RegScale 6.33.1.0

[6.33.1.0] 08-14-2026

Enhancements

AI and RegML

  • Expanded AI Agent Capabilities — Added AI Agent capabilities for Lines of Inquiry, Corrective Action Plans, Risk Treatment Mappings, Questionnaire Scoring, Lightning Assessment Tests, and Security Control Test Generation.
  • RegML Mapping Recommendations — Enhanced RegML capabilities with recommendations to assist users in mapping relevant content.
  • Azure OpenAI Connectivity Validation — Added startup connectivity validation to provide earlier detection of Azure OpenAI configuration or connectivity issues.
  • Improved RegML Reporting — Enhanced Report Builder support for RegML-generated reports and related-module fields.
  • Improved RegML Error Handling — Improved error reporting so connectivity and network issues are no longer incorrectly reported as API-key permission problems.

Evidence and Control Management

  • Evidence Improvements — Expanded evidence management capabilities and improved evidence workflows throughout Control Implementation and assessment experiences.
  • Evidence-to-Control Mapping Propagation — Improved the propagation of evidence-to-control relationships.
  • Enhanced Evidence Linking — Updated Control Implementation and SSP assessment workflows to provide improved access to evidence and files.
  • SSP Evidence Linking Options — Enhanced the System Security Plan creation wizard to support opting into evidence linking.
  • Evidence Management Consolidation — Improved the Evidence experience by consolidating Locker and List View functionality.

Security Plans and Excel Import/Export

  • Canonical SSP Excel Template — Added a standardized Security Plan Excel template schema with versioned metadata.
  • Downloadable SSP Excel Template — Added the ability to download a blank canonical SSP Excel template directly from the application.
  • SSP Excel Template Validation and Preview — Added validation, preview, and confirmation capabilities when uploading an SSP Excel template.
  • SSP Excel Import — Added support for creating and updating Security Plans from the canonical Excel template.
  • SSP Excel Export — Added the ability to export a Security Plan to the canonical Excel template format.
  • Export Builder Templates — Added the ability to download Export Builder templates.
  • Improved Export Integration Testing — Expanded automated integration coverage for export functionality.

Compliance and Catalogs

  • Control Framework Gap Assessment — Added enhanced support for evaluating gaps across control frameworks.
  • Automated Risk Mappings — Added automation capabilities to simplify risk-to-control mapping activities.
  • Expanded Compliance Settings — Expanded compliance configuration capabilities to support additional security management use cases.
  • Improved CRI Catalog Support — Enhanced support for CRI-related catalog functionality, including AI and cloud catalog capabilities.
  • OpenSSF Catalog — Added support for the OpenSSF catalog.
  • Security Plan Changelog — Added changelog visibility for Security Plans to improve traceability of changes.
  • SBOM Child Visibility — Added support for viewing child records associated with SBOM information.

Risk Management

  • Risk Module Enhancements — Improved risk management capabilities to support expanded risk workflows.
  • Aggregate CCM Dashboard — Added an aggregate dashboard for improved visibility into CCM-related information.
  • Risk Treatment Control Selection — Enhanced risk treatment workflows with improved control selection and filtering.
  • Risk Mapping Automation — Added capabilities to automate risk mappings and improve consistency across risk management workflows.

Workflow and Navigation

  • Kanban Navigation — Added Next/Previous navigation to Kanban workflows.
  • Workflow Designer Improvements — Enhanced workflow configuration and approval experiences.
  • Workflow Approval Accessibility — Improved access to workflow instances and approvals across applications.
  • Improved Record Navigation — Enhanced record navigation so Back actions return users to the expected previous screen.
  • Improved Grid Views — Continued UI and usability improvements to custom grid views.

Security and Platform Hardening

  • Authentication and JWT Hardening — Strengthened authentication and JWT handling to improve platform security.
  • Account Lockout Improvements — Enhanced account lockout and brute-force protection capabilities.
  • Authentication Rate Limiting — Improved authentication request throttling and protection against automated account enumeration.
  • Tenant Isolation Improvements — Strengthened tenant isolation across platform services and data access.
  • Security Audit Improvements — Enhanced auditing of API-created records and security-sensitive operations.
  • FedRAMP High UI Support — Added a FedRAMP High badge to the application footer.
  • Improved Accessibility — Improved UI accessibility, including WCAG-related color contrast and disabled-control styling.

User Interface Improvements

  • UI Polish — Continued visual and usability improvements across UI interface.
  • SSP Author Experience — Updated the SSP Author page to align with the current application branding and UI standards.
  • Export Builder UI Improvements — Improved template upload and management controls.
  • Status Board Improvements — Enhanced Status Board presentation and Baseball Card layouts.
  • File Upload Guidance — Improved the file upload experience by displaying supported file type restrictions.
  • Form Validation Improvements — Enhanced field validation behavior within Form Builder.
  • Questionnaire Improvements — Improved questionnaire self-assignment URL capabilities.
  • Workbench Link Support — Improved handling of hyperlinks in task and issue descriptions.

Fixes

Authentication and Security

  • SSO Role Assignment — Fixed an issue that could allow users authenticating through SSO to manipulate local application roles and produce unexpected access behavior.
  • SSO Application Administration — Fixed application administrator claim handling so app-admin privileges are correctly aligned with application group membership.
  • JWT Authentication — Fixed an intermittent issue where authentication tokens could be issued without the required expiration claim.
  • Authentication Regression — Resolved an issue causing authenticated API requests to intermittently return HTTP 401 responses in UI.
  • Account Enumeration Protection — Secured login configuration endpoints against unauthenticated account and tenant enumeration.
  • MFA Information Exposure — Prevented pre-authentication endpoints from exposing tenant identifiers, tenant names, or MFA posture.
  • Authorization Enforcement — Corrected missing module-permission checks on Control Implementation endpoints.
  • Exception Information Exposure — Fixed validation errors that could expose unnecessary exception details through API responses.
  • Tenant Isolation — Corrected cross-tenant data access paths in lineage and module-related services.
  • Security Audit Logging — Fixed security audit logging for password changes and API-created records.
  • Rate Limiting — Corrected authentication rate-limit calculations and ensured throttling responses report the appropriate limit and retry information.
  • Account Lockout — Fixed an issue where account lockout settings could be ineffective when the lockout duration was configured with a zero value.

Export Builder and Exports

  • Export Template Creation — Fixed an issue preventing users from creating Export Builder templates.
  • Export Template File Removal — Fixed errors that could occur when removing files from Export Builder templates.
  • Export Field Mapping — Fixed an issue where the Export Field mapping dropdown appeared empty in Nova.
  • Export Status Visibility — Fixed the Export Status box appearing behind the Export modal.
  • POA&M Re-Export — Fixed an issue requiring users to refresh or navigate away from the page before exporting a Rev5 POA&M again.
  • SSP Export Generation — Fixed an issue where SSP document exports could be generated as empty documents.
  • OSCAL Export — Fixed OSCAL SSP export failures when the Authorization Boundary was not populated.
  • OSCAL Non-NIST Catalogs — Fixed export failures for controls without Control IDs, including controls from non-NIST catalogs.
  • FedRAMP Rev5 SSP Export — Corrected cover-page typography and Ports & Protocols table formatting.
  • FedRAMP Rev5 Appendix A Export — Corrected fonts, colors, bullets, and Customer Responsibility content.
  • FedRAMP Rev5 Appendix Q Export — Corrected title, color, and formatting issues.
  • FedRAMP Rev5 CIS/CRM Export — Corrected control ordering in the High CIS worksheet.
  • FedRAMP Inventory Export — Addressed issues affecting FedRAMP inventory exports.
  • eMASS POA&M Export — Improved conditional handling of comments and milestones based on issue status.
  • eMASS Export Licensing Display — Corrected an incorrect Syncfusion license expiration message displayed during eMASS exports.

SSP and Compliance

  • SSP Compliance Scores — Fixed an issue preventing compliance scores from being generated on the SSP Dashboard.
  • SSP Control Population — Fixed SSP creation so controls are correctly populated from the selected profile and manually added controls can be added successfully.
  • Compliance Settings — Fixed the Control Builder so it correctly honors compliance settings when compliance configuration is changed on an existing SSP.
  • Inherited Controls in ScoreCards — Fixed an issue preventing inherited controls from appearing in ScoreCards.
  • SAP/SAR Export — Corrected the RMF Effort field in Section 1 of SAP/SAR exports.
  • Security Plan Status by Family — Corrected erroneous information indicators appearing in the Status by Family table.
  • Control Implementation Status Dashboard — Fixed an issue causing the By Status dashboard view to display no results.
  • Policy-to-Control Mapping — Fixed policy relationships so policies linked through Related Policies are correctly mapped to the associated control.

Risk Management

  • Risk Drill-Down — Fixed Manage Risks dashboard drill-down behavior so selecting a pie-chart segment displays only the risks represented by that segment.
  • Risk Treatment Control Filtering — Fixed control selection in Risk Treatments so users can filter the available controls.
  • Risk Treatment Control View — Fixed blank View Control dialogs when a control could not be loaded and improved error handling.
  • Risk Assessment Guidance — Improved the Risk Assessment experience when required risk configuration has not yet been established.
  • Risk Control Treatment Messaging — Fixed an erroneous "No Available Controls" warning after canceling a treatment and relinking controls.
  • Risk Assessment Help Modal — Fixed an issue preventing the Risk Assessment Help modal from closing correctly and corrected its styling.

Workflow

  • Workflow Template Steps — Fixed an intermittent issue where newly added workflow template steps appeared to save successfully but were not persisted.
  • Workflow Step Deletion — Fixed Visual Designer errors that could prevent workflow steps from being deleted and leave the UI unresponsive.
  • Workflow Branch Approval — Fixed an issue preventing halted branch steps without an assignee from being approved or rejected.
  • Workflow Branch Navigation — Improved validation of "Go to step" targets so unreachable workflow steps cannot be selected without appropriate warning.
  • Workflow Approvals Access — Fixed inconsistent permissions that could prevent users from accessing the workflow approvals inbox.
  • Workflow Security Plan Scoping — Corrected application scoping for System Role data used during SSP exports.

Data and Records

  • Data Save Handling — Fixed UI behavior where rejected saves could incorrectly navigate users back to a list.
  • Data Editor Validation — Fixed stale invalid text remaining in the Data editor after a rejected save.
  • Record Back Navigation — Corrected the Back button so users return to the previous screen instead of the module list.
  • Component Deletion — Fixed an issue preventing users from deleting multiple components at once.
  • ConMon Cleanup — Fixed cleanup behavior that could leave orphaned Vulnerability Mappings and inflate vulnerability counts.
  • Module Access Validation — Fixed errors returned when requesting a module outside the caller's tenant.
  • User Removal — Fixed errors that could occur when removing a user from an application.
  • Risk Record Permissions — Corrected permissions that could allow users with CRU access to delete risk records.

Questionnaires and Forms

  • Questionnaire Save — Fixed the Save button when field validation errors are present.
  • Questionnaire Self-Assignment — Fixed an issue preventing self-assignment URLs from being enabled.
  • Form Builder Validation — Corrected new-field validation behavior so validations do not trigger prematurely.
  • Questionnaire Data Export — Fixed Export Orchestration so it uses the most recent questionnaire response data rather than the original response data.

Evidence

  • Evidence Mapping Dialog — Added vertical scrolling support to the Evidence control-mapping dialog.
  • Evidence Relationships — Fixed evidence-to-control relationship propagation.
  • Evidence and Files Tabs — Corrected Evidence tab behavior in Control Implementation and SSP assessment workflows.

User Interface and Usability

  • POA&M Status Board — Fixed navigation, refresh and download actions, deviation-type filtering, empty owner/scope filters, and search behavior.
  • Compliance Hygiene Status Board — Fixed errors affecting the Compliance Hygiene Status Board.
  • Status Board Baseball Cards — Corrected header rendering issues on Status Board Baseball Cards.
  • Report Builder Layout — Fixed chart filter controls overflowing their container in Nova.
  • Security Profiles — Fixed control mappings disappearing after saving column changes.
  • Disabled Controls — Added appropriate visual styling for disabled dropdowns.
  • File Upload UI — Corrected positioning of the file-drop icon and improved upload control presentation.
  • Export Builder Layout — Corrected vertical alignment of uploaded template files and remove controls.
  • Add User Performance — Improved the Add User dialog, which could previously take several seconds to open.
  • Workbench Actions — Fixed issue detail Actions controls that could not be clicked because of global navigation hit-testing.
  • Security Plan UI — Corrected styling issues in inheritance model fields and other Security Plan controls.
  • Classification Banner Accessibility — Corrected insufficient color contrast in the light-theme classification banner to improve WCAG AA compliance.
  • CMMC Export Dialog — Fixed the CMMC SSP pre-export dialog so it opens in the correct layer above the export interface.
  • Save Navigation — Fixed navigation behavior when saves are rejected.

Platform and Infrastructure

  • Concurrent App Creation — Fixed SQL Server deadlock handling during concurrent application creation by adding appropriate retry behavior.
  • Environment Setup — Fixed first-time environment setup failures that could prevent tenant creation on a clean database.
  • Log Event Cleanup — Corrected the nightly process responsible for cleaning the LogEvents table.
  • Syslog Audit Delivery — Fixed duplicate audit records that could be sent to a SIEM when a TLS syslog connection experienced a mid-stream TCP interruption.
  • API Error Handling — Improved API validation responses so users receive more specific error messages rather than generic failures.
  • API Routing — Fixed unmatched routes incorrectly returning the application index page instead of an HTTP 404 response.
  • Release Notifications — Fixed release-notification email failures caused by invalid logger configuration.
  • Application Builds — Resolved stale namespace references that prevented the main application and automated test projects from building successfully.
  • Automated Testing — Corrected end-to-end test data generation issues involving vulnerability field length and invalid CVE values.
  • Coverage Reporting — Updated coverage configuration to include asynchronous method bodies.
  • Audit and Data Access — Corrected service-level data access patterns to ensure tenant isolation, soft-delete behavior, auditing, and webhook processing are consistently applied.