RegScale 6.33.2.0
[6.33.2.0] 08-20-2026
Enhancements
FedRAMP and Compliance
-
FedRAMP Deployment Provider Gating
Added provider gating for FedRAMP in-boundary deployments to help ensure that government and dedicated environments use supported and compliant service providers. -
POA&M Status Board Enhancements
Enhanced the POA&M Status Board with interactive charts and tables, allowing users to select dashboard metrics and drill into the underlying POA&M records. -
POA&M Date Filtering
Added improved date filtering capabilities to the POA&M Status Board for more targeted analysis of POA&M activity. -
POA&M Workflow Status Filtering
Added workflow status values and corresponding Status Board filters to make it easier to track POA&M progress. -
POA&M Deviation Request Filtering
Added the ability to filter POA&Ms based on whether a deviation request is required. -
FedRAMP POA&M Export Improvements
Improved POA&M exports to support long asset-identifier lists without exceeding Excel cell-size limitations. -
FedRAMP Inventory Export Reliability
Improved background processing and error handling for FedRAMP Inventory exports. -
OSCAL/XCCDF File Support
Added to supported file formats, enabling users to upload XCCDF-formatted content.
Security and Access Control
-
Authentication and JWT Hardening
Strengthened authentication and JWT handling to improve platform security. -
Service Account Token Rotation
Added a service-account token rotation capability to support recovery when signing keys change. -
Improved Service Account Security
Improved application scoping for service-account operations to ensure users only interact with accounts available within their authorized application context. -
Enhanced Access Control Filtering
Improved user and group selection controls and filtering to provide more efficient and appropriately scoped access-management experiences. -
View-Only Evidence Protection
Strengthened access controls to prevent view-only tenant users from accessing raw evidence payloads outside their authorized capabilities. -
Assessor Authorization Improvements
Added additional tenant and engagement validation when recording assessor determinations. -
Cross-Tenant Data Protection
Strengthened tenant isolation across questionnaire, vulnerability, GraphQL, and other API operations.
Audit and Governance
-
Evidence Access Auditing
Expanded auditing for evidence access so activity is captured on the application paths most commonly used by tenant members. -
Validation Mapping Audit Visibility
Improved audit information for validation mappings, including visibility into who confirmed a mapping and when. -
KSI Revision Chain Auditing
Improved revision-chain auditing to preserve the actor associated with KSI assertions. -
System Document Version History
Improved system document lifecycle management by adding version-history support and safer handling of deleted documents. -
Evidence Ingest Monitoring
Improved automated evidence ingestion visibility so rejected evidence and validation failures can be surfaced rather than silently disappearing.
App Builder and Administration
-
Search and Replace Utility
Added a Search and Replace utility to simplify bulk updates to applicable platform content. -
Security Profile Management
Improved installation, display, and management of RegScale security profiles. -
Color Theme Administration
Improved tenant validation and error handling when configuring color themes. -
Categorization Engine Configuration
Improved the categorization-engine workflow so users can continue configuring questions immediately after creating an engine. -
Security Plan Wizard
Expanded access to the Security Plan Wizard from applicable Security Plan creation workflows. -
Access Control User Pickers
Modernized user and group selectors for improved performance and usability.
Questionnaires and Workflow
-
Questionnaire Scoring Improvements
Improved questionnaire scoring behavior, including checkbox-based scoring and maximum-score calculations. -
Questionnaire Assignment and Notification Improvements
Improved questionnaire assignment, feedback, and submission notification workflows. -
Questionnaire Rules Engine Experience
Improved the Rules Engine interface to provide a clearer and more consistent save experience. -
Workflow Approval Experience
Improved approval workflow panels, comments, rejection routing, and handling of deleted records associated with approval workflows.
Reporting and Dashboards
-
Report Builder Improvements
Improved report generation and handling of vulnerability-related report modules. -
Dashboard Drill-Down Improvements
Improved dashboard drill-down behavior to ensure users receive appropriately filtered results. -
Compliance Explorer Improvements
Improved cross-framework coverage calculations so partial coverage is accurately represented. -
Security Plan Export Improvements
Improved exports so objective-row control mappings are correctly represented. -
MAC Address Validation
Standardized MAC address formatting and validation across supported interfaces and backend services.
Performance and Reliability
-
Vulnerability Processing Performance
Improved vulnerability batch processing by reducing unnecessary database queries and duplicate operations. -
Background Job Reliability
Improved background-job status handling so unsuccessful operations are no longer incorrectly reported as completed. -
Artifact Lifecycle Management
Improved artifact expiration processing to ensure expired artifacts are handled as expected. -
Application Logging Improvements
Improved application logging and monitoring integration to provide better visibility into application activity and failures. -
Event and Webhook Management
Improved webhook administration and event-management interfaces, including better responsive behavior and accessibility. -
Responsive Dashboard Experience
Improved dashboard layouts for narrower screen sizes to prevent horizontal overflow.
Fixes
Compliance and FedRAMP
- Fixed an issue where SSP Control Implementations were sorted correctly in the middle panel but not in the left navigation panel.
- Fixed mismatches between Control Implementation fields exposed through the UI and API.
- Fixed an issue preventing Security settings from being cleared on child records when using Apply to Child Records.
- Fixed an issue where CIS/CRM imports did not advance the last-updated timestamp for control parts.
- Fixed SSP Author processing that caused the entire plan to be processed regardless of accepted mappings.
- Fixed assessment-generated POA&Ms receiving identical or non-descriptive titles.
- Fixed automatic POA&M creation when a failed test references a missing parent test.
- Fixed several FedRAMP import services that failed to populate audit timestamps on imported records.
- Fixed FedRAMP Inventory exports that could report completion without generating an output file.
- Fixed inventory exports that could fail because of memory limitations.
- Fixed an issue where the FedRAMP Inventory export background process could fail and prevent subsequent exports.
- Fixed Security Plan exports where objective-row control mappings were displayed incorrectly.
- Fixed an issue where Not-Applicable KSIs were incorrectly included in provider compliance percentages.
- Fixed Compliance Explorer reporting that incorrectly represented partial cross-framework coverage as full coverage.
Evidence and Files
- Fixed the Upload Multiple Files functionality.
- Fixed file uploads being rejected because the extension was not included in permitted file extensions.
- Fixed replaced and deleted file uploads remaining in cloud storage.
- Improved evidence-file lifecycle handling during version-to-cycle transitions.
- Fixed Evidence & Files behavior within the SSP Subsystem workflow.
- Fixed an issue where rejected evidence from automated ingestion was not surfaced to users.
- Fixed an issue where evidence validation could stop without providing an indication that processing had failed.
Security and Tenant Isolation
- Fixed tenant-isolation issues involving questionnaire instances accessed without the appropriate tenant scope.
- Fixed GraphQL vulnerability-mapping queries that could bypass tenant and application filtering.
- Fixed a security issue where RegML could retrieve implementation statements from another application or the default application.
- Fixed an issue where assessor determinations did not adequately validate the associated engagement and tenant.
- Fixed an issue where view-only tenant users could access raw evidence payloads.
- Fixed service-account operations that were inconsistently scoped between listing and individual account operations.
- Fixed application and tenant validation issues affecting color-theme endpoints.
- Fixed an issue where administrators could receive incorrect authorization responses from GraphQL parameter queries.
Authentication and Identity
- Fixed Entra SAML thin provisioning so newly provisioned users receive their email address, first name, and last name.
- Fixed AD/LDAP synchronization from the AD/SYNC Preview page.
- Fixed authentication failures affecting the Harvester following security updates to the platform.
- Fixed an issue where valid lockout duration values of were rejected.
- Fixed Swagger-generated API commands that omitted the required API-version header for v1 and v2 calls.
- Fixed several API authorization responses that incorrectly returned HTTP 500 instead of HTTP 403.
Questionnaires
- Fixed questionnaire assignment and submission notifications that were not consistently generated.
- Fixed the Send Feedback workflow routing respondents to My Workbench instead of the questionnaire.
- Fixed question-level feedback emails that were not being sent to external respondents.
- Fixed questionnaire checkbox scoring that could report a maximum score lower than the actual possible score.
- Fixed questionnaire score calculations that could exceed 100%.
- Fixed questionnaire rule-builder behavior involving assignment-month calculations and boolean/zero-valued responses.
- Fixed confusing Rules Engine behavior caused by multiple Save buttons.
- Fixed questionnaire view-model handling.
Workflows
- Fixed approval workflows and notifications that remained after the associated record was deleted.
- Fixed workflow-template loading failures caused by invalid auto-save submissions.
- Fixed workflow instances incorrectly returning HTTP 403 when an authorized user had no visible workflow steps.
- Fixed workflow approval comments and rejection-routing behavior.
- Fixed background workflow processing where unsuccessful results could incorrectly be reported as completed.
Reporting and Dashboards
- Fixed unexpected data appearing in Report Builder columns.
- Fixed the Issue by Security Plan and Deviation Status report drill-down link.
- Fixed vulnerability report generation failures caused by unsupported module handling.
- Fixed dashboard drill-down queries that could load unfiltered data.
- Fixed issues-by-status-and-owner components that could fail when API responses were not returned as arrays.
- Fixed Issues by Status and Owner reports to correctly process paginated API responses.
- Fixed Manage Risks drill-down pagination alignment.
- Fixed ScoreCard Issues, Milestones, and Tasks tabs appearing empty for certain record types.
- Fixed Gantt views incorrectly capping displayed issues and reporting the page size as the total.
- Fixed AI-generated narrative citations being calculated but not displayed to reviewers.
Export Builder
- Fixed Export Builder mappings that displayed Select... instead of the saved field name when reopened.
- Fixed Sub Template mapping dropdowns that displayed Select rather than the mapped field name.
- Fixed Export Builder service and worksheet-related contract issues.
- Fixed export-template validation messages to provide more specific guidance.
- Fixed seeded export names and descriptions being unintentionally reset to their defaults.
- Fixed FedRAMP inventory and POA&M export reliability issues.
App Builder and UI
- Fixed the Duplicate hover state in App Builder App Management appearing continuously.
- Fixed the Security Profile installation page displaying raw catalog UUIDs instead of readable profile names.
- Fixed the Security Profile deletion workflow.
- Fixed the Profile Importer page title being overwritten by an embedded registry component.
- Fixed the SSP Wizard Finish button displaying an incorrect toast message.
- Fixed builder-wizard completion behavior when no profile was selected.
- Fixed Form Builder factory-reset operations that displayed an error toast despite the operation completing.
- Fixed required-field validation appearing during Summarize Control Parts instead of at the appropriate Save operation.
- Fixed validation errors displayed when summarizing controls.
- Fixed the per-data-type C/I/A override behavior to ensure an override applies only to its intended information type.
- Fixed inherited and remotely inherited controls displaying duplicate entries per control part in Control Builder.
- Fixed Status Board title issues.
- Fixed filter controls that were visually misaligned with their associated filter rows.
- Fixed Webhook administration dialogs where action buttons could be inaccessible at the bottom of the viewport.
- Fixed My Dashboard layouts overflowing horizontally on narrow screens.
- Fixed dark-mode rendering issues for Control Details in Lightning assessments within Third Party Risk.
Issues and Risk Management
- Fixed a 405 error encountered when navigating to vulnerabilities.
- Fixed deletion workflows to account for VulnerabilityMapping dependencies before removing records.
- Fixed issue batch processing where affected controls and asset identifiers were not included in batch requests.
- Fixed risk dashboard drill-down behavior and stale list-view reuse.
- Fixed validation errors that could occur when saving or updating requirements.
- Fixed cleanup failures that could leave orphaned subsystem records after security controls were deleted.
- Fixed risk records being incorrectly categorized under an unspecified bucket.
Data Integrity and Reliability
- Fixed seeding-lock database errors.
- Fixed application changes endpoints returning errors for authenticated users.
- Fixed Control Implementation API requests returning incorrect responses.
- Fixed pagination behavior that could duplicate or omit records during paged reads.
- Fixed migration circuit-breaker logic that could fail to activate because failure timestamps could not be parsed.
- Fixed application logging issues that prevented logs from reaching Application Insights.
- Fixed silent subsystem-cleanup failures.
- Fixed error-log date filtering so the end date includes the complete day.
- Fixed constraint violations being exposed as technical errors instead of user-friendly messages.
- Fixed API behavior for non-existent Security Plan identifiers so requests return an appropriate not-found response instead of HTTP 500.
Security Profiles and System Management
- Fixed RegScale Profiles installation when default profiles were not displayed.
- Fixed profile prerequisite messages that exposed raw catalog UUIDs rather than readable names.
- Fixed issues preventing Security Profiles from being deleted.
- Fixed Trust Center behavior so the New System button is hidden when an applicable FedRAMP system already exists.
- Added a Trust Center notification identifying when a system is non-production.
KSI and Validation
- Fixed KSI revision history so the actor associated with assertion creation is retained.
- Fixed the Public KSI page displaying literal Boolean values instead of user-friendly status information.
- Fixed the Public KSI page so the last validation date is displayed.
- Fixed KSI compliance calculations so Not-Applicable KSIs are not incorrectly included.
- Improved validation audit visibility and historical accountability.
User Experience and Notifications
- Fixed drill-down modals that could not be closed.
- Fixed Save buttons and dialogs that could become inaccessible due to viewport positioning.
- Fixed workflow and release notification failures.
- Fixed Slack and Teams background-process notifications when the associated tenant could not be resolved.
- Fixed questionnaire notification inconsistencies.
- Fixed an issue where service-account token exceptions could unnecessarily appear in logs.
- Improved user-facing validation and error messages throughout the platform.
Security Hardening
- Strengthened SaaS configuration-secret handling, including Key Vault reference resolution and validation of JWT signing keys.
- Fixed authorization and tenant-scoping gaps across questionnaire, evidence, vulnerability, service-account, and assessment workflows.
- Improved audit coverage for evidence access and validation activity.
- Improved handling of sensitive authentication and service-account operations.
