RegScale 6.34.1.0

[6.34.1.0] 09-14-2026

Enhancements

Control Guidance, Assessments & Compliance

  • Control Guidance: Control guidance now separates base guidance from supplemental profile guidance, so users can distinguish the standard requirement from framework-specific additions during assessment and authoring.
  • SSP and Control Assessment Navigation: Clearer control status indicators and streamlined navigation in the control assessment workflow reduce the clicks needed to move between controls during authoring and review.

Report Builder & Compliance Reporting

  • Report Builder Module Support: Report Builder now supports tenant-renamed modules (reports display the tenant's custom module name instead of the default) and adds Control Implementations and Interconnections as reportable modules.

Workflow & Automation

  • Webhook Reliability: Improved webhook management and event-subscription handling for a more reliable automation experience.

Artifact, Catalog & Import Workflows

  • Data Import and Integration Reliability: Improved reliability across vulnerability, checklist, OCSF, catalog, and other data-import workflows to reduce duplicate or incomplete records.

Form & Questionnaire Management

  • Form Builder: Enhanced validation and conditional-field behavior to provide more immediate and accurate feedback when building and completing forms.

Accessibility

  • Enhanced accessibility through improved table semantics, ARIA support, dark-mode color contrast, report tables, and form validation messaging.

Fixes

Authentication, SSO & Session Management

  • Login and Authentication: Resolved multiple issues that could prevent users from logging in correctly, including incorrect errors for deactivated users and authentication configuration and validation issues.
  • SSO Session Handling: Resolved issues affecting SAML session handoff and identity-provider session handling.
  • Logout Behavior: Resolved an issue where logging out of RegScale did not terminate the associated identity-provider session, which could cause the next SSO login to reuse the previous identity.
  • OIDC Configuration: Resolved issues involving OIDC audience comparisons and encryption-key configuration that could cause valid configurations to fail.
  • Login Diagnostics: Improved authentication logging and diagnostics to make OIDC and other login failures easier to troubleshoot.
  • Login Username Handling: Resolved an issue where usernames entered through an SSO login form were not consistently handled during authentication.

Security

  • Input & Log Handling: Improved sanitization and handling of user-provided input in logs and application content to prevent malformed log entries and unsafe content from being persisted or interpreted.
  • AI Prompt Protection: Strengthened handling of untrusted content supplied to AI processing to reduce the risk of unintended prompt manipulation.
  • Security Dependencies: Updated application dependencies and container components as part of routine vulnerability patching.

POA&M & Compliance Reporting

  • POA&M Export Reliability: Resolved issues that could cause POA&M exports to time out or consume excessive resources in environments with large volumes of POA&M records.
  • Reporting: Resolved formatting and data-display issues affecting nested parameters. Resolved an issue requiring users to run the Control Framework Gap Report twice before results were displayed.

Assessments, SSPs & Controls

  • SSP Risk Assessment Utility: Resolved an issue that prevented the SSP Risk Assessment Utility from functioning correctly.
  • Control Owner Updates: Resolved an issue where updates to CI Control Owners were not saving the correct information.
  • Assessment Restore: Restored the ability to create a new SSP record through the applicable restore workflow.
  • Assessment Authoring: Resolved an issue where plan authoring could complete with blank statements when an unreadable document was uploaded.
  • Checklist Re-import: Resolved an issue where re-importing a checklist could update only one asset per rule and fail to create records for newly introduced rules.
  • Requirements Mapping: Resolved an issue where attempting to remap an already-mapped control resulted in an error.
  • Continuous Monitoring Assessments: Resolved an issue where Lightning Assessments launched from Continuous Monitoring Assessments did not display the Control Preview pane.
  • SSP Wizard: Resolved multiple issues affecting SSP wizard navigation, validation, and data handling.
  • Control Implementation Parameters: Resolved an issue where control implementations created through certain API paths did not persist associated parameter records.
  • Component Type Display: Corrected Component Type dropdown options that were displayed in lowercase.

Forms & Questionnaires

  • Form Validation: Resolved an issue where field validation messages were not displayed until a dropdown was opened.
  • Conditional Fields: Resolved an issue where conditional fields remained hidden when a form was initially loaded until the triggering field was changed.
  • Custom Checkbox Values: Corrected inconsistent rendering of custom checkbox fields when stored values used representations other than the expected string format.
  • Custom Organization Fields: Resolved an issue where Custom Fields using the Organizations type did not display saved values in the user interface.
  • Questionnaire Assignment: Resolved issues with questionnaire assignment and removal, including validation behavior and authorization handling.
  • Questionnaire Access & Permissions: Improved permission enforcement for questionnaire operations and resolved issues that could allow unauthorized users to access questionnaire information.
  • Self-Assignment URLs: Resolved an issue where opening the Self-Assign URL dialog for an already-enabled questionnaire could unexpectedly save the questionnaire and report success.

Navigation & User Interface

  • Control & Module Navigation: Resolved issues with side navigation, workspace tooltips, module naming, and other navigation elements that could obscure or incorrectly display application controls.
  • Dark Mode: Resolved visual issues affecting the Security Plan Control Bulk Editor and improved text contrast for dark-mode users.
  • Calendar Navigation: Resolved an issue where navigating between months from dates near the end of a month could require an extra click.
  • RegML AI Generator: Resolved an issue where the RegML AI Generator menu item was displayed for Components even though the functionality was unavailable.

Attachments, Records & Saving

  • WYSIWYG Attachments: Resolved an issue where the WYSIWYG editor could report that an attachment was uploaded successfully even though the file was not added to the record.
  • Unexpected Record Saves: Resolved issues where navigation or preview actions could unexpectedly save record changes.
  • Artifact & Evidence Association: Corrected file and version associations to ensure content is linked to the appropriate audit cycle and record.

Accessibility & Application Behavior

  • Accessibility & Reduced Motion: Resolved issues affecting animations and accessibility behavior for users with operating-system motion-reduction settings enabled.
  • Application Startup: Resolved issues with configuration values containing accidental whitespace that could prevent an instance from starting correctly.