August 17th, 2026
OpenRMF® Professional v2.14.02 Released!
Soteria Software released a patch update to their flagship product OpenRMF® Professional v2.14.02 today. Please log into the Software & Documentation portal under the Resources link on the website and download the upgrade as soon as you can.
This is a patch for adding a few features, fixing performance issues, fixing some software bugs and updating the DISA checklist templates up to July 22, 2026.
- Added an expiration warning preference for System Packages
- Added the number of controls for each grouping on the Tailored Controls screen
- Added a Site Name, Site Key and Site ID (automatically generated) for each installation
- Added downloading from template history in CKL and CKLB format
- Added a download of CIS .audit file checklist templates in CKL or CKLB format
- Added upload of hardware, software, and ports/protocols/services listing in Team Subpackages
- Added ability to manage evidence to a POAM entry in a Team Subpackage
- Added ability to track Other Technology Vulnerabilities in a Team Subpackage
- Added External API Calls
- Get Application Settings
- Create/Update a Compliance Statement for a system package
- Create/Update a Compliance Statement for all SIEM-enabled system packages
- Pagination calls to replace deprecated calls on listing hardware, software, pps, vulnerabilities, etc. (see Developer’s Guide)
- Added the Service Provider Interface (SPI) option on Application Settings
- Added the Elastic AI and Elastic SIEM / Security (Feature release) SPI settings for integration
- Added a SIEM enable toggle if Elastic SIEM / Security is enabled for the installation
- Updated the POAM to use Residual Risk everywhere, versus the extra Resulting Residual Risk, including eMASS xlsx Upload
- Updated performance in several key areas when working with large lists of data for memory, speed, and CPU
- Updated the New System Package full form, not the wizard, to show links to your new system package right away
- Updated column headings on tables where there is no sort available
- Updated the User Permissions listing by system package and permission for better readability
- Updated Application Settings to show a response saving per section
- Updated IP Masking for patch vulnerability and checklist / SCAP uploads per the system package preference correctly
- Fixed a bug in compliance report for // double slashes in the backend call
- Fixed a bug where Impact from an uploaded eMASS POAM xlsx file was not being updated for that row/device/security check
- Fixed a bug when doing a “Delete Hardware” that did not remove all checklists from the main checklist listing
- Fixed a bug when uploading a license that is invalid for dates or size
- Fixed a bug on duplicate CCI listings on reports when using Tailored controls in your system package
- Fixed a bug to enable proper pagination on the External API when calling compliance records a group at a time
- DISA Template updates as of July 22, 2026 from DISA public.cyber.mil
- Updated libraries for NATS in the frontend and backend application components
- Updated the base image for our software components with the latest Alpine Linux curated image from RapidFort and DoD certificate authorities
- Upgraded Hashicorp Vault to v2.0
- Updated the base MongoDB image to 7.0.37 from RapidFort to fix a known CVE
More information on the software release and its availability as well as training can be found at their website www.soteriasoft.com.