Soteria Software Press Release

August 17th, 2026

OpenRMF® Professional v2.14.02 Released!

Soteria Software released a patch update to their flagship product OpenRMF® Professional v2.14.02 today. Please log into the Software & Documentation portal under the Resources link on the website and download the upgrade as soon as you can.


This is a patch for adding a few features, fixing performance issues, fixing some software bugs and updating the DISA checklist templates up to July 22, 2026.


  • Added an expiration warning preference for System Packages
  • Added the number of controls for each grouping on the Tailored Controls screen
  • Added a Site Name, Site Key and Site ID (automatically generated) for each installation
  • Added downloading from template history in CKL and CKLB format
  • Added a download of CIS .audit file checklist templates in CKL or CKLB format
  • Added upload of hardware, software, and ports/protocols/services listing in Team Subpackages
  • Added ability to manage evidence to a POAM entry in a Team Subpackage
  • Added ability to track Other Technology Vulnerabilities in a Team Subpackage
  • Added External API Calls
  • Get Application Settings
  • Create/Update a Compliance Statement for a system package
  • Create/Update a Compliance Statement for all SIEM-enabled system packages
  • Pagination calls to replace deprecated calls on listing hardware, software, pps, vulnerabilities, etc. (see Developer’s Guide)
  • Added the Service Provider Interface (SPI) option on Application Settings
  • Added the Elastic AI and Elastic SIEM / Security (Feature release) SPI settings for integration
  • Added a SIEM enable toggle if Elastic SIEM / Security is enabled for the installation
  • Updated the POAM to use Residual Risk everywhere, versus the extra Resulting Residual Risk, including eMASS xlsx Upload
  • Updated performance in several key areas when working with large lists of data for memory, speed, and CPU
  • Updated the New System Package full form, not the wizard, to show links to your new system package right away
  • Updated column headings on tables where there is no sort available
  • Updated the User Permissions listing by system package and permission for better readability
  • Updated Application Settings to show a response saving per section
  • Updated IP Masking for patch vulnerability and checklist / SCAP uploads per the system package preference correctly
  • Fixed a bug in compliance report for // double slashes in the backend call
  • Fixed a bug where Impact from an uploaded eMASS POAM xlsx file was not being updated for that row/device/security check
  • Fixed a bug when doing a “Delete Hardware” that did not remove all checklists from the main checklist listing
  • Fixed a bug when uploading a license that is invalid for dates or size
  • Fixed a bug on duplicate CCI listings on reports when using Tailored controls in your system package
  • Fixed a bug to enable proper pagination on the External API when calling compliance records a group at a time
  • DISA Template updates as of July 22, 2026 from DISA public.cyber.mil
  • Updated libraries for NATS in the frontend and backend application components
  • Updated the base image for our software components with the latest Alpine Linux curated image from RapidFort and DoD certificate authorities
  • Upgraded Hashicorp Vault to v2.0
  • Updated the base MongoDB image to 7.0.37 from RapidFort to fix a known CVE


More information on the software release and its availability as well as training can be found at their website www.soteriasoft.com.