RegScale 6.33.2.0

[6.33.2.0] 08-20-2026

Enhancements

FedRAMP and Compliance

  • FedRAMP Deployment Provider Gating
    Added provider gating for FedRAMP in-boundary deployments to help ensure that government and dedicated environments use supported and compliant service providers.

  • POA&M Status Board Enhancements
    Enhanced the POA&M Status Board with interactive charts and tables, allowing users to select dashboard metrics and drill into the underlying POA&M records.

  • POA&M Date Filtering
    Added improved date filtering capabilities to the POA&M Status Board for more targeted analysis of POA&M activity.

  • POA&M Workflow Status Filtering
    Added workflow status values and corresponding Status Board filters to make it easier to track POA&M progress.

  • POA&M Deviation Request Filtering
    Added the ability to filter POA&Ms based on whether a deviation request is required.

  • FedRAMP POA&M Export Improvements
    Improved POA&M exports to support long asset-identifier lists without exceeding Excel cell-size limitations.

  • FedRAMP Inventory Export Reliability
    Improved background processing and error handling for FedRAMP Inventory exports.

  • OSCAL/XCCDF File Support
    Added to supported file formats, enabling users to upload XCCDF-formatted content.

Security and Access Control

  • Authentication and JWT Hardening
    Strengthened authentication and JWT handling to improve platform security.

  • Service Account Token Rotation
    Added a service-account token rotation capability to support recovery when signing keys change.

  • Improved Service Account Security
    Improved application scoping for service-account operations to ensure users only interact with accounts available within their authorized application context.

  • Enhanced Access Control Filtering
    Improved user and group selection controls and filtering to provide more efficient and appropriately scoped access-management experiences.

  • View-Only Evidence Protection
    Strengthened access controls to prevent view-only tenant users from accessing raw evidence payloads outside their authorized capabilities.

  • Assessor Authorization Improvements
    Added additional tenant and engagement validation when recording assessor determinations.

  • Cross-Tenant Data Protection
    Strengthened tenant isolation across questionnaire, vulnerability, GraphQL, and other API operations.

Audit and Governance

  • Evidence Access Auditing
    Expanded auditing for evidence access so activity is captured on the application paths most commonly used by tenant members.

  • Validation Mapping Audit Visibility
    Improved audit information for validation mappings, including visibility into who confirmed a mapping and when.

  • KSI Revision Chain Auditing
    Improved revision-chain auditing to preserve the actor associated with KSI assertions.

  • System Document Version History
    Improved system document lifecycle management by adding version-history support and safer handling of deleted documents.

  • Evidence Ingest Monitoring
    Improved automated evidence ingestion visibility so rejected evidence and validation failures can be surfaced rather than silently disappearing.

App Builder and Administration

  • Search and Replace Utility
    Added a Search and Replace utility to simplify bulk updates to applicable platform content.

  • Security Profile Management
    Improved installation, display, and management of RegScale security profiles.

  • Color Theme Administration
    Improved tenant validation and error handling when configuring color themes.

  • Categorization Engine Configuration
    Improved the categorization-engine workflow so users can continue configuring questions immediately after creating an engine.

  • Security Plan Wizard
    Expanded access to the Security Plan Wizard from applicable Security Plan creation workflows.

  • Access Control User Pickers
    Modernized user and group selectors for improved performance and usability.

Questionnaires and Workflow

  • Questionnaire Scoring Improvements
    Improved questionnaire scoring behavior, including checkbox-based scoring and maximum-score calculations.

  • Questionnaire Assignment and Notification Improvements
    Improved questionnaire assignment, feedback, and submission notification workflows.

  • Questionnaire Rules Engine Experience
    Improved the Rules Engine interface to provide a clearer and more consistent save experience.

  • Workflow Approval Experience
    Improved approval workflow panels, comments, rejection routing, and handling of deleted records associated with approval workflows.

Reporting and Dashboards

  • Report Builder Improvements
    Improved report generation and handling of vulnerability-related report modules.

  • Dashboard Drill-Down Improvements
    Improved dashboard drill-down behavior to ensure users receive appropriately filtered results.

  • Compliance Explorer Improvements
    Improved cross-framework coverage calculations so partial coverage is accurately represented.

  • Security Plan Export Improvements
    Improved exports so objective-row control mappings are correctly represented.

  • MAC Address Validation
    Standardized MAC address formatting and validation across supported interfaces and backend services.

Performance and Reliability

  • Vulnerability Processing Performance
    Improved vulnerability batch processing by reducing unnecessary database queries and duplicate operations.

  • Background Job Reliability
    Improved background-job status handling so unsuccessful operations are no longer incorrectly reported as completed.

  • Artifact Lifecycle Management
    Improved artifact expiration processing to ensure expired artifacts are handled as expected.

  • Application Logging Improvements
    Improved application logging and monitoring integration to provide better visibility into application activity and failures.

  • Event and Webhook Management
    Improved webhook administration and event-management interfaces, including better responsive behavior and accessibility.

  • Responsive Dashboard Experience
    Improved dashboard layouts for narrower screen sizes to prevent horizontal overflow.


Fixes

Compliance and FedRAMP

  • Fixed an issue where SSP Control Implementations were sorted correctly in the middle panel but not in the left navigation panel.
  • Fixed mismatches between Control Implementation fields exposed through the UI and API.
  • Fixed an issue preventing Security settings from being cleared on child records when using Apply to Child Records.
  • Fixed an issue where CIS/CRM imports did not advance the last-updated timestamp for control parts.
  • Fixed SSP Author processing that caused the entire plan to be processed regardless of accepted mappings.
  • Fixed assessment-generated POA&Ms receiving identical or non-descriptive titles.
  • Fixed automatic POA&M creation when a failed test references a missing parent test.
  • Fixed several FedRAMP import services that failed to populate audit timestamps on imported records.
  • Fixed FedRAMP Inventory exports that could report completion without generating an output file.
  • Fixed inventory exports that could fail because of memory limitations.
  • Fixed an issue where the FedRAMP Inventory export background process could fail and prevent subsequent exports.
  • Fixed Security Plan exports where objective-row control mappings were displayed incorrectly.
  • Fixed an issue where Not-Applicable KSIs were incorrectly included in provider compliance percentages.
  • Fixed Compliance Explorer reporting that incorrectly represented partial cross-framework coverage as full coverage.

Evidence and Files

  • Fixed the Upload Multiple Files functionality.
  • Fixed file uploads being rejected because the extension was not included in permitted file extensions.
  • Fixed replaced and deleted file uploads remaining in cloud storage.
  • Improved evidence-file lifecycle handling during version-to-cycle transitions.
  • Fixed Evidence & Files behavior within the SSP Subsystem workflow.
  • Fixed an issue where rejected evidence from automated ingestion was not surfaced to users.
  • Fixed an issue where evidence validation could stop without providing an indication that processing had failed.

Security and Tenant Isolation

  • Fixed tenant-isolation issues involving questionnaire instances accessed without the appropriate tenant scope.
  • Fixed GraphQL vulnerability-mapping queries that could bypass tenant and application filtering.
  • Fixed a security issue where RegML could retrieve implementation statements from another application or the default application.
  • Fixed an issue where assessor determinations did not adequately validate the associated engagement and tenant.
  • Fixed an issue where view-only tenant users could access raw evidence payloads.
  • Fixed service-account operations that were inconsistently scoped between listing and individual account operations.
  • Fixed application and tenant validation issues affecting color-theme endpoints.
  • Fixed an issue where administrators could receive incorrect authorization responses from GraphQL parameter queries.

Authentication and Identity

  • Fixed Entra SAML thin provisioning so newly provisioned users receive their email address, first name, and last name.
  • Fixed AD/LDAP synchronization from the AD/SYNC Preview page.
  • Fixed authentication failures affecting the Harvester following security updates to the platform.
  • Fixed an issue where valid lockout duration values of were rejected.
  • Fixed Swagger-generated API commands that omitted the required API-version header for v1 and v2 calls.
  • Fixed several API authorization responses that incorrectly returned HTTP 500 instead of HTTP 403.

Questionnaires

  • Fixed questionnaire assignment and submission notifications that were not consistently generated.
  • Fixed the Send Feedback workflow routing respondents to My Workbench instead of the questionnaire.
  • Fixed question-level feedback emails that were not being sent to external respondents.
  • Fixed questionnaire checkbox scoring that could report a maximum score lower than the actual possible score.
  • Fixed questionnaire score calculations that could exceed 100%.
  • Fixed questionnaire rule-builder behavior involving assignment-month calculations and boolean/zero-valued responses.
  • Fixed confusing Rules Engine behavior caused by multiple Save buttons.
  • Fixed questionnaire view-model handling.

Workflows

  • Fixed approval workflows and notifications that remained after the associated record was deleted.
  • Fixed workflow-template loading failures caused by invalid auto-save submissions.
  • Fixed workflow instances incorrectly returning HTTP 403 when an authorized user had no visible workflow steps.
  • Fixed workflow approval comments and rejection-routing behavior.
  • Fixed background workflow processing where unsuccessful results could incorrectly be reported as completed.

Reporting and Dashboards

  • Fixed unexpected data appearing in Report Builder columns.
  • Fixed the Issue by Security Plan and Deviation Status report drill-down link.
  • Fixed vulnerability report generation failures caused by unsupported module handling.
  • Fixed dashboard drill-down queries that could load unfiltered data.
  • Fixed issues-by-status-and-owner components that could fail when API responses were not returned as arrays.
  • Fixed Issues by Status and Owner reports to correctly process paginated API responses.
  • Fixed Manage Risks drill-down pagination alignment.
  • Fixed ScoreCard Issues, Milestones, and Tasks tabs appearing empty for certain record types.
  • Fixed Gantt views incorrectly capping displayed issues and reporting the page size as the total.
  • Fixed AI-generated narrative citations being calculated but not displayed to reviewers.

Export Builder

  • Fixed Export Builder mappings that displayed Select... instead of the saved field name when reopened.
  • Fixed Sub Template mapping dropdowns that displayed Select rather than the mapped field name.
  • Fixed Export Builder service and worksheet-related contract issues.
  • Fixed export-template validation messages to provide more specific guidance.
  • Fixed seeded export names and descriptions being unintentionally reset to their defaults.
  • Fixed FedRAMP inventory and POA&M export reliability issues.

App Builder and UI

  • Fixed the Duplicate hover state in App Builder App Management appearing continuously.
  • Fixed the Security Profile installation page displaying raw catalog UUIDs instead of readable profile names.
  • Fixed the Security Profile deletion workflow.
  • Fixed the Profile Importer page title being overwritten by an embedded registry component.
  • Fixed the SSP Wizard Finish button displaying an incorrect toast message.
  • Fixed builder-wizard completion behavior when no profile was selected.
  • Fixed Form Builder factory-reset operations that displayed an error toast despite the operation completing.
  • Fixed required-field validation appearing during Summarize Control Parts instead of at the appropriate Save operation.
  • Fixed validation errors displayed when summarizing controls.
  • Fixed the per-data-type C/I/A override behavior to ensure an override applies only to its intended information type.
  • Fixed inherited and remotely inherited controls displaying duplicate entries per control part in Control Builder.
  • Fixed Status Board title issues.
  • Fixed filter controls that were visually misaligned with their associated filter rows.
  • Fixed Webhook administration dialogs where action buttons could be inaccessible at the bottom of the viewport.
  • Fixed My Dashboard layouts overflowing horizontally on narrow screens.
  • Fixed dark-mode rendering issues for Control Details in Lightning assessments within Third Party Risk.

Issues and Risk Management

  • Fixed a 405 error encountered when navigating to vulnerabilities.
  • Fixed deletion workflows to account for VulnerabilityMapping dependencies before removing records.
  • Fixed issue batch processing where affected controls and asset identifiers were not included in batch requests.
  • Fixed risk dashboard drill-down behavior and stale list-view reuse.
  • Fixed validation errors that could occur when saving or updating requirements.
  • Fixed cleanup failures that could leave orphaned subsystem records after security controls were deleted.
  • Fixed risk records being incorrectly categorized under an unspecified bucket.

Data Integrity and Reliability

  • Fixed seeding-lock database errors.
  • Fixed application changes endpoints returning errors for authenticated users.
  • Fixed Control Implementation API requests returning incorrect responses.
  • Fixed pagination behavior that could duplicate or omit records during paged reads.
  • Fixed migration circuit-breaker logic that could fail to activate because failure timestamps could not be parsed.
  • Fixed application logging issues that prevented logs from reaching Application Insights.
  • Fixed silent subsystem-cleanup failures.
  • Fixed error-log date filtering so the end date includes the complete day.
  • Fixed constraint violations being exposed as technical errors instead of user-friendly messages.
  • Fixed API behavior for non-existent Security Plan identifiers so requests return an appropriate not-found response instead of HTTP 500.

Security Profiles and System Management

  • Fixed RegScale Profiles installation when default profiles were not displayed.
  • Fixed profile prerequisite messages that exposed raw catalog UUIDs rather than readable names.
  • Fixed issues preventing Security Profiles from being deleted.
  • Fixed Trust Center behavior so the New System button is hidden when an applicable FedRAMP system already exists.
  • Added a Trust Center notification identifying when a system is non-production.

KSI and Validation

  • Fixed KSI revision history so the actor associated with assertion creation is retained.
  • Fixed the Public KSI page displaying literal Boolean values instead of user-friendly status information.
  • Fixed the Public KSI page so the last validation date is displayed.
  • Fixed KSI compliance calculations so Not-Applicable KSIs are not incorrectly included.
  • Improved validation audit visibility and historical accountability.

User Experience and Notifications

  • Fixed drill-down modals that could not be closed.
  • Fixed Save buttons and dialogs that could become inaccessible due to viewport positioning.
  • Fixed workflow and release notification failures.
  • Fixed Slack and Teams background-process notifications when the associated tenant could not be resolved.
  • Fixed questionnaire notification inconsistencies.
  • Fixed an issue where service-account token exceptions could unnecessarily appear in logs.
  • Improved user-facing validation and error messages throughout the platform.

Security Hardening

  • Strengthened SaaS configuration-secret handling, including Key Vault reference resolution and validation of JWT signing keys.
  • Fixed authorization and tenant-scoping gaps across questionnaire, evidence, vulnerability, service-account, and assessment workflows.
  • Improved audit coverage for evidence access and validation activity.
  • Improved handling of sensitive authentication and service-account operations.