Schellman’s cover photo
Schellman

Schellman

Professional Services

Tampa, FL 17,495 followers

Helping clients untangle complex compliance objectives. Schellman is the #1 FedRAMP 3PAO in the US Federal Marketplace.

About us

Schellman is a leading provider of attestation and compliance services. We are a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, and a FedRAMP 3PAO. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single project team.

Website
http://www.schellman.com
Industry
Professional Services
Company size
501-1,000 employees
Headquarters
Tampa, FL
Type
Privately Held
Founded
2002
Specialties
SOC 1 Examinations, SOC 2 and 3 Examinations, ISO 27001 Certifications, 3PAO Security Assessment (FedRAMP), PCI DSS Validations, HITRUST Certification, Penetration / Vulnerability Assessments, Privacy (GDPR, State Laws, HIPAA), CMMC, Digital Trust, and B Corp Certified

Locations

Employees at Schellman

Updates

  • If you're attending the GovForward FedRAMP Summit tomorrow, be sure to catch Schellman's Matt Hungate at 2:15 PM ET as he presents "Scaling FedRAMP: Reaching 4,500 Products Through Industry and Government Collaboration." Scaling the FedRAMP marketplace to meet growing demand for secure cloud solutions will require deeper collaboration between government and industry.  Matt's session will explore how FedRAMP 20x initiatives, including automation, authorization reuse, and machine-readable validation, can reduce friction in the authorization process while helping agencies accelerate the adoption of secure cloud solutions. As a proud sponsor of this year's summit, we're looking forward to connecting with attendees throughout the day. Register here: https://lnkd.in/g2ZKVRty 

    • No alternative text description for this image
  • Let's keep the conversations going after the GovForward FedRAMP Summit 🤝 Join Schellman, Second Front, and Salesforce Ventures on July 23 from 4:30 to 6:30 p.m. at Boqueria Penn Quarter for an evening of networking with the national security and defense tech community. No panels. No pitches. Just great food and the opportunity to connect with industry peers, exchange ideas, and build new relationships. Register here: https://lnkd.in/g8ru6-fM

    • No alternative text description for this image
  • What does assessment readiness actually look like for organizations pursuing both CMMC Level 2 certification and FedRAMP authorization?    On July 22 at 1:00 PM ET, hear from Schellman's Timothy Walsh, Jonathan Coffelt, alongside Chainguard’s John Osborne, as they discuss what assessors look for, common readiness gaps, and how software supply chain security and container hardening can help support both frameworks.    Register for the event here: https://lnkd.in/eX5VRvYX 

    • No alternative text description for this image
  • ISO/IEC 42001 follows a familiar management system framework, but one requirement sets it apart.    Before implementing an Artificial Intelligence Management System (AIMS), organizations must formally define their role in relation to the AI systems within scope. That distinction shapes everything from your responsibilities and documentation to the controls you implement and what auditors expect to see.    Learn more about role awareness, Annex A's 38 controls, and key certification considerations in our recent blog: https://lnkd.in/gAkbN6AN  

    • No alternative text description for this image
  • CMMC Phase II has been suspended, but don't mistake the pause for a change in your cybersecurity obligations. While DoW has paused the requirement for third-party CMMC Level 2 certification assessments pending a 60-day review, NIST SP 800-171 and DFARS 252.204-7012 requirements remain in effect. Prime contractors may also continue to enforce their own cybersecurity expectations. Whether you've already achieved certification or are evaluating your next steps, now is the time to reassess your compliance roadmap, not put it on hold. Read our latest blog to understand what this means for your organization and how to prepare for what's next: https://hubs.ly/Q04pvpQf0

    • No alternative text description for this image
  • AI regulations will continue to evolve, but effective governance shouldn’t depend on keeping up with every new requirement.    Tomorrow at 2:30 PM ET, Tristan Ingold, Schellman's Danny Manimbo, and Buchalter's Daniel Pietragallo (AIGP, CIPP/US, FIP) will discuss what it takes to build AI governance programs that can adapt to changing regulations.    The conversation will cover the U.S. regulatory landscape, lessons from enterprise AI governance, and how ISO 42001 can help organizations establish a flexible governance foundation.    Register here to join: https://hubs.ly/Q04ng-Ls0 

    • No alternative text description for this image
  • This Disability Pride Month, we celebrate the unique perspectives, experiences, and strengths that make our workplace stronger.    At Schellman, we're proud to celebrate the people and perspectives that make our culture stronger every day. 

  • The conversation around the EU AI Act is quickly shifting from understanding the regulation to demonstrating compliance.    That's where emerging frameworks like prEN 18286 come in. Designed to support EU AI Act governance, the draft standard complements ISO 42001 by providing a structured, auditable approach to AI risk management, accountability, and documentation.    Learn how these two frameworks work together to help organizations build AI governance programs that are ready for evolving regulatory expectations in our blog: https://hubs.ly/Q04dXpjj0 

    • No alternative text description for this image

Similar pages

Browse jobs