Responsible AI has quickly become a business imperative, but there's still no universal definition of what it looks like in practice. Schellman is excited to be a part of the proposed panel “The Responsible AI Reality Check” for SXSW 2027. The panel would bring together leaders from OneTrust, Treefera, Safe Security, and our very own Danny Manimbo to discuss how organizations can move beyond high-level principles and build AI governance programs grounded in privacy, transparency, sustainability, and accountability. If you'd like to see this conversation at SXSW, follow the link below or search for "The Responsible AI Reality Check" or "Schellman" in the SXSW PanelPicker and click the ❤️. Voting is open through August 23: https://lnkd.in/gQxPcDGz
Schellman
Professional Services
Tampa, FL 17,771 followers
Helping clients untangle complex compliance objectives. Schellman is the #1 FedRAMP 3PAO in the US Federal Marketplace.
About us
Schellman is a leading provider of attestation and compliance services. We are a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, and a FedRAMP 3PAO. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single project team.
- Website
-
http://www.schellman.com
External link for Schellman
- Industry
- Professional Services
- Company size
- 501-1,000 employees
- Headquarters
- Tampa, FL
- Type
- Privately Held
- Founded
- 2002
- Specialties
- SOC 1 Examinations, SOC 2 and 3 Examinations, ISO 27001 Certifications, 3PAO Security Assessment (FedRAMP), PCI DSS Validations, HITRUST Certification, Penetration / Vulnerability Assessments, Privacy (GDPR, State Laws, HIPAA), CMMC, Digital Trust, and B Corp Certified
Employees at Schellman
Locations
-
Primary
Get directions
4010 W Boy Scout Blvd., Suite 600
Tampa, FL 33607, US
-
Get directions
4510 Kenny Rd
Columbus, Ohio 43220, US
Updates
-
70% of the Fortune 500 use Cursor. Their AI agents read code, run commands, and open pull requests, often with access to systems companies care most about protecting. That's why Cursor pursued AIUC-1 certification, and we're proud to have audited the organization behind it. Our team validated Cursor's AI governance practices: data retention, Privacy Mode enforcement, and vendor governance. AIUC-1's evaluators then tested the live product across thousands of adversarial scenarios covering secrets protection, secure code generation, and resistance to malicious instructions. The distinction matters: a policy that says an agent won't run destructive commands isn't proof. Someone has to try to talk it into running one anyway. Cursor's guardrails held. Congratulations to the Cursor team! #AI #AIGovernance #AIUC1 #AgenticAI #Cybersecurity
-
Congratulations to Konami Gaming, Inc. on achieving ISO 27001 certification, now covering both SYNKROS and Konami Online Interactive. Their "compliance before commerce" approach reflects the kind of security discipline that protects casino operators and players alike. Proud to have supported this milestone. #ISO27001 #InformationSecurity #Gaming
NEWS RELEASE - "Konami Gaming, Inc. Earns ISO 27001 Certification, to include SYNKROS and Konami Online Interactive": https://lnkd.in/gKtRSmG4 🔐 #igaming #tech Schellman Eduardo Aching
-
-
FedRAMP's new certification model is changing the path to authorization for cloud service providers. Jonathan Coffelt, Director of Federal Practice at Schellman, explains how the new Class A through D structure replaces the legacy Low, Moderate, and High impact levels, while FedRAMP Ready is being retired in favor of Class A. For some CSPs with an existing SOC 2, GovRAMP, or other NIST SP 800-53 Rev. 5-aligned assessment, the new framework may offer a faster path into the FedRAMP Marketplace. The new certification classes make it more important than ever to understand where your offering fits within the FedRAMP authorization process.
-
Black Hat 2026 was a reminder that the conversation around trust is changing as quickly as AI itself. Throughout the week, Schellman was proud to contribute to that conversation. CEO Avani D. joined industry leaders to explore how agentic AI is reshaping trust, why traditional frameworks like SOC 2 are no longer enough on their own, and what the future of AI assurance may require. The discussion highlighted the growing need for continuous trust and security validation as organizations adopt increasingly autonomous technologies. We also had the opportunity to bring the community together at Black Hat After Dark alongside BLACKCLOAK, Securin Inc., Chainguard, Straiker, and OX Security, creating space for meaningful conversations beyond the conference floor. Thank you to everyone who joined us, shared insights, and made the week such a valuable exchange of ideas 🤝
-
-
AI governance doesn't have to start from scratch. Organizations with an existing ISO/IEC 42001 program may already have much of the foundation needed for AIUC-1 certification. On August 12 at 1:00 PM MST, risk3sixty and Schellman's Joe Sigman will compare AIUC-1 and ISO 42001, highlighting where the frameworks overlap, where AIUC-1 introduces additional agent-specific requirements, and how organizations can build on existing governance work rather than starting over. Learn how to identify reusable controls and evidence, address agent-specific testing and monitoring requirements, and prepare for certification with confidence. Register here: https://lnkd.in/gW4wGzHH
-
-
Planning a FedRAMP authorization when the rules just changed is harder than it sounds. On August 5 at 2:00 PM ET, Schellman's Nick Rundhaug is joined by Tim Sandage and Corey Clements from SecureIT to break down exactly what that looks like under 20X.
FedRAMP 20X: What it Actually Means for Your Authorization Timeline
www.linkedin.com
-
What if scaling CMMC isn't about scaling assessors, but scaling architecture? Following the DoW's suspension of CMMC Phase II and its review of small business impact, our latest blog looks at how the payments industry solved a nearly identical problem. PCI DSS didn't become affordable for small merchants by lowering the security bar. It became affordable by shrinking what had to be assessed, letting outsourced processors absorb complexity through validated infrastructure. The parallel for CMMC: turnkey, pre-validated environments and reliance models that let small contractors trust an ESP's validation the way merchants trust their payment processor's. Read the full analysis: https://lnkd.in/e53VZWNp #CMMC #DefenseIndustrial #Compliance #NISTSP800171 #PCI
-
-
FedRAMP 20X has been finalized, and now the real planning begins. For organizations pursuing or maintaining FedRAMP authorization, understanding what the new framework means for authorization timelines and how to sequence the work is critical. Join Schellman's Nick Rundhaug alongside SecureIT's Corey Clements and Timothy Sandage on August 5 at 2:00 PM ET as they discuss how FedRAMP 20X changes authorization planning, the biggest variables impacting timelines, where organizations commonly lose time, and how to build a strategy for success under the finalized framework. Register for the LinkedIn Live event here: https://hubs.ly/Q04qngzn0
-
-
Proud to have supported Harvey across both their ISO 42001 and AIUC-1 certifications. Having worked closely with their team through both processes, the commitment they bring to security and governance is exceptional. Congratulations on a well-earned milestone!
Legal AI just got its first certified agents. Today Harvey became the first legal AI company to achieve AIUC-1, the certification for AI agent security, safety, and reliability. To earn it, Harvey's agentic platform was independently evaluated against 86 risk categories through more than 3,000 unique tests spanning hallucination, tool misuse, data leakage, and adversarial manipulation. And it doesn't stop there: testing re-runs at least quarterly. Thank you to our trust, security, and product teams who supported the evaluations, and to Rajiv Dattani and the AIUC-1 team for setting the bar for AI agents. Learn more about why this matters in our blog here: https://lnkd.in/gHQC-CtQ and in my conversation with Rajiv below.