RegScale 6.33.1.0
August 14th, 2026
[6.33.1.0] 08-14-2026
Enhancements
AI and RegML
- Expanded AI Agent Capabilities — Added AI Agent capabilities for Lines of Inquiry, Corrective Action Plans, Risk Treatment Mappings, Questionnaire Scoring, Lightning Assessment Tests, and Security Control Test Generation.
- RegML Mapping Recommendations — Enhanced RegML capabilities with recommendations to assist users in mapping relevant content.
- Azure OpenAI Connectivity Validation — Added startup connectivity validation to provide earlier detection of Azure OpenAI configuration or connectivity issues.
- Improved RegML Reporting — Enhanced Report Builder support for RegML-generated reports and related-module fields.
- Improved RegML Error Handling — Improved error reporting so connectivity and network issues are no longer incorrectly reported as API-key permission problems.
Evidence and Control Management
- Evidence Improvements — Expanded evidence management capabilities and improved evidence workflows throughout Control Implementation and assessment experiences.
- Evidence-to-Control Mapping Propagation — Improved the propagation of evidence-to-control relationships.
- Enhanced Evidence Linking — Updated Control Implementation and SSP assessment workflows to provide improved access to evidence and files.
- SSP Evidence Linking Options — Enhanced the System Security Plan creation wizard to support opting into evidence linking.
- Evidence Management Consolidation — Improved the Evidence experience by consolidating Locker and List View functionality.
Security Plans and Excel Import/Export
- Canonical SSP Excel Template — Added a standardized Security Plan Excel template schema with versioned metadata.
- Downloadable SSP Excel Template — Added the ability to download a blank canonical SSP Excel template directly from the application.
- SSP Excel Template Validation and Preview — Added validation, preview, and confirmation capabilities when uploading an SSP Excel template.
- SSP Excel Import — Added support for creating and updating Security Plans from the canonical Excel template.
- SSP Excel Export — Added the ability to export a Security Plan to the canonical Excel template format.
- Export Builder Templates — Added the ability to download Export Builder templates.
- Improved Export Integration Testing — Expanded automated integration coverage for export functionality.
Compliance and Catalogs
- Control Framework Gap Assessment — Added enhanced support for evaluating gaps across control frameworks.
- Automated Risk Mappings — Added automation capabilities to simplify risk-to-control mapping activities.
- Expanded Compliance Settings — Expanded compliance configuration capabilities to support additional security management use cases.
- Improved CRI Catalog Support — Enhanced support for CRI-related catalog functionality, including AI and cloud catalog capabilities.
- OpenSSF Catalog — Added support for the OpenSSF catalog.
- Security Plan Changelog — Added changelog visibility for Security Plans to improve traceability of changes.
- SBOM Child Visibility — Added support for viewing child records associated with SBOM information.
Risk Management
- Risk Module Enhancements — Improved risk management capabilities to support expanded risk workflows.
- Aggregate CCM Dashboard — Added an aggregate dashboard for improved visibility into CCM-related information.
- Risk Treatment Control Selection — Enhanced risk treatment workflows with improved control selection and filtering.
- Risk Mapping Automation — Added capabilities to automate risk mappings and improve consistency across risk management workflows.
Workflow and Navigation
- Kanban Navigation — Added Next/Previous navigation to Kanban workflows.
- Workflow Designer Improvements — Enhanced workflow configuration and approval experiences.
- Workflow Approval Accessibility — Improved access to workflow instances and approvals across applications.
- Improved Record Navigation — Enhanced record navigation so Back actions return users to the expected previous screen.
- Improved Grid Views — Continued UI and usability improvements to custom grid views.
Security and Platform Hardening
- Authentication and JWT Hardening — Strengthened authentication and JWT handling to improve platform security.
- Account Lockout Improvements — Enhanced account lockout and brute-force protection capabilities.
- Authentication Rate Limiting — Improved authentication request throttling and protection against automated account enumeration.
- Tenant Isolation Improvements — Strengthened tenant isolation across platform services and data access.
- Security Audit Improvements — Enhanced auditing of API-created records and security-sensitive operations.
- FedRAMP High UI Support — Added a FedRAMP High badge to the application footer.
- Improved Accessibility — Improved UI accessibility, including WCAG-related color contrast and disabled-control styling.
User Interface Improvements
- UI Polish — Continued visual and usability improvements across UI interface.
- SSP Author Experience — Updated the SSP Author page to align with the current application branding and UI standards.
- Export Builder UI Improvements — Improved template upload and management controls.
- Status Board Improvements — Enhanced Status Board presentation and Baseball Card layouts.
- File Upload Guidance — Improved the file upload experience by displaying supported file type restrictions.
- Form Validation Improvements — Enhanced field validation behavior within Form Builder.
- Questionnaire Improvements — Improved questionnaire self-assignment URL capabilities.
- Workbench Link Support — Improved handling of hyperlinks in task and issue descriptions.
Fixes
Authentication and Security
- SSO Role Assignment — Fixed an issue that could allow users authenticating through SSO to manipulate local application roles and produce unexpected access behavior.
- SSO Application Administration — Fixed application administrator claim handling so app-admin privileges are correctly aligned with application group membership.
- JWT Authentication — Fixed an intermittent issue where authentication tokens could be issued without the required expiration claim.
- Authentication Regression — Resolved an issue causing authenticated API requests to intermittently return HTTP 401 responses in UI.
- Account Enumeration Protection — Secured login configuration endpoints against unauthenticated account and tenant enumeration.
- MFA Information Exposure — Prevented pre-authentication endpoints from exposing tenant identifiers, tenant names, or MFA posture.
- Authorization Enforcement — Corrected missing module-permission checks on Control Implementation endpoints.
- Exception Information Exposure — Fixed validation errors that could expose unnecessary exception details through API responses.
- Tenant Isolation — Corrected cross-tenant data access paths in lineage and module-related services.
- Security Audit Logging — Fixed security audit logging for password changes and API-created records.
- Rate Limiting — Corrected authentication rate-limit calculations and ensured throttling responses report the appropriate limit and retry information.
- Account Lockout — Fixed an issue where account lockout settings could be ineffective when the lockout duration was configured with a zero value.
Export Builder and Exports
- Export Template Creation — Fixed an issue preventing users from creating Export Builder templates.
- Export Template File Removal — Fixed errors that could occur when removing files from Export Builder templates.
- Export Field Mapping — Fixed an issue where the Export Field mapping dropdown appeared empty in Nova.
- Export Status Visibility — Fixed the Export Status box appearing behind the Export modal.
- POA&M Re-Export — Fixed an issue requiring users to refresh or navigate away from the page before exporting a Rev5 POA&M again.
- SSP Export Generation — Fixed an issue where SSP document exports could be generated as empty documents.
- OSCAL Export — Fixed OSCAL SSP export failures when the Authorization Boundary was not populated.
- OSCAL Non-NIST Catalogs — Fixed export failures for controls without Control IDs, including controls from non-NIST catalogs.
- FedRAMP Rev5 SSP Export — Corrected cover-page typography and Ports & Protocols table formatting.
- FedRAMP Rev5 Appendix A Export — Corrected fonts, colors, bullets, and Customer Responsibility content.
- FedRAMP Rev5 Appendix Q Export — Corrected title, color, and formatting issues.
- FedRAMP Rev5 CIS/CRM Export — Corrected control ordering in the High CIS worksheet.
- FedRAMP Inventory Export — Addressed issues affecting FedRAMP inventory exports.
- eMASS POA&M Export — Improved conditional handling of comments and milestones based on issue status.
- eMASS Export Licensing Display — Corrected an incorrect Syncfusion license expiration message displayed during eMASS exports.
SSP and Compliance
- SSP Compliance Scores — Fixed an issue preventing compliance scores from being generated on the SSP Dashboard.
- SSP Control Population — Fixed SSP creation so controls are correctly populated from the selected profile and manually added controls can be added successfully.
- Compliance Settings — Fixed the Control Builder so it correctly honors compliance settings when compliance configuration is changed on an existing SSP.
- Inherited Controls in ScoreCards — Fixed an issue preventing inherited controls from appearing in ScoreCards.
- SAP/SAR Export — Corrected the RMF Effort field in Section 1 of SAP/SAR exports.
- Security Plan Status by Family — Corrected erroneous information indicators appearing in the Status by Family table.
- Control Implementation Status Dashboard — Fixed an issue causing the By Status dashboard view to display no results.
- Policy-to-Control Mapping — Fixed policy relationships so policies linked through Related Policies are correctly mapped to the associated control.
Risk Management
- Risk Drill-Down — Fixed Manage Risks dashboard drill-down behavior so selecting a pie-chart segment displays only the risks represented by that segment.
- Risk Treatment Control Filtering — Fixed control selection in Risk Treatments so users can filter the available controls.
- Risk Treatment Control View — Fixed blank View Control dialogs when a control could not be loaded and improved error handling.
- Risk Assessment Guidance — Improved the Risk Assessment experience when required risk configuration has not yet been established.
- Risk Control Treatment Messaging — Fixed an erroneous "No Available Controls" warning after canceling a treatment and relinking controls.
- Risk Assessment Help Modal — Fixed an issue preventing the Risk Assessment Help modal from closing correctly and corrected its styling.
Workflow
- Workflow Template Steps — Fixed an intermittent issue where newly added workflow template steps appeared to save successfully but were not persisted.
- Workflow Step Deletion — Fixed Visual Designer errors that could prevent workflow steps from being deleted and leave the UI unresponsive.
- Workflow Branch Approval — Fixed an issue preventing halted branch steps without an assignee from being approved or rejected.
- Workflow Branch Navigation — Improved validation of "Go to step" targets so unreachable workflow steps cannot be selected without appropriate warning.
- Workflow Approvals Access — Fixed inconsistent permissions that could prevent users from accessing the workflow approvals inbox.
- Workflow Security Plan Scoping — Corrected application scoping for System Role data used during SSP exports.
Data and Records
- Data Save Handling — Fixed UI behavior where rejected saves could incorrectly navigate users back to a list.
- Data Editor Validation — Fixed stale invalid text remaining in the Data editor after a rejected save.
- Record Back Navigation — Corrected the Back button so users return to the previous screen instead of the module list.
- Component Deletion — Fixed an issue preventing users from deleting multiple components at once.
- ConMon Cleanup — Fixed cleanup behavior that could leave orphaned Vulnerability Mappings and inflate vulnerability counts.
- Module Access Validation — Fixed errors returned when requesting a module outside the caller's tenant.
- User Removal — Fixed errors that could occur when removing a user from an application.
- Risk Record Permissions — Corrected permissions that could allow users with CRU access to delete risk records.
Questionnaires and Forms
- Questionnaire Save — Fixed the Save button when field validation errors are present.
- Questionnaire Self-Assignment — Fixed an issue preventing self-assignment URLs from being enabled.
- Form Builder Validation — Corrected new-field validation behavior so validations do not trigger prematurely.
- Questionnaire Data Export — Fixed Export Orchestration so it uses the most recent questionnaire response data rather than the original response data.
Evidence
- Evidence Mapping Dialog — Added vertical scrolling support to the Evidence control-mapping dialog.
- Evidence Relationships — Fixed evidence-to-control relationship propagation.
- Evidence and Files Tabs — Corrected Evidence tab behavior in Control Implementation and SSP assessment workflows.
User Interface and Usability
- POA&M Status Board — Fixed navigation, refresh and download actions, deviation-type filtering, empty owner/scope filters, and search behavior.
- Compliance Hygiene Status Board — Fixed errors affecting the Compliance Hygiene Status Board.
- Status Board Baseball Cards — Corrected header rendering issues on Status Board Baseball Cards.
- Report Builder Layout — Fixed chart filter controls overflowing their container in Nova.
- Security Profiles — Fixed control mappings disappearing after saving column changes.
- Disabled Controls — Added appropriate visual styling for disabled dropdowns.
- File Upload UI — Corrected positioning of the file-drop icon and improved upload control presentation.
- Export Builder Layout — Corrected vertical alignment of uploaded template files and remove controls.
- Add User Performance — Improved the Add User dialog, which could previously take several seconds to open.
- Workbench Actions — Fixed issue detail Actions controls that could not be clicked because of global navigation hit-testing.
- Security Plan UI — Corrected styling issues in inheritance model fields and other Security Plan controls.
- Classification Banner Accessibility — Corrected insufficient color contrast in the light-theme classification banner to improve WCAG AA compliance.
- CMMC Export Dialog — Fixed the CMMC SSP pre-export dialog so it opens in the correct layer above the export interface.
- Save Navigation — Fixed navigation behavior when saves are rejected.
Platform and Infrastructure
- Concurrent App Creation — Fixed SQL Server deadlock handling during concurrent application creation by adding appropriate retry behavior.
- Environment Setup — Fixed first-time environment setup failures that could prevent tenant creation on a clean database.
- Log Event Cleanup — Corrected the nightly process responsible for cleaning the LogEvents table.
- Syslog Audit Delivery — Fixed duplicate audit records that could be sent to a SIEM when a TLS syslog connection experienced a mid-stream TCP interruption.
- API Error Handling — Improved API validation responses so users receive more specific error messages rather than generic failures.
- API Routing — Fixed unmatched routes incorrectly returning the application index page instead of an HTTP 404 response.
- Release Notifications — Fixed release-notification email failures caused by invalid logger configuration.
- Application Builds — Resolved stale namespace references that prevented the main application and automated test projects from building successfully.
- Automated Testing — Corrected end-to-end test data generation issues involving vulnerability field length and invalid CVE values.
- Coverage Reporting — Updated coverage configuration to include asynchronous method bodies.
- Audit and Data Access — Corrected service-level data access patterns to ensure tenant isolation, soft-delete behavior, auditing, and webhook processing are consistently applied.
