RegScale 6.33.3.0

[6.33.3.0] 08-28-2026

Enhancements

Dashboard Consolidation

The dashboard experience has been consolidated to provide a more consistent and streamlined way to access and review organizational metrics.

Key Risk Indicator (KRI) System

Introduced a Key Risk Indicator system to help organizations monitor important risk metrics, identify threshold breaches, and track risk conditions over time.

FedRAMP POA&M Export Updates

The FedRAMP POA&M export has been updated to align with the current Rev. 5 format and now uses the Export Builder framework for improved consistency and maintainability.

Army Test Results and POA&M Exports

Added support for Army-specific Test Results and POA&M export requirements.

Army Framework Import Profile

Added a profile to support Army framework imports and simplify configuration for Army compliance requirements.

Crosswalk Importer and Converter

Added support for manually importing and converting crosswalk information from supported compliance sources.

RAG Embedding Backfill

Added support for automatically backfilling embeddings for SSPs, Control Implementations, Policies, Evidence, and Components when Retrieval-Augmented Generation (RAG) capabilities are enabled.

SSP Re-Approval for Substantive Changes

Security Plans can now be routed through the appropriate re-approval process when substantive modifications are made.

SSP Approval History

Approval history is now recorded for Security Plans when approval workflows are initiated by triggers, including configurations where the SSP Approval Workflow feature is disabled.

Evidence File Version Management

Improved Evidence file version management, including support for renumbering cycle versions to provide clearer version history.

Security Plan Bulk Editor

Improved the Security Plan Bulk Editor experience, including more consistent placement of drag handles in accordance with application UI conventions.

Catalog Navigation

Improved catalog navigation by selecting the Catalog module by default when appropriate.

Categorization Override

Added support for overriding categorization values where applicable.

AI SSP Author Selection

Improved file selection controls in AI SSP Author, including more reliable Select All and Deselect All functionality.

RegML Author Filtering

Improved bulk selection in RegML Author so that Select All respects the currently active control-family filter.

Accessibility Improvements

Improved accessibility across several areas of the application, including command palette controls, dashboard controls, theme colors, target sizes, and permission-related messaging.

GitHub and Jira Release Documentation

Added documentation describing how GitHub releases correlate with Jira release versions to improve release tracking and traceability.

Fixes

Tasks Navigation and Terminology

Corrected Tasks terminology and navigation across the main Actions module and its record-level subsystem.

File Versioning

Resolved an issue where file version increments could occur unpredictably and unrelated files could incorrectly be marked as superseded.

External Service Status

Resolved an issue preventing External Service entries from being changed to Cancelled status.

Planned Implementation Date

Fixed issues that prevented the Planned Implementation Date from being saved or persisted for controls, including Control Builder v2.

Inheritance Fields

Removed obsolete Inherited and Remote Inheritance Instance fields.

Related Policy Linking

Fixed an issue where a Related Policy selection did not correctly display or link to the associated policy in the Policy module.

Questionnaire Completion

Improved questionnaire completion calculations to provide more reliable completion status and a clear path to submission.

Component and Security Plan Associations

Resolved issues that prevented some Components from being attached to Security Plans.

Control Implementation Display

Fixed the Control Implementation list so that the associated Security Plan title is displayed correctly.

Export Builder and DOCX Templates

Resolved several export-related issues, including:

  • Diagram field placeholders not being replaced correctly in DOCX templates.
  • Export names incorrectly displaying "template."
  • FedRAMP POA&M exports returning errors.
  • Incorrect formatting of the FedRAMP POA&M export dialog.
  • Raw template tokens appearing in FedRAMP Rev. 5 SSP DOCX exports.
  • eMASS SSP exports failing for larger Security Plans.
  • Incorrect MIME type being used for Excel downloads.

Compliance Hygiene Dashboard

Corrected the ISO 27001 catalog information displayed in the Compliance Hygiene Dashboard.

RegML Auditor

Fixed chart scaling that could display values outside the expected 0–100 range.

Evidence and Files

Resolved issues affecting the Evidence and Files experience, including:

  • Incorrect Evidence badge counts.
  • Evidence cycle toggle alignment.
  • Evidence upload styling.
  • Evidence file version numbering.
  • Hard-deleted Evidence records continuing to appear in module lists.

SSP Inventory Workspace

Fixed the SSP Inventory Workspace so vulnerability and issue counts display correctly.

POA&M Status Board

Resolved issues affecting POA&M Status Board record pages and dashboard analytics, including secondary Baseball Cards that could not be selected for drill-down.

Report Builder

Fixed filtering and time-bucketing issues that could cause errors, incorrect filter behavior, or unexpected handling of dates.

XCCDF and STIG Imports

Improved XCCDF import processing to correctly handle valid Boolean values and resolved issues where imported benchmarks could not subsequently be accessed.

Questionnaire Authorization

Corrected authorization controls for Questionnaire endpoints to ensure appropriate permission checks are applied.

API Authorization and Tenant Isolation

Strengthened authorization and tenant-isolation protections across several API operations to prevent unauthorized access to data across application or tenant boundaries.

HTTP Authorization Responses

Corrected API responses so permission failures return the appropriate 403 Forbidden response instead of 401 Unauthorized.

Issue Management

Resolved several issues affecting Issues, including:

  • Facility fields appearing when they should be inactive.
  • Deviation Summary appearing when configured as inactive.
  • Issues becoming unsavable after automation populated Date First Detected.
  • Due Dates being unexpectedly replaced by SLA dates.
  • Blank Date First Detected values being incorrectly populated with the current date and time.

Authorization Boundary Diagrams

Fixed an issue preventing authorization boundary diagrams from being attached or linked within the system authorization boundary description.

Workflow Designer

Resolved an issue where the workflow template designer could fail to load due to invalid automatically saved steps.

Workflow Assignments and History

Fixed workflow tooltips and history displays that incorrectly showed Assigned to: None for Manager-type workflow steps.

Policy Workflows

Resolved an issue where starting a Policy custom workflow could incorrectly activate the Evidence workflow.

Scheduled Audits

Fixed the Lightning Assessment action in Scheduled Audits so that it opens within the appropriate audit context instead of navigating away.

Third-Party Risk Assessments

Corrected the display of control descriptions in Lightning Assessments so that raw HTML is no longer displayed.

Policy Requirement Assessments

Resolved an issue preventing multiple Requirement Assessments from being created from the Assess Requirements workspace.

Security Plan Creation and Naming

Fixed intermittent errors that could occur when creating or renaming Security Plans.

Breadcrumb Navigation

Fixed an issue where Controls did not refresh correctly when navigating from a Component to its parent Security Plan using breadcrumbs.

Implementation Statements

Corrected Control behavior requiring an Implementation Statement when the Control is configured as Fully Inherited.

Form Builder

Fixed an issue where duplicating a field did not create the corresponding custom form field.

Hard Delete Processing

Resolved issues affecting deletion and record cleanup, including records remaining visible after deletion and problems with changes and interconnect deletion workflows.

Catalog Import

Fixed catalog import failures that could occur when users did not have a workspace or application in scope.

Catalog and External Mapping Updates

Improved catalog synchronization and external mapping updates to ensure changes are correctly tracked and existing mapping data is preserved.

Dashboard Drill-Down

Fixed an issue where dashboard drill-down operations could continue retrying indefinitely when underlying module data failed to load.

Application Hierarchy

Resolved concurrency issues that could cause application deletion or creation operations to become blocked or take several minutes to complete.

My Dashboard Accessibility

Improved dashboard control sizing to meet accessibility requirements for interactive target sizes.

Command Palette Accessibility

Restored appropriate accessibility semantics for the command palette and its decorative elements.

Security Plan Creation Stability

Resolved intermittent errors during Security Plan creation when newly created records could not immediately be retrieved within the request scope.

Migration Reliability

Improved migration resilience so migration circuit-breaker state persists across container restarts.

Paging and Sorting

Fixed paging behavior that could cause records to be duplicated or omitted when queries did not have consistent ordering.

KRI Grid

Resolved an issue preventing the KRI grid Save control from displaying correctly.

KRI Breach Processing

Fixed an issue where subsequent KRI threshold breaches could create duplicate Issues instead of updating the existing open Issue.

Request Logging

Corrected request logging so the logged response status accurately reflects the status returned to the client.

Token and Application Context

Resolved an issue where requests without an application identifier could receive an invalid application context, causing subsequent operations to fail.

Cascade Delete Processing

Improved cascade-delete processing to prevent database deadlocks when multiple test suites or delete operations execute concurrently.

Production Container Security

Removed unnecessary build tooling from the production application image to reduce the deployed runtime footprint.

Removed Legacy Automation Credentials

Removed an obsolete plaintext-token service account purpose associated with the retired Automation Manager functionality.

Risk Display

Fixed an issue where risks associated with a Control Implementation were not displayed correctly.

Compliance and Security

Additional security and reliability improvements were made across the platform, including stronger tenant isolation, authorization enforcement, audit handling, error responses, and protection against unintended information disclosure.