RegScale 6.33.3.0
[6.33.3.0] 08-28-2026
Enhancements
Dashboard Consolidation
The dashboard experience has been consolidated to provide a more consistent and streamlined way to access and review organizational metrics.
Key Risk Indicator (KRI) System
Introduced a Key Risk Indicator system to help organizations monitor important risk metrics, identify threshold breaches, and track risk conditions over time.
FedRAMP POA&M Export Updates
The FedRAMP POA&M export has been updated to align with the current Rev. 5 format and now uses the Export Builder framework for improved consistency and maintainability.
Army Test Results and POA&M Exports
Added support for Army-specific Test Results and POA&M export requirements.
Army Framework Import Profile
Added a profile to support Army framework imports and simplify configuration for Army compliance requirements.
Crosswalk Importer and Converter
Added support for manually importing and converting crosswalk information from supported compliance sources.
RAG Embedding Backfill
Added support for automatically backfilling embeddings for SSPs, Control Implementations, Policies, Evidence, and Components when Retrieval-Augmented Generation (RAG) capabilities are enabled.
SSP Re-Approval for Substantive Changes
Security Plans can now be routed through the appropriate re-approval process when substantive modifications are made.
SSP Approval History
Approval history is now recorded for Security Plans when approval workflows are initiated by triggers, including configurations where the SSP Approval Workflow feature is disabled.
Evidence File Version Management
Improved Evidence file version management, including support for renumbering cycle versions to provide clearer version history.
Security Plan Bulk Editor
Improved the Security Plan Bulk Editor experience, including more consistent placement of drag handles in accordance with application UI conventions.
Catalog Navigation
Improved catalog navigation by selecting the Catalog module by default when appropriate.
Categorization Override
Added support for overriding categorization values where applicable.
AI SSP Author Selection
Improved file selection controls in AI SSP Author, including more reliable Select All and Deselect All functionality.
RegML Author Filtering
Improved bulk selection in RegML Author so that Select All respects the currently active control-family filter.
Accessibility Improvements
Improved accessibility across several areas of the application, including command palette controls, dashboard controls, theme colors, target sizes, and permission-related messaging.
GitHub and Jira Release Documentation
Added documentation describing how GitHub releases correlate with Jira release versions to improve release tracking and traceability.
Fixes
Tasks Navigation and Terminology
Corrected Tasks terminology and navigation across the main Actions module and its record-level subsystem.
File Versioning
Resolved an issue where file version increments could occur unpredictably and unrelated files could incorrectly be marked as superseded.
External Service Status
Resolved an issue preventing External Service entries from being changed to Cancelled status.
Planned Implementation Date
Fixed issues that prevented the Planned Implementation Date from being saved or persisted for controls, including Control Builder v2.
Inheritance Fields
Removed obsolete Inherited and Remote Inheritance Instance fields.
Related Policy Linking
Fixed an issue where a Related Policy selection did not correctly display or link to the associated policy in the Policy module.
Questionnaire Completion
Improved questionnaire completion calculations to provide more reliable completion status and a clear path to submission.
Component and Security Plan Associations
Resolved issues that prevented some Components from being attached to Security Plans.
Control Implementation Display
Fixed the Control Implementation list so that the associated Security Plan title is displayed correctly.
Export Builder and DOCX Templates
Resolved several export-related issues, including:
- Diagram field placeholders not being replaced correctly in DOCX templates.
- Export names incorrectly displaying "template."
- FedRAMP POA&M exports returning errors.
- Incorrect formatting of the FedRAMP POA&M export dialog.
- Raw template tokens appearing in FedRAMP Rev. 5 SSP DOCX exports.
- eMASS SSP exports failing for larger Security Plans.
- Incorrect MIME type being used for Excel downloads.
Compliance Hygiene Dashboard
Corrected the ISO 27001 catalog information displayed in the Compliance Hygiene Dashboard.
RegML Auditor
Fixed chart scaling that could display values outside the expected 0–100 range.
Evidence and Files
Resolved issues affecting the Evidence and Files experience, including:
- Incorrect Evidence badge counts.
- Evidence cycle toggle alignment.
- Evidence upload styling.
- Evidence file version numbering.
- Hard-deleted Evidence records continuing to appear in module lists.
SSP Inventory Workspace
Fixed the SSP Inventory Workspace so vulnerability and issue counts display correctly.
POA&M Status Board
Resolved issues affecting POA&M Status Board record pages and dashboard analytics, including secondary Baseball Cards that could not be selected for drill-down.
Report Builder
Fixed filtering and time-bucketing issues that could cause errors, incorrect filter behavior, or unexpected handling of dates.
XCCDF and STIG Imports
Improved XCCDF import processing to correctly handle valid Boolean values and resolved issues where imported benchmarks could not subsequently be accessed.
Questionnaire Authorization
Corrected authorization controls for Questionnaire endpoints to ensure appropriate permission checks are applied.
API Authorization and Tenant Isolation
Strengthened authorization and tenant-isolation protections across several API operations to prevent unauthorized access to data across application or tenant boundaries.
HTTP Authorization Responses
Corrected API responses so permission failures return the appropriate 403 Forbidden response instead of 401 Unauthorized.
Issue Management
Resolved several issues affecting Issues, including:
- Facility fields appearing when they should be inactive.
- Deviation Summary appearing when configured as inactive.
- Issues becoming unsavable after automation populated Date First Detected.
- Due Dates being unexpectedly replaced by SLA dates.
- Blank Date First Detected values being incorrectly populated with the current date and time.
Authorization Boundary Diagrams
Fixed an issue preventing authorization boundary diagrams from being attached or linked within the system authorization boundary description.
Workflow Designer
Resolved an issue where the workflow template designer could fail to load due to invalid automatically saved steps.
Workflow Assignments and History
Fixed workflow tooltips and history displays that incorrectly showed Assigned to: None for Manager-type workflow steps.
Policy Workflows
Resolved an issue where starting a Policy custom workflow could incorrectly activate the Evidence workflow.
Scheduled Audits
Fixed the Lightning Assessment action in Scheduled Audits so that it opens within the appropriate audit context instead of navigating away.
Third-Party Risk Assessments
Corrected the display of control descriptions in Lightning Assessments so that raw HTML is no longer displayed.
Policy Requirement Assessments
Resolved an issue preventing multiple Requirement Assessments from being created from the Assess Requirements workspace.
Security Plan Creation and Naming
Fixed intermittent errors that could occur when creating or renaming Security Plans.
Breadcrumb Navigation
Fixed an issue where Controls did not refresh correctly when navigating from a Component to its parent Security Plan using breadcrumbs.
Implementation Statements
Corrected Control behavior requiring an Implementation Statement when the Control is configured as Fully Inherited.
Form Builder
Fixed an issue where duplicating a field did not create the corresponding custom form field.
Hard Delete Processing
Resolved issues affecting deletion and record cleanup, including records remaining visible after deletion and problems with changes and interconnect deletion workflows.
Catalog Import
Fixed catalog import failures that could occur when users did not have a workspace or application in scope.
Catalog and External Mapping Updates
Improved catalog synchronization and external mapping updates to ensure changes are correctly tracked and existing mapping data is preserved.
Dashboard Drill-Down
Fixed an issue where dashboard drill-down operations could continue retrying indefinitely when underlying module data failed to load.
Application Hierarchy
Resolved concurrency issues that could cause application deletion or creation operations to become blocked or take several minutes to complete.
My Dashboard Accessibility
Improved dashboard control sizing to meet accessibility requirements for interactive target sizes.
Command Palette Accessibility
Restored appropriate accessibility semantics for the command palette and its decorative elements.
Security Plan Creation Stability
Resolved intermittent errors during Security Plan creation when newly created records could not immediately be retrieved within the request scope.
Migration Reliability
Improved migration resilience so migration circuit-breaker state persists across container restarts.
Paging and Sorting
Fixed paging behavior that could cause records to be duplicated or omitted when queries did not have consistent ordering.
KRI Grid
Resolved an issue preventing the KRI grid Save control from displaying correctly.
KRI Breach Processing
Fixed an issue where subsequent KRI threshold breaches could create duplicate Issues instead of updating the existing open Issue.
Request Logging
Corrected request logging so the logged response status accurately reflects the status returned to the client.
Token and Application Context
Resolved an issue where requests without an application identifier could receive an invalid application context, causing subsequent operations to fail.
Cascade Delete Processing
Improved cascade-delete processing to prevent database deadlocks when multiple test suites or delete operations execute concurrently.
Production Container Security
Removed unnecessary build tooling from the production application image to reduce the deployed runtime footprint.
Removed Legacy Automation Credentials
Removed an obsolete plaintext-token service account purpose associated with the retired Automation Manager functionality.
Risk Display
Fixed an issue where risks associated with a Control Implementation were not displayed correctly.
Compliance and Security
Additional security and reliability improvements were made across the platform, including stronger tenant isolation, authorization enforcement, audit handling, error responses, and protection against unintended information disclosure.
