[6.33.1.0] 08-14-2026

Enhancements

AI and RegML

  • Expanded AI Agent Capabilities — Added AI Agent capabilities for Lines of Inquiry, Corrective Action Plans, Risk Treatment Mappings, Questionnaire Scoring, Lightning Assessment Tests, and Security Control Test Generation.
  • RegML Mapping Recommendations — Enhanced RegML capabilities with recommendations to assist users in mapping relevant content.
  • Azure OpenAI Connectivity Validation — Added startup connectivity validation to provide earlier detection of Azure OpenAI configuration or connectivity issues.
  • Improved RegML Reporting — Enhanced Report Builder support for RegML-generated reports and related-module fields.
  • Improved RegML Error Handling — Improved error reporting so connectivity and network issues are no longer incorrectly reported as API-key permission problems.

Evidence and Control Management

  • Evidence Improvements — Expanded evidence management capabilities and improved evidence workflows throughout Control Implementation and assessment experiences.
  • Evidence-to-Control Mapping Propagation — Improved the propagation of evidence-to-control relationships.
  • Enhanced Evidence Linking — Updated Control Implementation and SSP assessment workflows to provide improved access to evidence and files.
  • SSP Evidence Linking Options — Enhanced the System Security Plan creation wizard to support opting into evidence linking.
  • Evidence Management Consolidation — Improved the Evidence experience by consolidating Locker and List View functionality.

Security Plans and Excel Import/Export

  • Canonical SSP Excel Template — Added a standardized Security Plan Excel template schema with versioned metadata.
  • Downloadable SSP Excel Template — Added the ability to download a blank canonical SSP Excel template directly from the application.
  • SSP Excel Template Validation and Preview — Added validation, preview, and confirmation capabilities when uploading an SSP Excel template.
  • SSP Excel Import — Added support for creating and updating Security Plans from the canonical Excel template.
  • SSP Excel Export — Added the ability to export a Security Plan to the canonical Excel template format.
  • Export Builder Templates — Added the ability to download Export Builder templates.
  • Improved Export Integration Testing — Expanded automated integration coverage for export functionality.

Compliance and Catalogs

  • Control Framework Gap Assessment — Added enhanced support for evaluating gaps across control frameworks.
  • Automated Risk Mappings — Added automation capabilities to simplify risk-to-control mapping activities.
  • Expanded Compliance Settings — Expanded compliance configuration capabilities to support additional security management use cases.
  • Improved CRI Catalog Support — Enhanced support for CRI-related catalog functionality, including AI and cloud catalog capabilities.
  • OpenSSF Catalog — Added support for the OpenSSF catalog.
  • Security Plan Changelog — Added changelog visibility for Security Plans to improve traceability of changes.
  • SBOM Child Visibility — Added support for viewing child records associated with SBOM information.

Risk Management

  • Risk Module Enhancements — Improved risk management capabilities to support expanded risk workflows.
  • Aggregate CCM Dashboard — Added an aggregate dashboard for improved visibility into CCM-related information.
  • Risk Treatment Control Selection — Enhanced risk treatment workflows with improved control selection and filtering.
  • Risk Mapping Automation — Added capabilities to automate risk mappings and improve consistency across risk management workflows.

Workflow and Navigation

  • Kanban Navigation — Added Next/Previous navigation to Kanban workflows.
  • Workflow Designer Improvements — Enhanced workflow configuration and approval experiences.
  • Workflow Approval Accessibility — Improved access to workflow instances and approvals across applications.
  • Improved Record Navigation — Enhanced record navigation so Back actions return users to the expected previous screen.
  • Improved Grid Views — Continued UI and usability improvements to custom grid views.

Security and Platform Hardening

  • Authentication and JWT Hardening — Strengthened authentication and JWT handling to improve platform security.
  • Account Lockout Improvements — Enhanced account lockout and brute-force protection capabilities.
  • Authentication Rate Limiting — Improved authentication request throttling and protection against automated account enumeration.
  • Tenant Isolation Improvements — Strengthened tenant isolation across platform services and data access.
  • Security Audit Improvements — Enhanced auditing of API-created records and security-sensitive operations.
  • FedRAMP High UI Support — Added a FedRAMP High badge to the application footer.
  • Improved Accessibility — Improved UI accessibility, including WCAG-related color contrast and disabled-control styling.

User Interface Improvements

  • UI Polish — Continued visual and usability improvements across UI interface.
  • SSP Author Experience — Updated the SSP Author page to align with the current application branding and UI standards.
  • Export Builder UI Improvements — Improved template upload and management controls.
  • Status Board Improvements — Enhanced Status Board presentation and Baseball Card layouts.
  • File Upload Guidance — Improved the file upload experience by displaying supported file type restrictions.
  • Form Validation Improvements — Enhanced field validation behavior within Form Builder.
  • Questionnaire Improvements — Improved questionnaire self-assignment URL capabilities.
  • Workbench Link Support — Improved handling of hyperlinks in task and issue descriptions.

Fixes

Authentication and Security

  • SSO Role Assignment — Fixed an issue that could allow users authenticating through SSO to manipulate local application roles and produce unexpected access behavior.
  • SSO Application Administration — Fixed application administrator claim handling so app-admin privileges are correctly aligned with application group membership.
  • JWT Authentication — Fixed an intermittent issue where authentication tokens could be issued without the required expiration claim.
  • Authentication Regression — Resolved an issue causing authenticated API requests to intermittently return HTTP 401 responses in UI.
  • Account Enumeration Protection — Secured login configuration endpoints against unauthenticated account and tenant enumeration.
  • MFA Information Exposure — Prevented pre-authentication endpoints from exposing tenant identifiers, tenant names, or MFA posture.
  • Authorization Enforcement — Corrected missing module-permission checks on Control Implementation endpoints.
  • Exception Information Exposure — Fixed validation errors that could expose unnecessary exception details through API responses.
  • Tenant Isolation — Corrected cross-tenant data access paths in lineage and module-related services.
  • Security Audit Logging — Fixed security audit logging for password changes and API-created records.
  • Rate Limiting — Corrected authentication rate-limit calculations and ensured throttling responses report the appropriate limit and retry information.
  • Account Lockout — Fixed an issue where account lockout settings could be ineffective when the lockout duration was configured with a zero value.

Export Builder and Exports

  • Export Template Creation — Fixed an issue preventing users from creating Export Builder templates.
  • Export Template File Removal — Fixed errors that could occur when removing files from Export Builder templates.
  • Export Field Mapping — Fixed an issue where the Export Field mapping dropdown appeared empty in Nova.
  • Export Status Visibility — Fixed the Export Status box appearing behind the Export modal.
  • POA&M Re-Export — Fixed an issue requiring users to refresh or navigate away from the page before exporting a Rev5 POA&M again.
  • SSP Export Generation — Fixed an issue where SSP document exports could be generated as empty documents.
  • OSCAL Export — Fixed OSCAL SSP export failures when the Authorization Boundary was not populated.
  • OSCAL Non-NIST Catalogs — Fixed export failures for controls without Control IDs, including controls from non-NIST catalogs.
  • FedRAMP Rev5 SSP Export — Corrected cover-page typography and Ports & Protocols table formatting.
  • FedRAMP Rev5 Appendix A Export — Corrected fonts, colors, bullets, and Customer Responsibility content.
  • FedRAMP Rev5 Appendix Q Export — Corrected title, color, and formatting issues.
  • FedRAMP Rev5 CIS/CRM Export — Corrected control ordering in the High CIS worksheet.
  • FedRAMP Inventory Export — Addressed issues affecting FedRAMP inventory exports.
  • eMASS POA&M Export — Improved conditional handling of comments and milestones based on issue status.
  • eMASS Export Licensing Display — Corrected an incorrect Syncfusion license expiration message displayed during eMASS exports.

SSP and Compliance

  • SSP Compliance Scores — Fixed an issue preventing compliance scores from being generated on the SSP Dashboard.
  • SSP Control Population — Fixed SSP creation so controls are correctly populated from the selected profile and manually added controls can be added successfully.
  • Compliance Settings — Fixed the Control Builder so it correctly honors compliance settings when compliance configuration is changed on an existing SSP.
  • Inherited Controls in ScoreCards — Fixed an issue preventing inherited controls from appearing in ScoreCards.
  • SAP/SAR Export — Corrected the RMF Effort field in Section 1 of SAP/SAR exports.
  • Security Plan Status by Family — Corrected erroneous information indicators appearing in the Status by Family table.
  • Control Implementation Status Dashboard — Fixed an issue causing the By Status dashboard view to display no results.
  • Policy-to-Control Mapping — Fixed policy relationships so policies linked through Related Policies are correctly mapped to the associated control.

Risk Management

  • Risk Drill-Down — Fixed Manage Risks dashboard drill-down behavior so selecting a pie-chart segment displays only the risks represented by that segment.
  • Risk Treatment Control Filtering — Fixed control selection in Risk Treatments so users can filter the available controls.
  • Risk Treatment Control View — Fixed blank View Control dialogs when a control could not be loaded and improved error handling.
  • Risk Assessment Guidance — Improved the Risk Assessment experience when required risk configuration has not yet been established.
  • Risk Control Treatment Messaging — Fixed an erroneous "No Available Controls" warning after canceling a treatment and relinking controls.
  • Risk Assessment Help Modal — Fixed an issue preventing the Risk Assessment Help modal from closing correctly and corrected its styling.

Workflow

  • Workflow Template Steps — Fixed an intermittent issue where newly added workflow template steps appeared to save successfully but were not persisted.
  • Workflow Step Deletion — Fixed Visual Designer errors that could prevent workflow steps from being deleted and leave the UI unresponsive.
  • Workflow Branch Approval — Fixed an issue preventing halted branch steps without an assignee from being approved or rejected.
  • Workflow Branch Navigation — Improved validation of "Go to step" targets so unreachable workflow steps cannot be selected without appropriate warning.
  • Workflow Approvals Access — Fixed inconsistent permissions that could prevent users from accessing the workflow approvals inbox.
  • Workflow Security Plan Scoping — Corrected application scoping for System Role data used during SSP exports.

Data and Records

  • Data Save Handling — Fixed UI behavior where rejected saves could incorrectly navigate users back to a list.
  • Data Editor Validation — Fixed stale invalid text remaining in the Data editor after a rejected save.
  • Record Back Navigation — Corrected the Back button so users return to the previous screen instead of the module list.
  • Component Deletion — Fixed an issue preventing users from deleting multiple components at once.
  • ConMon Cleanup — Fixed cleanup behavior that could leave orphaned Vulnerability Mappings and inflate vulnerability counts.
  • Module Access Validation — Fixed errors returned when requesting a module outside the caller's tenant.
  • User Removal — Fixed errors that could occur when removing a user from an application.
  • Risk Record Permissions — Corrected permissions that could allow users with CRU access to delete risk records.

Questionnaires and Forms

  • Questionnaire Save — Fixed the Save button when field validation errors are present.
  • Questionnaire Self-Assignment — Fixed an issue preventing self-assignment URLs from being enabled.
  • Form Builder Validation — Corrected new-field validation behavior so validations do not trigger prematurely.
  • Questionnaire Data Export — Fixed Export Orchestration so it uses the most recent questionnaire response data rather than the original response data.

Evidence

  • Evidence Mapping Dialog — Added vertical scrolling support to the Evidence control-mapping dialog.
  • Evidence Relationships — Fixed evidence-to-control relationship propagation.
  • Evidence and Files Tabs — Corrected Evidence tab behavior in Control Implementation and SSP assessment workflows.

User Interface and Usability

  • POA&M Status Board — Fixed navigation, refresh and download actions, deviation-type filtering, empty owner/scope filters, and search behavior.
  • Compliance Hygiene Status Board — Fixed errors affecting the Compliance Hygiene Status Board.
  • Status Board Baseball Cards — Corrected header rendering issues on Status Board Baseball Cards.
  • Report Builder Layout — Fixed chart filter controls overflowing their container in Nova.
  • Security Profiles — Fixed control mappings disappearing after saving column changes.
  • Disabled Controls — Added appropriate visual styling for disabled dropdowns.
  • File Upload UI — Corrected positioning of the file-drop icon and improved upload control presentation.
  • Export Builder Layout — Corrected vertical alignment of uploaded template files and remove controls.
  • Add User Performance — Improved the Add User dialog, which could previously take several seconds to open.
  • Workbench Actions — Fixed issue detail Actions controls that could not be clicked because of global navigation hit-testing.
  • Security Plan UI — Corrected styling issues in inheritance model fields and other Security Plan controls.
  • Classification Banner Accessibility — Corrected insufficient color contrast in the light-theme classification banner to improve WCAG AA compliance.
  • CMMC Export Dialog — Fixed the CMMC SSP pre-export dialog so it opens in the correct layer above the export interface.
  • Save Navigation — Fixed navigation behavior when saves are rejected.

Platform and Infrastructure

  • Concurrent App Creation — Fixed SQL Server deadlock handling during concurrent application creation by adding appropriate retry behavior.
  • Environment Setup — Fixed first-time environment setup failures that could prevent tenant creation on a clean database.
  • Log Event Cleanup — Corrected the nightly process responsible for cleaning the LogEvents table.
  • Syslog Audit Delivery — Fixed duplicate audit records that could be sent to a SIEM when a TLS syslog connection experienced a mid-stream TCP interruption.
  • API Error Handling — Improved API validation responses so users receive more specific error messages rather than generic failures.
  • API Routing — Fixed unmatched routes incorrectly returning the application index page instead of an HTTP 404 response.
  • Release Notifications — Fixed release-notification email failures caused by invalid logger configuration.
  • Application Builds — Resolved stale namespace references that prevented the main application and automated test projects from building successfully.
  • Automated Testing — Corrected end-to-end test data generation issues involving vulnerability field length and invalid CVE values.
  • Coverage Reporting — Updated coverage configuration to include asynchronous method bodies.
  • Audit and Data Access — Corrected service-level data access patterns to ensure tenant isolation, soft-delete behavior, auditing, and webhook processing are consistently applied.

ROH 6.32.0.4 Release

Release Overview

Release Name: ROH Beta Hotfix Release

Release Type: Hotfix

Release Number: 6.32.0.4

Purpose

RegScale Orchestration Hub (ROH) enables organizations to automate the import and export of data between RegScale and external systems through configurable integrations and commands.

This beta release is intended for early adopters and validation of core orchestration capabilities. Functionality, supported integrations, and performance characteristics may change before General Availability (GA). This minor release delivers reliability, usability, and maintenance improvements for early adopters, summarized below.

What's Fixed

  • Duplicate software inventory on repeated asset syncs: Asset syncs no longer add a second copy of an asset's software inventory each time they run. Previously every run appended the full list again, so a package that should appear once was listed twice after the second sync and gained another entry with each run after that. Software inventory is now reconciled against the records RegScale already holds, and packages reported more than once within a single scan are collapsed into one entry. This affects every integration that synchronizes assets in batches. Note that this fix prevents new duplicates from being recorded; it does not remove entries already written, so any duplicates accumulated before upgrading need to be cleared separately.
  • Tanium Cloud vulnerability and compliance synchronization on large data sets: Tanium Cloud jobs that collect vulnerability and compliance findings no longer stop before ingesting any records when a request exceeds the Tanium gateway's data limit. ROH now reduces the amount of data requested per page and retries automatically, so these synchronizations complete. Previously an affected run could finish and report success while ingesting nothing.
  • Consistent Qualys asset identifiers: Qualys assets are now recorded with the same identifier whether the asset is created for the first time or updated by a later synchronization. Previously the two paths wrote different values, which could leave an asset's vulnerabilities and issues unlinked from the asset itself. Existing Qualys assets are updated in place to the corrected identifier, so they keep their RegScale IDs and their existing links.

Maintenance and Updates

  • Routine dependency and security updates across backend components.

[6.40.0] - 2026-08-13

Added

  • Configurable base directory for scanner and integration output files via the artifactsDir setting
  • Optional Wiz data-retention reconciliation that closes issues whose findings have aged out of Wiz's retention window, enabled with wizRetentionReconciliation and tuned with wizDataRetentionDays

Changed

  • Changelog entries are now added as changelog.d fragment files per PR instead of editing CHANGELOG.md directly
  • Historical changelog entries are now organized into one file per minor release under changelog/, with the root file holding only an index
  • JCAM POA&M imports now warn when a POA&M's criticality is missing or unrecognized instead of silently importing it with no severity

Fixed

  • Repeated asset syncs no longer add a duplicate copy of every software inventory record to each asset
  • Software inventory no longer records a package twice when a scanner reports the same name and version more than once for one asset
  • Wiz report generation now retries rate-limited and transient gateway responses instead of failing the run
  • Wiz syncs now warn when the server caps or truncates a result set, so a partial pull is no longer mistaken for a complete one
  • Wiz vulnerability findings now carry CVSS v2 and v3 vectors and a known-exploit flag, with EPSS scores, CISA KEV listing, detection method, container layer provenance, and lifecycle dates recorded in the plugin output
  • Wiz assets now record their Wiz resource id on the asset's Wiz ID field, so an asset can be traced back to its record in the Wiz console and matched on later imports
  • AWS assets now honor the setting that copies the asset identifier into the Other Identifier field, so findings link to the correct asset instead of an unknown one
  • Wiz sync now closes findings that were resolved at the source; a failing excessive-access query had been disabling stale-finding closure for the entire run
  • Wiz cloud configuration findings are now scoped to the selected project instead of being pulled tenant-wide
  • Wiz compliance report is now reused after it has been renamed in the Wiz console instead of a duplicate being created on every run
  • Wiz consolidated issues no longer close automatically when Wiz reports a status the CLI does not recognize
  • Wiz network exposures that have no matching asset in RegScale are now logged, instead of being dropped silently
  • Wiz policy compliance now fetches assessments scoped to the selected Wiz project instead of the entire tenant, and warns when a tenant rejects every project filter and the fetch falls back to tenant-wide
  • Asset and component mapping lookups, along with issue, link, assessment, risk, threat, and other GraphQL queries, no longer fail with a server field error caused by an internal constant leaking into the request
  • AWS EC2 instance, Lambda function, and ECS cluster inventory now honor the configured account ID and tag filters instead of returning every resource in the region
  • AWS CloudTrail log metadata collection now honors the configured account ID filter instead of collecting metadata for trails owned by other accounts

[6.39.0] - 2026-08-10

Added

  • Splunk integration with search, streaming export, saved searches, search job management, asset and finding processing, and evidence ingestion
  • splunk sync command that runs the saved searches listed in splunkSavedSearches and imports assets, findings, and control evidence in one pass, running each saved search only once no matter how many import targets are enabled
  • Splunk evidence ingestion driven by named saved searches, so control evidence can be collected on a schedule without exporting search results by hand
  • Splunk HTTP Event Collector upload command for pushing JSON, CSV, or raw log files into Splunk
  • Splunk advanced export command supporting JSON, CSV, TSV, XML, and raw output with optional gzip, bzip2, or LZMA compression and chunked files
  • Splunk support for instances behind an Entra ID Application Proxy, including Azure Government
  • Splunk saved searches can name the controls their evidence attests to, overriding the control identifier in the search results, so evidence still maps when a search is labelled in a different control framework than the security plan
  • Splunk evidence can map to several controls at once, and results can name several controls in one field, comma-separated, space-separated, or as a multivalue field
  • Splunk result fields holding the control and evidence title are configurable, so searches naming them anything other than control_id and control_evidence work without changes
  • Splunk evidence can map control labels from another framework onto the security plan's controls using the crosswalks shipped with the CLI, so a search labelled in CMMC, CSF, SOC 2, ISO 27001, or CIS can attach evidence to a NIST plan; off by default via splunkCrossFrameworkMapping, with every translation logged
  • Splunk evidence control matching ignores zero-padding differences between catalogs, so a result naming AC-2 maps correctly in a plan that labels the same control AC-02
  • Splunk evidence ingestion reports when a source carries no control fields versus when a control ID doesn't exist in the target plan, naming the plan's actual controls so a framework mismatch is obvious
  • Splunk assets record the operating system reported by the search
  • Splunk process and ingest-evidence accept -m / --regscale_module to attach records to a component instead of a security plan
  • Splunk connection credentials can be supplied through the SPLUNK_USERNAME and SPLUNK_PASSWORD environment variables, keeping secrets out of the command line
  • Splunk commands run unattended without interactive prompts, using configured or sensible default values for connection port, scheme, timeout, result limit, output mode, and TLS verification
  • Splunk sync and process report a failing exit code when Splunk returns data but nothing is written to RegScale, so scheduled runs don't report success when nothing was actually imported
  • Splunk logs and audit records omit the Splunk account name and replace search text with a non-reversible fingerprint by default, so personal data in a query is not written to disk; set splunkLogQueryText to true to record the full text
  • FedRAMP Key Security Indicator (KSI) and Zero Trust Architecture (ZTA) control crosswalks, so evidence and findings labelled in either framework can map to NIST 800-53 controls

Changed

  • Imported scan files now keep their original name and are filed under a dated folder, processed/YYYY-MM-DD/, instead of having a timestamp appended to the filename
  • Re-importing a file on a day it was already imported now saves it alongside the earlier copy as name_2 rather than leaving it behind in the scan folder
  • The log line after an import now reports where the scan file was actually moved and uploaded from
  • CSAM is now JCAM throughout the CLI, following the DoJ's rename of the product; use regscale jcam and the jcam* settings in init.yaml
  • Existing CSAM setups keep working without changes — regscale csam, the csam* init.yaml settings, and the "CSAM Id" field on the system Basic Info tab are all still honored, with a warning pointing to the new names
  • The JCAM API route prefix can now be set with the jcamBasePath setting for tenants whose route has been renamed

Fixed

  • Snyk findings now record the date from the FIRST_INTRODUCED column as their first seen date, falling back to the scan file's date when the column is empty or unreadable
  • Snyk XLSX imports no longer fail with a type error when the FIRST_INTRODUCED column is populated; dates, times, and blank values are all accepted, with the scan date used when a value cannot be read
  • Flat file imports no longer report a parsing error for Microsoft Office lock files (~$name.xlsx) or hidden sidecar files left in the scan folder; they are now skipped
  • Qualys API errors are now reported with their real meaning instead of "Unknown error code", so rate limits, bad credentials, and rejected filter parameters are each named and can be acted on
  • Qualys authentication failures are now recognized as fatal and stop the run rather than being reported as a missing response
  • Records that fail validation now report the specific field and reason instead of being silently sent to RegScale as empty requests and rejected
  • Jira task sync now skips and reports individual issues that cannot be mapped to a RegScale task, instead of stopping the rest of the sync
  • Security patch for the bundled HTTP/2 dependency, resolving a request smuggling advisory
  • Security patches for the bundled GitPython, python-multipart, Ansible, and Airflow SMTP provider dependencies, resolving multiple high-severity advisories
  • Qualys VMDR scan report imports now record the CVE, CVSS v3 and v2 base scores, Qualys ID, and first and last detected dates on each vulnerability, which were previously left blank
  • Qualys VMDR scan report vulnerabilities are now kept as separate records per Qualys ID instead of collapsing into a single record per security plan
  • Qualys Web Application Scanning imports no longer fail with a validation error when creating vulnerabilities
  • Bulk vulnerability and issue imports no longer fail with stream or connection errors when a single finding affects many assets, which prevented AWS Security Hub syncs from saving vulnerabilities; requests are now sized by the number of affected assets and can be tuned with maxAssetIdentifiersPerBatch in init.yaml
  • eMASS CAC authentication on macOS no longer terminates the CLI without an error message; a versioned OpenSSL library is now located explicitly, and a clear message is shown when OpenSSL 3 is not installed

[6.33.0.1] 08-10-2026

Bug Fixes

  • Minor bug fixes made to the POA&M Status Board.

[6.33.0.0] 08-10-2026

App Builder Enhancements

  • The App Management page now provides the option to define a hierarchy of applications.

  • Within the application's Advanced Security tab, you can now enable global visibility for the parent-level application.

  • Users with access to multiple applications and Report Mode are provided with a dropdown containing all available applications and a toggle to switch to Report Mode.

    • Report Mode provides users with view-only access to all selected applications.
    • Users can select data from the applications they want to include, generate reports, and view dashboards containing data across multiple applications.

eMASS Export Templates

  • eMASS export templates are now supported in additional formats.

Evidence Module Enhancements

  • The Evidence Locker and Evidence Module have been consolidated into a single, updated Evidence Module view.
  • Evidence records can now be automatically mapped to controls using catalog-based relationships.

General Usability Improvements

  • Evidence Versioning: A new per-user setting determines whether uploading a file with the same name defaults to creating a new version or adding to the current version. The default remains New Version, and users can still override the choice for individual uploads.
  • The Grid UI element now allows users to customize which columns are displayed.
  • Related-record forms across the application now remain open and display an error when a save fails. The form closes only after a save is confirmed as successful.
  • Pick Lists and Lookups: Components that have not yet been assigned to a compliance framework now appear in Security Plan component mapping lists instead of being hidden.

RegML Updates

  • A new RegML Agents page lists all available RegML agents, describes what each agent does, and identifies where each agent can be used.

    • Agent runs are recorded, and the time and cost savings from AI-assisted work roll up into the Administrator Cost Savings view.
  • Use RegML to generate lines of inquiry for an Assessment Plan based on the relevant control and assessment context, eliminating the need to manually write each question.

  • The new Corrective Action Plan Generator analyzes an issue and proposes a set of remediation tasks, including a suggested owner and due date. Users can adjust the proposed tasks before creating them.

  • The new Risk Control Mapper recommends existing security controls that can mitigate a risk, providing a confidence score and rationale for each recommendation.

  • The Risk Mitigation Plan Generator drafts standalone treatment plans for risks based on user-provided direction.

  • RegML can now draft per-question scores and reviewer feedback for completed questionnaires. Reviewers can edit and approve the results rather than manually grading every response.

  • RegML can draft assessment tests for a control in the Lightning Assessment wizard.

  • Users can draft catalog-level Security Control Test Plans from a control's Test Plans tab, with options for high-level, standard, or detailed test granularity.

SSP Imports Action

Security Plans now support a new Imports action for uploading supported files directly to a Security Plan.

The following file types are supported:

  • FedRAMP Inventory Workbook: Upload the standard Excel workbook to populate the system inventory.
  • POA&Ms: Upload the standard FedRAMP POA&M Excel template to bulk-create issues and findings.
  • CIS/CRM Workbook: Import CIS Benchmark or CRM tracking workbook files.
  • FedRAMP SSP in OSCAL: Import an existing FedRAMP SSP in OSCAL JSON or XML format to create a complete SSP record with controls pre-populated.
  • Deviation Request Forms: Import the standardized FedRAMP form.

SSP Software Bill of Materials Inventory

  • A Security Plan's SBOM tab can now display the complete software inventory within scope, including SBOMs attached directly to the plan as well as those attached to its components and assets.

  • A new Direct / All Related toggle on the plan's SBOM tab expands the view from the plan's direct SBOMs to all SBOMs associated with the plan, its components, and its assets.

    • A Source column identifies where each SBOM is associated.
  • Users can open, compare, and edit an SBOM directly from the related list while maintaining its association with the correct component or asset.

  • SBOM previews, copies, and downloads now produce clean, readable JSON.

Preset Configuration Templates

  • A new US Air Force template is now available under Preset Configuration Templates.

POA&M Status Board

The POA&M Status Board provides an interactive experience that makes it easier to track, investigate, and act on POA&M items. Dashboard visualizations—including pie charts, bar charts, and summary metrics—are interactive. Users can select a dashboard element to drill down directly into the corresponding POA&M records.

  • A new POA&M Status Board displays POA&Ms and includes filters for Deviation Requests.
  • POA&Ms are created by selecting the POA&M page on an issue and selecting Cyber Reportable Plan of Action and Milestones as the Type and the appropriate Status.
  • The Deviation Request page is now available when an Issue is converted to a POA&M.
  • To convert an issue to a Deviation Request, select Deviation Request as the Type and select the appropriate Status.
  • Interactive Dashboard Metrics: Click charts, chart elements, and summary metrics to investigate the underlying POA&M records.
  • Automatic Filtering: Selecting a dashboard metric automatically applies the corresponding filter to the POA&M record list. Existing dashboard filters are retained when drilling down, providing consistent context throughout the investigation.
  • POA&M Record Navigation: Individual POA&M records can be selected directly from the filtered results to open their detail pages.
  • Permission-Aware Results: Dashboard metrics and drill-down results respect user permissions, ensuring users only see POA&M records they are authorized to access.
  • Consistent Metrics: Dashboard counts remain consistent with the records available to the user based on their permissions.

Vulnerability Management Enhancements

  • A vulnerability's Days Open value is now calculated from the date the vulnerability was first detected.

    • The value increases daily while the vulnerability remains open.
    • Once the vulnerability is closed or mitigated, the value stops increasing and is frozen at the closure date.
  • The Days Open column now sorts correctly based on the calculated age.

  • The Stale quick filter, which identifies findings that have been open for more than 90 days, now uses the same corrected calculation.

[6.38.0] - 2026-08-05

Added

  • eMASS CAC authentication can trust a custom CA bundle (e.g. DoD PKI) for verifying the eMASS server certificate via emass.ssl_ca_cert or the EMASS_SSL_CA_CERT environment variable, with a matching --ca-cert option on emass_api register

Fixed

  • Security patches for the bundled aiohttp and cryptography dependencies, resolving multiple high-severity advisories
  • eMASS CAC registration now reads the server response reliably instead of erroring on TLS retry or an unexpected connection close, and reports the redirect target when the request is bounced to a gateway login (a sign the certificate is not a registered API client)
  • eMASS CAC authentication now pins OpenSC to the PIV driver so dual CAC+PIV cards no longer intermittently fail with "PKCS11_get_private_key returned NULL"; override with OPENSC_DRIVER for legacy cards
  • eMASS CAC registration now reports a clean error message instead of a raw stack trace when the server's certificate cannot be verified or when CAC transport setup fails (missing PKCS#11 engine or private-key load failure)
  • SSP and Appendix A imports now bring in every sub-part of a control part, such as Part a(1) and a(2), instead of keeping only the last one
  • SSP imports and updates no longer fail with a "field must be enabled to enter a value" error when a plan has a FedRAMP ID, which disables the Other and Private deployment model options in RegScale
  • SSP saves no longer fail when any other form field is disabled in RegScale, and instead save without that field and report which fields were skipped
  • FedRAMP SSP imports only record deployment model remarks when the deployment model is Other, instead of filling them in for public, private, hybrid, and government clouds
  • AWS Inspector V2 POA&M exports now show AWS Inspector V2 as the weakness detector source instead of a generic Scanner Integration label
  • AWS Inspector V2 syncs now close out issues and POA&M items for findings that are no longer reported by Inspector, including on repeat runs the same day, and skip the close-out when account, tag, or resource-type filters mean the run covers only part of the environment
  • AWS Inspector V2 control mappings no longer report scanning coverage gaps against CM-6, which Inspector produces no configuration baseline evidence for; coverage gaps and container image scanning are now reported under RA-5, and SA-11 covers Lambda static code analysis only

[6.37.69] - 2026-07-30

Added

  • Option to sync Qualys and Prisma vulnerabilities and issues without creating or updating assets
  • Tanium open ports and protocols synchronization to assets and the system Ports, Protocols, and Services table

Changed

  • Tanium ports and protocols sync now recognizes many more service names (VNC, Redis, MongoDB, Elasticsearch, Kafka, and others), falling back to the operating system service list before labeling a port Unknown
  • SARIF import summary now reports the number of vulnerabilities created or updated rather than splitting the two, since the batch endpoint does not report which records were new
  • Nessus findings are now labeled with the scan name from each .nessus file, so imports of multiple scans can be told apart instead of all showing a generic Nessus source

Fixed

  • GCP inventory collection now gathers Compute, GKE, Cloud Run, Cloud Functions, Filestore, IAM, networking, and DNS resources that previously failed to load
  • Qualys asset tracking numbers no longer carry a security-plan suffix, and Qualys syncs now rewrite previously suffixed tracking numbers so existing assets keep their vulnerability and issue links instead of being duplicated
  • Qualys asset re-syncs no longer overwrite an asset's tracking number with a different value than the one used when the asset was created, which had prevented vulnerabilities and issues from linking to the asset
  • Qualys import_scans no longer fails immediately with an unexpected keyword argument error, and now honors --dry-run and the AWS credential options when downloading files from S3
  • Qualys sync_qualys now applies the --asset_group_id and --asset_group_name filters instead of silently syncing every asset
  • Nessus finding and issue titles no longer end in "None" when a plugin provides no synopsis
  • AWS asset sync no longer creates a duplicate AWS account asset for every IAM role, which had forced the batch upload into slow one-at-a-time processing
  • Tanium ports and protocols sync no longer creates duplicate rows when the same port is reported more than once for an endpoint
  • GitPython version security patch for high-severity security advisory
  • Wiz STIG import no longer creates duplicate assessments when the same asset and benchmark are imported more than once in a day
  • Bulk control implementation and software inventory updates now persist instead of silently failing
  • FedRAMP document imports no longer silently drop stakeholders that are missing a job title
  • FedRAMP stakeholder import no longer fails with an authorization error when creating stakeholders or reading existing ones, which had prevented stakeholders from importing and could create duplicates
  • eMASS SLCM import no longer fails to read control implementations due to a dropped authorization header
  • FedRAMP stakeholder imports preserve street address details in notes when a country is not provided
  • SARIF imports now flag findings as Known Exploited Vulnerabilities when their CVE is on the CISA KEV catalog; previously the CVE was discarded and the records bypassed the ingestion path that applies KEV matching
  • SARIF findings now take their severity from the file's level value, mapping error to High, warning to Medium, note to Low, and none to Informational; previously every level was stored as Low regardless of what the file said
  • SARIF imports no longer store a value in the CVE field when it is not a well-formed CVE identifier
  • Run and step timing summaries ("Completed: ... in ...") are now logged in non-interactive runs (redirected or containerized output), not only when attached to a terminal

ROH 6.32.0.3 Release

Release Overview

Release Name: ROH Beta Hotfix Release

Release Type: Hotfix

Release Number: 6.32.0.3

Purpose

RegScale Orchestration Hub (ROH) enables organizations to automate the import and export of data between RegScale and external systems through configurable integrations and commands.

This beta release is intended for early adopters and validation of core orchestration capabilities. Functionality, supported integrations, and performance characteristics may change before General Availability (GA). This minor release delivers reliability, usability, and maintenance improvements for early adopters, summarized below.

What's Fixed

  • Tanium fixes and improvements: Tanium data synchronization is now more complete and accurate — vulnerability and compliance findings reliably link back to the correct assets, and vulnerability severities reflect the most current scoring. Asset syncs now also capture installed software, a software bill of materials (SBOM), and open network ports and protocols.

Maintenance and Updates

  • Routine dependency and security updates across backend components.

[6.32.3.0] 07-25-2026

Enhancements

  • Expanded Asset Scanning Configuration

    • Added an Asset Scanning Tool De-Duplication option, giving administrators greater control over how duplicate findings are identified and consolidated during asset scanning workflows.
  • Improved Framework Template Experience

    • Renamed Framework Importer to Preset Configuration Templates to better reflect its purpose and improve discoverability within the application.
  • Export Builder Template Downloads

    • Added the ability to download associated template files directly from the Export Builder configuration menu, making it easier to obtain and work with import/export templates.

Fixes

Administration & Security

  • Fixed an issue where newly created users in newly provisioned tenants could be prevented from logging in.
  • Resolved an issue where cross-tenant access events were not properly recorded.
  • Corrected several User Management audit logging inconsistencies where events were either missing or incorrectly logged as failures.
  • Fixed an issue where Service Accounts appeared in questionnaire user assignment lists, ensuring only appropriate assignable users are displayed.

User Experience

  • Fixed an accessibility issue where opening the Approval History dialog did not properly prevent interaction with the left navigation panel.
  • Corrected an issue that prevented the Save button loading indicator from displaying while save operations were in progress.
  • Resolved an issue where custom dropdown fields could incorrectly display cached values when hovering over entries and could not be properly cleared or removed.
  • Resolved issue where Asset Hardware Creation does not save certain Yes/No fields.

Export Builder

  • Fixed an issue that prevented Import Mapping Functions from working correctly within Export Builder.
  • Resolved an issue where the Export Field dropdown displayed no available values when configuring export mappings.
  • Corrected a layout issue that caused the Export Builder configuration page to render in a narrow column instead of using the full available workspace.
  • Restored the Clear option for Export Field selections, allowing mappings to be removed as expected.

Catalog & Framework Management

  • Fixed an issue where catalog update-in-place operations could silently skip updating objectives, test plans, CCIs, and parameters, improving the reliability of catalog synchronization.

Platform Reliability

  • Resolved an intermittent issue that could cause HTTP 500 errors immediately after login due to Entity Framework query compilation conflicts when adapting RAG embedding dimensions. This improves application stability and login reliability.

[6.37.45] - 2026-07-22

Added

  • eMASS sync_system command to synchronize all structural records (assets, controls, POAMs, milestones, artifacts) between a RegScale SSP and its linked eMASS system in a single dependency-ordered invocation
  • AWS Inspector sync --exclude_tags option to skip resources carrying the given tags, with --exclude_tags_match any|all
  • CSAM organization-defined parameter (ODP) import into RegScale's OSCAL parameter model, with an Excel mapping workbook for reviewing unmatched values

Changed

  • FIPS container image now built on a Python 3.12 base to align with the Airflow FIPS image and clear security policy scanning
  • AWS Inspector V2 sync keeps only the most recently pushed image per ECR repository and names assets by repository and digest instead of image tag, and can be turned off with --no_dedupe_ecr_images or the inspectorDedupeEcrImages init.yaml setting to sync every image digest
  • AWS Inspector V2 sync scopes compliance coverage and statistics to the selected resource types
  • AWS Inspector V2 sync now applies the --tags filter server-side when pulling findings and coverage, so only tagged resources are retrieved instead of being downloaded and then filtered
  • Minimum supported Python version raised to 3.11 (Python 3.10 is no longer supported)
  • Jira Data Center tickets pushed from RegScale now include the issue's recommended actions and remediation description along with a direct link back to the source RegScale issue

Fixed

  • Qualys sync now applies the configured Total Cloud include and exclude tag filters when the command-line tag options are not supplied, instead of silently ingesting all Total Cloud data
  • FIPS container image now built on a Python 3.12 base to align with the Airflow FIPS image and clear security policy scanning
  • Wiz container images pinned by digest now import with a version derived from the image digest instead of a blank value, so downstream eMASS hardware/software exports no longer fail validation on the required Version field
  • Wiz secret findings that share a detection rule now consolidate into a single issue listing all affected resources instead of creating a near-identical issue for each resource
  • Scanner imports no longer intermittently drop vulnerability-to-asset links under heavy multi-threaded processing