RegScale 6.33.0.1

[6.33.0.1] 08-10-2026

Bug Fixes

  • Minor bug fixes made to the POA&M Status Board.

[6.33.0.0] 08-10-2026

App Builder Enhancements

  • The App Management page now provides the option to define a hierarchy of applications.

  • Within the application's Advanced Security tab, you can now enable global visibility for the parent-level application.

  • Users with access to multiple applications and Report Mode are provided with a dropdown containing all available applications and a toggle to switch to Report Mode.

    • Report Mode provides users with view-only access to all selected applications.
    • Users can select data from the applications they want to include, generate reports, and view dashboards containing data across multiple applications.

eMASS Export Templates

  • eMASS export templates are now supported in additional formats.

Evidence Module Enhancements

  • The Evidence Locker and Evidence Module have been consolidated into a single, updated Evidence Module view.
  • Evidence records can now be automatically mapped to controls using catalog-based relationships.

General Usability Improvements

  • Evidence Versioning: A new per-user setting determines whether uploading a file with the same name defaults to creating a new version or adding to the current version. The default remains New Version, and users can still override the choice for individual uploads.
  • The Grid UI element now allows users to customize which columns are displayed.
  • Related-record forms across the application now remain open and display an error when a save fails. The form closes only after a save is confirmed as successful.
  • Pick Lists and Lookups: Components that have not yet been assigned to a compliance framework now appear in Security Plan component mapping lists instead of being hidden.

RegML Updates

  • A new RegML Agents page lists all available RegML agents, describes what each agent does, and identifies where each agent can be used.

    • Agent runs are recorded, and the time and cost savings from AI-assisted work roll up into the Administrator Cost Savings view.
  • Use RegML to generate lines of inquiry for an Assessment Plan based on the relevant control and assessment context, eliminating the need to manually write each question.

  • The new Corrective Action Plan Generator analyzes an issue and proposes a set of remediation tasks, including a suggested owner and due date. Users can adjust the proposed tasks before creating them.

  • The new Risk Control Mapper recommends existing security controls that can mitigate a risk, providing a confidence score and rationale for each recommendation.

  • The Risk Mitigation Plan Generator drafts standalone treatment plans for risks based on user-provided direction.

  • RegML can now draft per-question scores and reviewer feedback for completed questionnaires. Reviewers can edit and approve the results rather than manually grading every response.

  • RegML can draft assessment tests for a control in the Lightning Assessment wizard.

  • Users can draft catalog-level Security Control Test Plans from a control's Test Plans tab, with options for high-level, standard, or detailed test granularity.

SSP Imports Action

Security Plans now support a new Imports action for uploading supported files directly to a Security Plan.

The following file types are supported:

  • FedRAMP Inventory Workbook: Upload the standard Excel workbook to populate the system inventory.
  • POA&Ms: Upload the standard FedRAMP POA&M Excel template to bulk-create issues and findings.
  • CIS/CRM Workbook: Import CIS Benchmark or CRM tracking workbook files.
  • FedRAMP SSP in OSCAL: Import an existing FedRAMP SSP in OSCAL JSON or XML format to create a complete SSP record with controls pre-populated.
  • Deviation Request Forms: Import the standardized FedRAMP form.

SSP Software Bill of Materials Inventory

  • A Security Plan's SBOM tab can now display the complete software inventory within scope, including SBOMs attached directly to the plan as well as those attached to its components and assets.

  • A new Direct / All Related toggle on the plan's SBOM tab expands the view from the plan's direct SBOMs to all SBOMs associated with the plan, its components, and its assets.

    • A Source column identifies where each SBOM is associated.
  • Users can open, compare, and edit an SBOM directly from the related list while maintaining its association with the correct component or asset.

  • SBOM previews, copies, and downloads now produce clean, readable JSON.

Preset Configuration Templates

  • A new US Air Force template is now available under Preset Configuration Templates.

POA&M Status Board

The POA&M Status Board provides an interactive experience that makes it easier to track, investigate, and act on POA&M items. Dashboard visualizations—including pie charts, bar charts, and summary metrics—are interactive. Users can select a dashboard element to drill down directly into the corresponding POA&M records.

  • A new POA&M Status Board displays POA&Ms and includes filters for Deviation Requests.
  • POA&Ms are created by selecting the POA&M page on an issue and selecting Cyber Reportable Plan of Action and Milestones as the Type and the appropriate Status.
  • The Deviation Request page is now available when an Issue is converted to a POA&M.
  • To convert an issue to a Deviation Request, select Deviation Request as the Type and select the appropriate Status.
  • Interactive Dashboard Metrics: Click charts, chart elements, and summary metrics to investigate the underlying POA&M records.
  • Automatic Filtering: Selecting a dashboard metric automatically applies the corresponding filter to the POA&M record list. Existing dashboard filters are retained when drilling down, providing consistent context throughout the investigation.
  • POA&M Record Navigation: Individual POA&M records can be selected directly from the filtered results to open their detail pages.
  • Permission-Aware Results: Dashboard metrics and drill-down results respect user permissions, ensuring users only see POA&M records they are authorized to access.
  • Consistent Metrics: Dashboard counts remain consistent with the records available to the user based on their permissions.

Vulnerability Management Enhancements

  • A vulnerability's Days Open value is now calculated from the date the vulnerability was first detected.

    • The value increases daily while the vulnerability remains open.
    • Once the vulnerability is closed or mitigated, the value stops increasing and is frozen at the closure date.
  • The Days Open column now sorts correctly based on the calculated age.

  • The Stale quick filter, which identifies findings that have been open for more than 90 days, now uses the same corrected calculation.