You are correct. DISA offers SCAP analysis which you can download and plug into BSA and immediately run against your servers. But the results aren't captured on the BDSSA side and, if I'm not mistaken, you have to export the results per individual server in an XML format. You can't get an overall environment results report. And you don't get remediation.
In order to get the reports in BDSSA and have selective remediation you need to create your own STIG compliance within BSA with Component Templates and BLPackages.
I recently did this but for Windows 2008 R2 servers, not RHEL. This is obviously time consuming. One of our architects wrote some code that at least created the framework for me (automatically created all the Rules with a default rule based on the DISA STIG text) and I went back in and modified the rules and created remediation packages as I went along.
If you go this route I can see if I can make that content available for public use.
The SCAP standard does not have a reporting spec - that said i believe it's something we are looking at. SCAP also does not provide a remediation spec either, which is why you cannot remediate w/ scap.
we are working on providing updates to the ct-based stig checks, though i don't have an eta on that. for now the best bet would be updating the existing templates w/ the most recent stig changes.