Archive for RegScale

RegScale Collaborates with Microsoft to Support Accelerated FedRAMP Readiness

Posted in Commentary with tags on August 19, 2026 by itnerd

RegScale, the AI-powered continuous controls monitoring (CCM) platform, today announced it is collaborating with Microsoft to help customers pursue FedRAMP readiness and authorization to operate (ATO) efforts on Microsoft Azure. RegScale customers will benefit from Microsoft Azure’s FedRAMP-authorized secure cloud environment complemented by RegScale’s compliance automation and continuous controls monitoring platform. 

Achieving FedRAMP has long been one of the most time-consuming and resource-intensive milestones for any CSP selling to the U.S. federal government, often taking a minimum of 18 months. This collaboration pairs the scale of Microsoft with RegScale’s compliance-as-code native platform to help software providers realize a faster, clearer route to certification, regardless of where they are in their compliance journey.

The partnership also aligns with FedRAMP 20x, the initiative that moves security assurance away from point-in-time paperwork toward continuous, automated validation. Its core principles of transparency, flexibility, accountability, accuracy, and automatic validation map directly to how RegScale operates: continuously validating controls and reporting on them in real time rather than staging evidence for an audit.

RegScale supports the customer-owned compliance automation and continuous controls monitoring path by automating evidence collection, continuously validating controls against FedRAMP’s Key Security Indicators (KSIs) and through RegScale’s RegML AI agents, and turns FedRAMP certification from a periodic project into a continuous capability.

RegScale builds on a proven federal track record: the company achieved FedRAMP High in just six months using its own platform, a fraction of the typical 18-month minimum timeline. That combination of credibility and automation enables RegScale to serve as an important compliance automation path for industry customers seeking to achieve their own FedRAMP certification.

Looking ahead, the collaboration lays the groundwork for RegScale’s expanding role in the federal ecosystem, including forthcoming capabilities to help agencies consume continuous monitoring data directly from their cloud service providers.

RegScale Achieves ISO 27001 Certification in Under 30 Days Using Its Own Continuous Controls Monitoring Platform

Posted in Commentary with tags on June 11, 2026 by itnerd

RegScale today announced it has achieved ISO 27001 certification in under 30 days using its own Continuous Controls Monitoring (CCM) platform. For most organizations pursuing certification through manual processes, the journey runs around six months. RegScale’s result demonstrates what becomes possible when compliance runs continuously: certification is a byproduct of the program, not a project of its own.

The ISO/IEC 27001 certification was conducted by leading compliance assessor A-LIGN, a technology-enabled security and compliance partner trusted by more than 4,000 global organizations to help mitigate cybersecurity risks.

RegScale completed certification with zero major nonconformities and 123 fully implemented controls, managing its entire Information Security Management System within the platform. With RegScale having FedRAMP High authorization, the team reused existing control infrastructure and leveraged AI to write implementation statements directly from policy documentation, building all evidence artifacts in under two weeks. Total audit interview time across both Stage 1 and Stage 2 sessions was under 8 hours, roughly a third of what a typical ISO assessment requires.

Housing the entire ISMS in RegScale, including Change Management and Risk Management, also made it straightforward to present the full program to the auditors. Rather than assembling evidence from disparate sources on demand, the team demonstrated CCM in real time, directly within the platform.

The result reflects a broader shift across compliance operations. RegScale’s second annual State of CCM Report found that 83% of organizations report moderate or major delays due to manual compliance processes, while 58% spend more than 2,000 person-hours annually on evidence collection alone.

RegScale enables organizations to replace static audit preparation with always-on compliance readiness, where the work that achieves certification is the same work that maintains it through every surveillance audit that follows.

Today, RegScale also announces the latest OSCAL Hub innovations that further simplify the transition to continuous compliance management, making machine-readable formats easier to generate, validate, and operationalize across highly regulated environments. The latest OSCAL Hub release introduces new data-sharing capabilities for OSCAL artifacts, making the OSCAL Hub a leading distribution center for compliance-as-code. The Hub also introduces AI-powered OSCAL generation, visual document builders, and automated reconciliation capabilities that eliminate the manual bottlenecks slowing security and compliance teams.

To learn more about RegScale or schedule a demonstration, visit RegScale.

RegScale Emerges as Category Leader in AI-Driven Continuous Controls Monitoring

Posted in Commentary with tags on May 14, 2026 by itnerd

RegScale today announced record growth and market-defining momentum as enterprises and government agencies accelerate their shift away from manual, audit-driven GRC toward real-time, automated assurance.  

The company reported 300% revenue growth and 140% net revenue retention, powered by an oversubscribed $30+ million Series B led by Washington Harbour Partners with participation from M12 (Microsoft’s Venture Fund), Hitachi, Ankona, SYN Ventures, and others, bringing total funding to more than $50 million. RegScale customers consistently report achieving compliance certifications 90% faster and cutting audit preparation effort by 60%. 

Platform Leadership: AI Agents, Open Source, and Certification at Scale 

RegScale continued to accelerate its AI product, RegML, deploying purpose-built AI agents that continuously monitor and validate controls, automate evidence collection, analyze risk in real time, and trigger remediation without human intervention. RegScale’s AI leadership was independently validated when it was named 2025 Gartner® Cool Vendors™ with AI-Powered Technologies for Assurance Leaders, recognizing RegScale’s differentiated approach to AI-driven compliance at scale. The platform earned the CSA STAR “Valid-AI-ted” designation with a 97.7% score, and RegScale’s security credential portfolio now includes FedRAMP High Authorization and TX-RAMP.  

RegScale simultaneously launched and donated the OSCAL Hub to the open-source community, continuing to contribute to machine-readable compliance standards now being adopted across government and commercial sectors. 

Market Expansion: Enterprise, Federal, and Channel 

RegScale also moved into a new tier of Fortune 500 and large federal enterprise accounts. The GTM team expanded into new territories in North America and across Europe and deepened channel investment through a strategic partnership with Leidos. Channel momentum was further reinforced through the company’s partner ecosystem, anchored by relationships with GuidePoint, CALIBRE, Microsoft, and Carahsoft, among others. 

Leadership, Recognition, and the Road Ahead 

RegScale strengthened its leadership team this fiscal year, appointing Chad Woolf as Chief Product Officer to lead the company’s compliance and risk modernization agenda, alongside new product and go-to-market leaders across the organization. The company has grown by more than 30% in employee count and is proactively scaling its team to meet market demand. 

Industry recognition for RegScale’s category leadership reached new heights in FY26. Travis Howerton was named a Finalist in the prestigious 2026 EY Entrepreneur Of The Year Mid-Atlantic Awards and the company was named a CCM winner of numerous cybersecurity awards, solidifying its leadership in cyber GRC and CCM.  

Gartner projects that by 2028, 75% of all DevOps continuous compliance automation processes will leverage AI technology to drive efficiencies in auditing, reporting, validating, and remediating regulatory compliance. RegScale’s customers are not waiting for 2028. With AI agents already in production across Fortune 500 and federal environments, RegScale is the platform delivering on that future today.  

In FY27, the company will accelerate investment in DevSecOps, next-generation RegML agents, and real-time alignment with emerging frameworks like FedRAMP 20x and CMMC. With OSCAL adoption accelerating across government and financial services, RegScale is moving compliance from a business tax or revenue blocker to a continuous, intelligent layer of modern risk management for the CISO.  

2026 State of CCM Report: Resource Constraints Drive 85% of Organizations to Rethink Traditional GRC Approaches

Posted in Commentary with tags on January 20, 2026 by itnerd

RegScale today announced its second annual State of Continuous Controls Monitoring (CCM) Report, building on last year’s landmark study with expanded insights into how organizations are adapting to rising regulatory pressure and increasing security demands.

This year’s data shows that 83% of organizations report moderate or major delays caused by manual compliance work, with 53% dedicating the equivalent of one full-time employeeexclusively to evidence collection — just one of dozens of manual GRC workflows. As security and risk frameworks multiply and regulatory expectations accelerate, teams are facing the highest operational stress levels recorded to date.

Key Findings from the 2026 Report

  • 85% of organizations report delaying or eliminating legacy GRC activities due to resource constraints.
  • 44% have postponed control testing and monitoring, while 33% have postponed policy updates and governance reviews with 25% citing a lack of skilled employees as a major barrier.

AI Adoption Rising, Yet Full Automation Remains Rare:

  • 95% of organizations have implemented some level of automation in GRC.
  • Only 4% have achieved full end-to-end automation.
  • Only 28% monitor their security controls continuously in real- time, while 72% still rely on periodic assessments.
  • 64% report significant or transformational improvement from AI adoption.

The 2026 report underscores a pivotal trend: real-time compliance and security are becoming indistinguishable requirements. Organizations that rely on manual evidence collection, fragmented data, and periodic control checks face increased exposure and higher operational costs, particularly as AI-driven threats accelerate.

Beyond workforce strain and automation maturity, the report examines board-level reporting and metrics, industry-specific compliance challenges, regulatory complexity, and how organizations are evolving governance models to support continuous assurance. Together, these insights provide a broader view of how compliance programs are being reshaped to meet rising expectations from regulators, executives, and businesses.

To explore the full findings of the 2026 State of Continuous Controls Monitoring Report, please download the full report or attend the exclusive webinar on January 27, 2026, where industry experts will share actionable guidance on strengthening compliance operations, improving automation maturity, and building a more resilient security posture.

Methodology:

The 2026 State of Continuous Controls Monitoring Report is based on a survey conducted in September and October 2025 among 253 InfoSec leaders, including CISOs, CIOs, Chief Risk Officers, and VPs and Directors of Security. Respondents were surveyed from organizations with more than 1,000 employees and across a range of industries, including financial services, healthcare, tech, retail, government, business services, manufacturing, and more.

RegScale Donates Open-Source OSCAL Hub to the OSCAL Foundation

Posted in Commentary with tags on December 16, 2025 by itnerd

 RegScale, the leader in Continuous Controls Monitoring (CCM), today launched the OSCAL Hub, an open-source industry platform that will help accelerate the approval of security authorizations (Authority to Operate (ATO) for government regulators, federal agencies, cloud service providers, and other organizations using the Open Security Controls Assessment Language (OSCAL) standardized framework for information systems. The OSCAL Hub was unveiled this week at OSCAL Plugfest, a hands-on event bringing together OSCAL practitioners, industry, regulators, and the broader community to collaborate on real-world technical challenges and workstreams.  

Federal agencies and contractors spend thousands of hours on manual compliance work. As cyber threats to national security escalate in speed and sophistication, the need to automate cybersecurity risk management has become a priority across the public and private sectors to speed innovative technology solutions into production to support government missions and citizen services.  

To meet this mission need, the OSCAL Hub was created as a free, open-source, and comprehensive platform for security compliance teams working with OSCAL documents. It enables government regulators and any Authorizing Officials to review and approve packages, and industry technology providers to submit their Risk Management Framework (RMF) documents in an OSCAL format—resulting in up to 85 percent time savings, due to machine-readable artifacts that can be reviewed and audited with automated approaches. 

RegScale also announced today that it is donating the OSCAL Hub source code as both free and open source to the OSCAL Foundation to advance the use of the application in the community, across both commercial and federal applications.  

The OSCAL Hub features templates and visual tools and can be run as a modern web application for supporting simple, rapid, and robust authorization processes and content sharing.  It can be deployed to Google Cloud, Azure, AWS, locally, or even as a command line tool inside of customer data pipelines. The OSCAL Hub allows: 

  • Federal Agencies to maintain RMF packages and their associated ATOs 
  • Technology vendors to share component definitions for easy ingestion into their OSCAL tooling 
  • Regulators to publish and share OSCAL catalogs and profiles that can serve as a foundation for modern GRC tooling 
  • Security Engineers to validate OSCAL in CI/CD pipelines, convert between formats automatically, and integrate into workflows via REST APIs 
  • AOs to review validated packages and track conditions of approval and Plans of Action and Milestones (POAMs) over time 

Learn more about the OSCAL Hub here or access the Hub in this link.  

RegScale Raises $30+ Million to Redefine Cyber GRC for Highly Regulated Industries

Posted in Commentary with tags on September 17, 2025 by itnerd

RegScale, the leader in Continuous Controls Monitoring (CCM), today announced it has raised $30+ million in an oversubscribed Series B round led by Washington Harbour Partners, with additional investment from new investors M12, Microsoft’s Venture Fund, Hitachi Ventures, and Ankona Capital, as well as continued participation from existing investors SYN Ventures and SineWave Ventures. This raise confirms what customers and investors already know: RegScale isn’t building the next wave of cyber GRC, it’s redefining it, turning compliance from a burdensome, manual checklist process into a real-time and automated platform for the most heavily regulated industries.

The new capital will accelerate RegScale’s leadership in the $50+ billion GRC market and fuel key hires across R&D and sales, enabling the company to deliver increased impact to its growing customer base. It will accelerate RegScale’s RegML, industry-leading AI roadmap, expanding the only CCM platform with AI agents purpose-built to continuously monitor compliance, automate evidence collection/reviews, conduct audits, and analyze risk — capabilities no other provider delivers securely at scale. “RegScale’s AI-powered compliance-as-code approach delivers what today’s operators need most: faster certifications, lower costs, and a stronger security posture. This is the future of cyber GRC, and we’re excited to support RegScale as they scale to meet the growing demand,” said Todd Graham, Managing Partner at M12, Microsoft’s Venture Fund.

With this funding, RegScale is not only strengthening its value for government agencies, financial services, and high-tech organizations but also accelerating expansion into energy, utilities, and other highly regulated sectors where continuous compliance and security assurance are most urgent.

With cyberattacks escalating, nation-states and criminal groups exploiting compliance gaps, and budget cuts pushing for cost takeout and tool consolidation across all industries, CISOs can no longer rely on traditional GRC and manual labor approaches to just check a box. They need CCM to operationalize their risk program and deliver real-time control assurance against a growing set of cybersecurity threats.

RegScale is leading this revolutionary change in managing cyber GRC. Customers report 60% faster audit prep, 3–4x faster FedRAMP High authorizations, and up to 80% greater accuracy, with AI and automation delivering up to 10x staff efficiency. RegScale continues to promote industry standards, serving as the lead affiliate for the Cyber Risk Institute’s (CRI) OSCAL initiative, as a founding member of the OSCAL Foundation, a participant in the Cloud Security Alliance (CSA) Compliance Automation Revolution, and a contributor to the FedRAMP 20x initiative. Its impact has been recognized across the industry, most recently being named Best Compliance Solution by SC Media and as an industry leader by Gartner.

As proof of its platform’s maturity, RegScale achieved FedRAMP High Authorization sponsored by the DHS in half the cost and in just six months, versus the typical 18–24 months. Inside the company, the team is driving incredible growth: ARR has tripled year-over-year, key enterprise and federal customers are on board, and the team has expanded with major additions, including Devon Goforth as CTO, Rich Shirley as VP of Strategic Partnerships, Mike Kimball and Meghan Shafer as VPs of sales, Jennifer Stafford as GM of Federal, and strategic advisors Roland Cloutier and Alex Tosheff.

RegScale is a continuous controls monitoring (CCM) platform that is designed to be the operational risk tool for the CISO. Built on a compliance as code foundation, RegScale enables extreme automation with our API first strategy, self-updating paperwork, and powerful AI agents that all but eliminate manual labor, turn your program more proactive, save money, accelerate time to market, and reduce risk in your operational environment. Heavily regulated organizations, including Fortune 500 enterprises and the Federal government, use RegScale and report achieving compliance certifications 90% faster and trimming audit preparation efforts by 60%, thereby strengthening security and reducing costs. Learn more at http://www.regscale.com.