to populate the system inventory.
- POA&Ms: Upload the standard FedRAMP POA&M Excel template to bulk-create issues and findings.
- CIS/CRM Workbook: Import CIS Benchmark or CRM tracking workbook files.
- FedRAMP SSP in OSCAL: Import an existing FedRAMP SSP in OSCAL JSON or XML format to create a complete SSP record with controls pre-populated.
- Deviation Request Forms: Import the standardized FedRAMP form.
SSP Software Bill of Materials Inventory
-
A Security Plan's SBOM tab can now display the complete software inventory within scope, including SBOMs attached directly to the plan as well as those attached to its components and assets.
-
A new Direct / All Related toggle on the plan's SBOM tab expands the view from the plan's direct SBOMs to all SBOMs associated with the plan, its components, and its assets.
- A Source column identifies where each SBOM is associated.
-
Users can open, compare, and edit an SBOM directly from the related list while maintaining its association with the correct component or asset.
-
SBOM previews, copies, and downloads now produce clean, readable JSON.
Preset Configuration Templates
- A new US Air Force template is now available under Preset Configuration Templates.
POA&M Status Board
The POA&M Status Board provides an interactive experience that makes it easier to track, investigate, and act on POA&M items. Dashboard visualizations—including pie charts, bar charts, and summary metrics—are interactive. Users can select a dashboard element to drill down directly into the corresponding POA&M records.
- A new POA&M Status Board displays POA&Ms and includes filters for Deviation Requests.
- POA&Ms are created by selecting the POA&M page on an issue and selecting Cyber Reportable Plan of Action and Milestones as the Type and the appropriate Status.
- The Deviation Request page is now available when an Issue is converted to a POA&M.
- To convert an issue to a Deviation Request, select Deviation Request as the Type and select the appropriate Status.
- Interactive Dashboard Metrics: Click charts, chart elements, and summary metrics to investigate the underlying POA&M records.
- Automatic Filtering: Selecting a dashboard metric automatically applies the corresponding filter to the POA&M record list. Existing dashboard filters are retained when drilling down, providing consistent context throughout the investigation.
- POA&M Record Navigation: Individual POA&M records can be selected directly from the filtered results to open their detail pages.
- Permission-Aware Results: Dashboard metrics and drill-down results respect user permissions, ensuring users only see POA&M records they are authorized to access.
- Consistent Metrics: Dashboard counts remain consistent with the records available to the user based on their permissions.
Vulnerability Management Enhancements
-
A vulnerability's Days Open value is now calculated from the date the vulnerability was first detected.
- The value increases daily while the vulnerability remains open.
- Once the vulnerability is closed or mitigated, the value stops increasing and is frozen at the closure date.
-
The Days Open column now sorts correctly based on the calculated age.
-
The Stale quick filter, which identifies findings that have been open for more than 90 days, now uses the same corrected calculation.
