Schellman & Company
Schellman & Company is a Top 50 CPA firm and global certification body focused exclusively on IT compliance and cybersecurity attestation. It serves highly regulated enterprises and government clients with SOC, ISO, FedRAMP, PCI, HITRUST, and AI governance assessments across nearly 60 service lines.
- Company typePrivate
- Founded2002
- HeadquartersTampa, United States
- Headcount501–1,000
- GTM typeB2B
- OfferingServices
What Schellman & Company does
Schellman & Company, LLC is a Tampa, Florida-based licensed CPA firm and global certification body focused exclusively on IT compliance and cybersecurity attestation. Founded in 2002, the firm offers nearly 60 distinct audit and assessment types spanning SOC examinations (issuing more than 2,000 SOC reports annually), ISO management system certifications (including ISO 27001, ISO 42001, ISO 27701, ISO 9001, and others), FedRAMP 3PAO and CMMC C3PAO federal assessments, PCI DSS validation, HITRUST CSF certification, HIPAA/HITECH assessments, GDPR and US state privacy assessments, penetration testing including AI Red Teaming, and emerging digital trust and crypto audit services. Schellman holds the #1 FedRAMP 3PAO position with 200+ assessed offerings and was the first ANAB-accredited ISO 42001 certification body and the first authorized AIUC-1 auditor globally. The firm is privately held, majority-owned by Goldman Sachs Alternatives since March 2026 (with Lightyear Capital as minority investor since 2021), and serves highly regulated enterprise and government clients including OpenAI, Meta, Oracle, Walmart, VMware, Box, Workday, UiPath, Iron Mountain, and federal agencies. Revenue is generated through professional services engagements structured as multi-year contracts with recurring annual re-certifications, priced individually based on assessment scope, complexity, and framework; distribution is entirely direct enterprise sales with a consultative, practice-leader-led motion and a content-driven thought leadership engine supporting inbound demand. The firm expanded through strategic acquisitions (Perry in 2022; INSYTE CPAs, Sustas, and Connor Consulting TPRM in 2024) and operates an internal AuditSource platform for engagement management.
Schellman & Company firmographics
Firmographics- Name
- Schellman & Company
- Legal name
- Schellman & Company, LLC
- Website
- https://schellman.com
- Company type
- Private
- Founded year
- 2002
- Operating status
- Operating
- Headcount range
- 501–1,000 employees
- Short description
- Schellman & Company is a Top 50 CPA firm and global certification body focused exclusively on IT compliance and cybersecurity attestation. It serves highly regulated enterprises and government clients with SOC, ISO, FedRAMP, PCI, HITRUST, and AI governance assessments across nearly 60 service lines.
- Ownership category
- akta.pro rank
Schellman & Company industry classification
Industry- Product category
- Cybersecurity Compliance & Attestation Services
- NAICS
- Offices of Certified Public Accountants (541211), Professional, Scientific, and Technical Services (541)
- SIC
- Services-Services, Nec (8900)
- akta.pro primary industry
- Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
- akta.pro secondary industries
- POS Certification, Testing & Compliance (EMVCo, PCI PTS/PCI DSS) (FSAMADAL), Proof of Reserves, Attestations & On-Chain Audit/Assurance (FSADALAK)
Keywords
Where Schellman & Company is headquartered
LocationHeadquarters
- HQ city
- Tampa
- HQ country
- United States
- HQ region
- North America
Offices2 records
Markets served
Schellman & Company business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Revenue model
- Compliance and Attestation Assessment Services: Professional services revenue generated from conducting compliance assessments, audits, and certifications. Services include SOC examinations, ISO certifications, FedRAMP assessments, PCI DSS validation, HITRUST certification, and AI governance assessments. Revenue is project-based with recurring client relationships as organizations need annual or periodic re-certifications.
- Training Services: World-class training and certification services delivered directly to cybersecurity professionals.
Pricing tiers
| Model | Billing | Price |
|---|---|---|
| Other | Multi-year contract | Custom enterprise engagement pricing based on assessment scope and complexity |
Go-to-market motion1 record
Distribution channels1 record
Marketing channels5 records
Schellman & Company product offering
Product offeringCore offering
Schellman & Company provides independent IT compliance, cybersecurity, and attestation assessment services, operating simultaneously as a licensed CPA firm and globally accredited certification body. The firm delivers nearly 60 types of audits and assessments, including SOC 1/2/3 examinations, ISO 27001/42001/27701/9001/22301/20000-1/14001/45001/50001 certifications, FedRAMP 3PAO and CMMC C3PAO federal assessments, PCI DSS validation, HITRUST CSF certification, penetration testing, AI Red Teaming, AI governance (ISO 42001, AIUC-1), privacy assessments (GDPR, CCPA), cryptocurrency/digital trust audits, and sustainability assurance.
Product overview
Schellman & Company is the only Top 50 CPA firm focused exclusively on IT Compliance and Cybersecurity, offering nearly 60 types of audits and assessments. The firm operates as both a CPA firm and a globally licensed certification body, providing a unified compliance portfolio through a single assessor model. Their core offerings include SOC & Attestations (SOC 1, SOC 2, SOC 3), Payment Card Assessments (PCI DSS), ISO Certifications (including ISO 42001 for AI governance), Privacy Assessments (GDPR, CCPA), Federal Assessments (FedRAMP, CMMC), Healthcare Assessments (HITRUST, HIPAA), Penetration Testing (including AI Red Teaming), Cybersecurity Assessments, Crypto and Digital Trust services, AI Governance, Training, and Sustainability Services. The firm expanded through strategic acquisitions including INSYTE CPAs, Perry (crypto/digital trust), Connor Consulting's TPRM practice, and Sustas (sustainability). Schellman leverages its AuditSource platform for service delivery.
Differentiator
Problem solved
Functional benefit
Brands
- Schellman Compliance: Provides non-attest cybersecurity and compliance professional services under the Schellman brand. Not a licensed CPA firm.
Products and services
- SOC & Attestations Independent SOC 1, SOC 2, SOC 3, SOC for Supply Chain, SOC for Cybersecurity, SOC Essentials, C5, and CSA STAR examinations and attestations providing trust and confidence in service organization controls for service organizations and their customers.
- Payment Card Assessments
Quantifiable outcome
- Issues over 2,000 SOC reports annually
- +3 more outcomes
Companies that use Schellman & Company
Customer profileNamed customers12 records
Segments7 records
Ideal customer profiles4 records
Schellman & Company technology and API
TechnologyTechnology focussed No
API detail
- Has API
- Yes
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability4 records
Feature4 records
Schellman & Company partnerships and signals
Strategic signalScale indicators5 records
Recent moves7 records
Expansion highlights6 records
Schellman & Company competitors and assessment
Company assessmentRegional players
- AssuranceLab: AssuranceLab is a CPA-led compliance firm specializing in SOC 2, ISO 27001, and other IT audits primarily for the Australian and APAC markets. Operates the same multi-framework assessment model as Schellman but does not overlap significantly in North American territory.
Direct peers
- Linford & Company: Linford & Company is a CPA firm focused on SOC examinations, HITRUST, and PCI DSS assessments for healthcare, financial services, and technology clients. Comparable to Schellman in its narrowly focused CPA compliance posture and similar customer base.
- A-LIGN: A-LIGN is a technology-enabled compliance firm specializing in SOC 2, ISO 27001, PCI DSS, HITRUST, and FedRAMP assessments. Closely comparable to Schellman in its multi-framework single-assessor model and its focus on the regulated enterprise and SaaS market.
- 360 Advanced: 360 Advanced is a cybersecurity compliance firm delivering SOC, ISO, PCI, HITRUST, and penetration testing services. Comparable to Schellman as a mid-sized multi-framework assessor targeting similar regulated SaaS and enterprise clients.
- BARR Advisory: BARR Advisory is a cybersecurity compliance firm delivering SOC, ISO 27001, PCI DSS, HITRUST, and FedRAMP assessments with a similar mid-market and enterprise focus. Headquartered in Kansas City and serves many of the same SaaS and cloud service provider clients as Schellman.
- Coalfire: Coalfire is a leading cybersecurity advisory and assessment firm providing FedRAMP, PCI DSS, HITRUST, and ISO certifications. Directly competes with Schellman across federal compliance, payment card, and healthcare attestation engagements for the same enterprise and cloud service provider clients.
- KirkpatrickPrice: KirkpatrickPrice is a CPA-led compliance firm providing SOC, ISO, PCI, HITRUST, and penetration testing services. Operates a similar multi-framework attestation model with comparable customer profiles in regulated industries.
Broad incumbents
- Deloitte: Deloitte is one of the Big Four and operates a large Risk & Compliance Advisory practice covering SOC, ISO, FedRAMP (via subsidiary), HITRUST, and cyber assessments. Overlaps with Schellman across enterprise compliance work but as part of a vastly broader services portfolio and not specialized to IT compliance alone.
- KPMG: KPMG is a Big Four professional services firm with a dedicated cyber and IT compliance practice offering SOC, ISO, FedRAMP, and cyber risk assessments. Comparable to Schellman in IT attestation but as part of a diversified audit, tax, and advisory portfolio rather than a focused compliance specialist.
- EY (Ernst & Young): EY is a Big Four accounting firm with a sizable cybersecurity and IT compliance practice performing SOC, ISO, PCI, and FedRAMP assessments. Competes with Schellman in enterprise IT attestation engagements but as a full-service professional services firm rather than a specialized compliance assessor.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks6 records
Key highlights7 records
Customer concentration
Schellman & Company social profiles
Digital presenceSchellman & Company compliance and trust
Trust signalCompliance32 records
Schellman & Company financial estimates
Financial estimateRevenue estimate
Valuation estimate
Schellman & Company leadership team
Management profileNumber of profiles
Profiles9 records
Schellman & Company subsidiaries and ownership
Company hierarchySubsidiaries3 records
Schellman & Company funding detail
Funding detailFunding overview
Funding rounds2 records
Investors2 records
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Schellman & Company M&A and investment
M&A and investmentM&A2 records
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Schellman & Company
What does Schellman & Company do?
Schellman & Company provides independent IT compliance, cybersecurity, and attestation assessment services, operating simultaneously as a licensed CPA firm and globally accredited certification body. The firm delivers nearly 60 types of audits and assessments, including SOC 1/2/3 examinations, ISO 27001/42001/27701/9001/22301/20000-1/14001/45001/50001 certifications, FedRAMP 3PAO and CMMC C3PAO federal assessments, PCI DSS validation, HITRUST CSF certification, penetration testing, AI Red Teaming, AI governance (ISO 42001, AIUC-1), privacy assessments (GDPR, CCPA), cryptocurrency/digital trust audits, and sustainability assurance.
Is Schellman & Company a public or private company?
Schellman & Company is a private company. It is classified as private equity controlled and is currently operating.
When was Schellman & Company founded?
Schellman & Company was founded in 2002. It employs 501 to 1,000 people.
Where is Schellman & Company based?
Schellman & Company is headquartered in Tampa, United States, in the North America region.
How does Schellman & Company make money?
Two revenue lines are on record. Compliance and Attestation Assessment Services are the primary driver. The others are training Services.
Who are Schellman & Company's main competitors?
AssuranceLab is listed as a regional player. Direct peers are Linford & Company, A-LIGN, 360 Advanced, BARR Advisory, Coalfire and KirkpatrickPrice. Broad incumbents are Deloitte, KPMG and EY (Ernst & Young).
Does Schellman & Company have an API?
Yes. Schellman offers an AuditSource platform with Open API Terms of Use referenced in their privacy policy. The platform appears to provide API-based access for audit and compliance services, though specific API documentation URL, authentication methods, rate limits, and versioning details are not publicly specified in available sources.
What industry is Schellman & Company in?
Schellman & Company's product category is Cybersecurity Compliance & Attestation Services. Its primary akta.pro industry code is BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX), with a secondary code of FSAMADAL, POS Certification, Testing & Compliance (EMVCo, PCI PTS/PCI DSS). Its NAICS code is 541211 and its SIC code is 8900.