Schellman’s cover photo
Schellman

Schellman

Professional Services

Tampa, FL 17,771 followers

Helping clients untangle complex compliance objectives. Schellman is the #1 FedRAMP 3PAO in the US Federal Marketplace.

About us

Schellman is a leading provider of attestation and compliance services. We are a globally licensed PCI Qualified Security Assessor, an ISO Certification Body, HITRUST CSF Assessor, and a FedRAMP 3PAO. Renowned for expertise tempered by practical experience, Schellman's professionals provide superior client service balanced by steadfast independence. Our approach builds successful, long-term relationships and allows our clients to achieve multiple compliance objectives through a single project team.

Website
http://www.schellman.com
Industry
Professional Services
Company size
501-1,000 employees
Headquarters
Tampa, FL
Type
Privately Held
Founded
2002
Specialties
SOC 1 Examinations, SOC 2 and 3 Examinations, ISO 27001 Certifications, 3PAO Security Assessment (FedRAMP), PCI DSS Validations, HITRUST Certification, Penetration / Vulnerability Assessments, Privacy (GDPR, State Laws, HIPAA), CMMC, Digital Trust, and B Corp Certified

Employees at Schellman

View 537 employees at Schellman

or

By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.

See all employees

Locations

Updates

  • Responsible AI has quickly become a business imperative, but there's still no universal definition of what it looks like in practice. Schellman is excited to be a part of the proposed panel “The Responsible AI Reality Check” for SXSW 2027. The panel would bring together leaders from OneTrust, Treefera, Safe Security, and our very own Danny Manimbo to discuss how organizations can move beyond high-level principles and build AI governance programs grounded in privacy, transparency, sustainability, and accountability. If you'd like to see this conversation at SXSW, follow the link below or search for "The Responsible AI Reality Check" or "Schellman" in the SXSW PanelPicker and click the ❤️. Voting is open through August 23: https://lnkd.in/gQxPcDGz  

  • 70% of the Fortune 500 use Cursor. Their AI agents read code, run commands, and open pull requests, often with access to systems companies care most about protecting. That's why Cursor pursued AIUC-1 certification, and we're proud to have audited the organization behind it. Our team validated Cursor's AI governance practices: data retention, Privacy Mode enforcement, and vendor governance. AIUC-1's evaluators then tested the live product across thousands of adversarial scenarios covering secrets protection, secure code generation, and resistance to malicious instructions. The distinction matters: a policy that says an agent won't run destructive commands isn't proof. Someone has to try to talk it into running one anyway. Cursor's guardrails held. Congratulations to the Cursor team! #AI #AIGovernance #AIUC1 #AgenticAI #Cybersecurity

  • Congratulations to Konami Gaming, Inc. on achieving ISO 27001 certification, now covering both SYNKROS and Konami Online Interactive. Their "compliance before commerce" approach reflects the kind of security discipline that protects casino operators and players alike. Proud to have supported this milestone. #ISO27001 #InformationSecurity #Gaming

  • FedRAMP's new certification model is changing the path to authorization for cloud service providers. Jonathan Coffelt, Director of Federal Practice at Schellman, explains how the new Class A through D structure replaces the legacy Low, Moderate, and High impact levels, while FedRAMP Ready is being retired in favor of Class A. For some CSPs with an existing SOC 2, GovRAMP, or other NIST SP 800-53 Rev. 5-aligned assessment, the new framework may offer a faster path into the FedRAMP Marketplace. The new certification classes make it more important than ever to understand where your offering fits within the FedRAMP authorization process.

  • Black Hat 2026 was a reminder that the conversation around trust is changing as quickly as AI itself. Throughout the week, Schellman was proud to contribute to that conversation.  CEO Avani D. joined industry leaders to explore how agentic AI is reshaping trust, why traditional frameworks like SOC 2 are no longer enough on their own, and what the future of AI assurance may require. The discussion highlighted the growing need for continuous trust and security validation as organizations adopt increasingly autonomous technologies. We also had the opportunity to bring the community together at Black Hat After Dark alongside BLACKCLOAK, Securin Inc., Chainguard, Straiker, and OX Security, creating space for meaningful conversations beyond the conference floor. Thank you to everyone who joined us, shared insights, and made the week such a valuable exchange of ideas 🤝 

    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
    • No alternative text description for this image
  • AI governance doesn't have to start from scratch. Organizations with an existing ISO/IEC 42001 program may already have much of the foundation needed for AIUC-1 certification. On August 12 at 1:00 PM MST, risk3sixty and Schellman's Joe Sigman will compare AIUC-1 and ISO 42001, highlighting where the frameworks overlap, where AIUC-1 introduces additional agent-specific requirements, and how organizations can build on existing governance work rather than starting over. Learn how to identify reusable controls and evidence, address agent-specific testing and monitoring requirements, and prepare for certification with confidence. Register here: https://lnkd.in/gW4wGzHH 

    • No alternative text description for this image
  • What if scaling CMMC isn't about scaling assessors, but scaling architecture? Following the DoW's suspension of CMMC Phase II and its review of small business impact, our latest blog looks at how the payments industry solved a nearly identical problem. PCI DSS didn't become affordable for small merchants by lowering the security bar. It became affordable by shrinking what had to be assessed, letting outsourced processors absorb complexity through validated infrastructure. The parallel for CMMC: turnkey, pre-validated environments and reliance models that let small contractors trust an ESP's validation the way merchants trust their payment processor's. Read the full analysis: https://lnkd.in/e53VZWNp #CMMC #DefenseIndustrial #Compliance #NISTSP800171 #PCI

    • No alternative text description for this image
  • FedRAMP 20X has been finalized, and now the real planning begins. For organizations pursuing or maintaining FedRAMP authorization, understanding what the new framework means for authorization timelines and how to sequence the work is critical. Join Schellman's Nick Rundhaug alongside SecureIT's Corey Clements and Timothy Sandage on August 5 at 2:00 PM ET as they discuss how FedRAMP 20X changes authorization planning, the biggest variables impacting timelines, where organizations commonly lose time, and how to build a strategy for success under the finalized framework. Register for the LinkedIn Live event here: https://hubs.ly/Q04qngzn0 

    • No alternative text description for this image
  • Proud to have supported Harvey across both their ISO 42001 and AIUC-1 certifications. Having worked closely with their team through both processes, the commitment they bring to security and governance is exceptional. Congratulations on a well-earned milestone!

    Legal AI just got its first certified agents. Today Harvey became the first legal AI company to achieve AIUC-1, the certification for AI agent security, safety, and reliability. To earn it, Harvey's agentic platform was independently evaluated against 86 risk categories through more than 3,000 unique tests spanning hallucination, tool misuse, data leakage, and adversarial manipulation. And it doesn't stop there: testing re-runs at least quarterly. Thank you to our trust, security, and product teams who supported the evaluations, and to Rajiv Dattani and the AIUC-1 team for setting the bar for AI agents. Learn more about why this matters in our blog here: https://lnkd.in/gHQC-CtQ and in my conversation with Rajiv below.

Similar pages

Browse jobs