Developer docs
API playgroundTry for free, no card

Search company profiles

Schellman & Company

Full company profile

uuid0006efu

Namestring
Schellman & Company
Legal namestring
Schellman & Company, LLC
Websiteurl
schellman.com
Company typeenum
Private
Founded yearint
2002
Descriptiontext

Schellman & Company, LLC is a Tampa, Florida-based licensed CPA firm and global certification body focused exclusively on IT compliance and cybersecurity attestation. Founded in 2002, the firm offers nearly 60 distinct audit and assessment types spanning SOC examinations (issuing more than 2,000 SOC reports annually), ISO management system certifications (including ISO 27001, ISO 42001, ISO 27701, ISO 9001, and others), FedRAMP 3PAO and CMMC C3PAO federal assessments, PCI DSS validation, HITRUST CSF certification, HIPAA/HITECH assessments, GDPR and US state privacy assessments, penetration testing including AI Red Teaming, and emerging digital trust and crypto audit services. Schellman holds the #1 FedRAMP 3PAO position with 200+ assessed offerings and was the first ANAB-accredited ISO 42001 certification body and the first authorized AIUC-1 auditor globally. The firm is privately held, majority-owned by Goldman Sachs Alternatives since March 2026 (with Lightyear Capital as minority investor since 2021), and serves highly regulated enterprise and government clients including OpenAI, Meta, Oracle, Walmart, VMware, Box, Workday, UiPath, Iron Mountain, and federal agencies. Revenue is generated through professional services engagements structured as multi-year contracts with recurring annual re-certifications, priced individually based on assessment scope, complexity, and framework; distribution is entirely direct enterprise sales with a consultative, practice-leader-led motion and a content-driven thought leadership engine supporting inbound demand. The firm expanded through strategic acquisitions (Perry in 2022; INSYTE CPAs, Sustas, and Connor Consulting TPRM in 2024) and operates an internal AuditSource platform for engagement management.

Short descriptiontext

Schellman & Company is a Top 50 CPA firm and global certification body focused exclusively on IT compliance and cybersecurity attestation. It serves highly regulated enterprises and government clients with SOC, ISO, FedRAMP, PCI, HITRUST, and AI governance assessments across nearly 60 service lines.

Operating statusenum
Operating
Ownership categoryenum
Headcount rangeband
501–1,000
akta.pro rankint
HeadquartersTampa, United States
HQ citystring
Tampa
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices2 records

Each record includes

City, Country, Type, Description, Source

Keyword5 values
cybersecurity compliance services, SOC audit examinations, ISO certification body, FedRAMP 3PAO assessments, PCI DSS validation
Industry3 codes
1Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX)
CodeBPAKADACPrimaryYes
2POS Certification, Testing & Compliance (EMVCo, PCI PTS/PCI DSS)
CodeFSAMADALPrimaryNo
3Proof of Reserves, Attestations & On-Chain Audit/Assurance
CodeFSADALAKPrimaryNo
NAICS code2 codes
  • Offices of Certified Public Accountants541211
  • Professional, Scientific, and Technical Services541
SIC code1 code
  • Services-Services, Nec8900
Product category
Cybersecurity Compliance & Attestation Services
GTM motion1 record

Each record includes

Type, Description, Source

Revenue model2 records
1Compliance and Attestation Assessment Services
TypeProfessional Services
Description

Professional services revenue generated from conducting compliance assessments, audits, and certifications. Services include SOC examinations, ISO certifications, FedRAMP assessments, PCI DSS validation, HITRUST certification, and AI governance assessments. Revenue is project-based with recurring client relationships as organizations need annual or periodic re-certifications.

schellman.com
2Training Services
TypeProfessional Services
Description

World-class training and certification services delivered directly to cybersecurity professionals.

schellman.com
Marketing channels5 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels1 record

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Operations, Technology or R&D, Marketing or Sales, Others
Pricing details1 tier
1Custom enterprise engagement pricing based on assessment scope and complexity
ModelOtherBilling cadenceMulti-year contract
Notes

Pricing varies by assessment type (SOC, ISO, FedRAMP, PCI, etc.), organization size, scope of assessment, and complexity of controls environment. engagements are quoted individually based on client requirements.

schellman.com
GTM typeB2B
B2B
Offering typeServices
Services
Brand1 record
1Schellman Compliance
Description

Provides non-attest cybersecurity and compliance professional services under the Schellman brand. Not a licensed CPA firm.

schellman.com
Core offering1 text field

Schellman & Company provides independent IT compliance, cybersecurity, and attestation assessment services, operating simultaneously as a licensed CPA firm and globally accredited certification body. The firm delivers nearly 60 types of audits and assessments, including SOC 1/2/3 examinations, ISO 27001/42001/27701/9001/22301/20000-1/14001/45001/50001 certifications, FedRAMP 3PAO and CMMC C3PAO federal assessments, PCI DSS validation, HITRUST CSF certification, penetration testing, AI Red Teaming, AI governance (ISO 42001, AIUC-1), privacy assessments (GDPR, CCPA), cryptocurrency/digital trust audits, and sustainability assurance.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 4 values shown
  • Issues over 2,000 SOC reports annually
+3 more records
Product overview1 text field

Schellman & Company is the only Top 50 CPA firm focused exclusively on IT Compliance and Cybersecurity, offering nearly 60 types of audits and assessments. The firm operates as both a CPA firm and a globally licensed certification body, providing a unified compliance portfolio through a single assessor model. Their core offerings include SOC & Attestations (SOC 1, SOC 2, SOC 3), Payment Card Assessments (PCI DSS), ISO Certifications (including ISO 42001 for AI governance), Privacy Assessments (GDPR, CCPA), Federal Assessments (FedRAMP, CMMC), Healthcare Assessments (HITRUST, HIPAA), Penetration Testing (including AI Red Teaming), Cybersecurity Assessments, Crypto and Digital Trust services, AI Governance, Training, and Sustainability Services. The firm expanded through strategic acquisitions including INSYTE CPAs, Perry (crypto/digital trust), Connor Consulting's TPRM practice, and Sustas (sustainability). Schellman leverages its AuditSource platform for service delivery.

Product and service2 records
1SOC & Attestations
CategoryAudit & Attestation
Description

Independent SOC 1, SOC 2, SOC 3, SOC for Supply Chain, SOC for Cybersecurity, SOC Essentials, C5, and CSA STAR examinations and attestations providing trust and confidence in service organization controls for service organizations and their customers.

2Payment Card Assessments
Scale indicator5 records

Each record includes

Type, Value, Description, Source

Recent move7 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeRegional player
Description

AssuranceLab is a CPA-led compliance firm specializing in SOC 2, ISO 27001, and other IT audits primarily for the Australian and APAC markets. Operates the same multi-framework assessment model as Schellman but does not overlap significantly in North American territory.

TypeDirect peer
Description

Linford & Company is a CPA firm focused on SOC examinations, HITRUST, and PCI DSS assessments for healthcare, financial services, and technology clients. Comparable to Schellman in its narrowly focused CPA compliance posture and similar customer base.

TypeDirect peer
Description

A-LIGN is a technology-enabled compliance firm specializing in SOC 2, ISO 27001, PCI DSS, HITRUST, and FedRAMP assessments. Closely comparable to Schellman in its multi-framework single-assessor model and its focus on the regulated enterprise and SaaS market.

TypeDirect peer
Description

360 Advanced is a cybersecurity compliance firm delivering SOC, ISO, PCI, HITRUST, and penetration testing services. Comparable to Schellman as a mid-sized multi-framework assessor targeting similar regulated SaaS and enterprise clients.

TypeBroad incumbent
Description

Deloitte is one of the Big Four and operates a large Risk & Compliance Advisory practice covering SOC, ISO, FedRAMP (via subsidiary), HITRUST, and cyber assessments. Overlaps with Schellman across enterprise compliance work but as part of a vastly broader services portfolio and not specialized to IT compliance alone.

TypeDirect peer
Description

BARR Advisory is a cybersecurity compliance firm delivering SOC, ISO 27001, PCI DSS, HITRUST, and FedRAMP assessments with a similar mid-market and enterprise focus. Headquartered in Kansas City and serves many of the same SaaS and cloud service provider clients as Schellman.

TypeDirect peer
Description

Coalfire is a leading cybersecurity advisory and assessment firm providing FedRAMP, PCI DSS, HITRUST, and ISO certifications. Directly competes with Schellman across federal compliance, payment card, and healthcare attestation engagements for the same enterprise and cloud service provider clients.

TypeBroad incumbent
Description

KPMG is a Big Four professional services firm with a dedicated cyber and IT compliance practice offering SOC, ISO, FedRAMP, and cyber risk assessments. Comparable to Schellman in IT attestation but as part of a diversified audit, tax, and advisory portfolio rather than a focused compliance specialist.

TypeDirect peer
Description

KirkpatrickPrice is a CPA-led compliance firm providing SOC, ISO, PCI, HITRUST, and penetration testing services. Operates a similar multi-framework attestation model with comparable customer profiles in regulated industries.

TypeBroad incumbent
Description

EY is a Big Four accounting firm with a sizable cybersecurity and IT compliance practice performing SOC, ISO, PCI, and FedRAMP assessments. Competes with Schellman in enterprise IT attestation engagements but as a full-service professional services firm rather than a specialized compliance assessor.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks6 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers12 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment7 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile4 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
No
API detail
Has APIbool
Yes

Docs URL, Description

AI capability4 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature4 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles9 records

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

Subsidiaries3 records

Each record includes

Name, Acquired on, Relationship type, Type, Business focus

Compliance32 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds2 records

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors2 records

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A2 records

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Schellman & Company

Cybersecurity Compliance & Attestation Servicesschellman.com

Schellman & Company is a Top 50 CPA firm and global certification body focused exclusively on IT compliance and cybersecurity attestation. It serves highly regulated enterprises and government clients with SOC, ISO, FedRAMP, PCI, HITRUST, and AI governance assessments across nearly 60 service lines.

What Schellman & Company does

Schellman & Company, LLC is a Tampa, Florida-based licensed CPA firm and global certification body focused exclusively on IT compliance and cybersecurity attestation. Founded in 2002, the firm offers nearly 60 distinct audit and assessment types spanning SOC examinations (issuing more than 2,000 SOC reports annually), ISO management system certifications (including ISO 27001, ISO 42001, ISO 27701, ISO 9001, and others), FedRAMP 3PAO and CMMC C3PAO federal assessments, PCI DSS validation, HITRUST CSF certification, HIPAA/HITECH assessments, GDPR and US state privacy assessments, penetration testing including AI Red Teaming, and emerging digital trust and crypto audit services. Schellman holds the #1 FedRAMP 3PAO position with 200+ assessed offerings and was the first ANAB-accredited ISO 42001 certification body and the first authorized AIUC-1 auditor globally. The firm is privately held, majority-owned by Goldman Sachs Alternatives since March 2026 (with Lightyear Capital as minority investor since 2021), and serves highly regulated enterprise and government clients including OpenAI, Meta, Oracle, Walmart, VMware, Box, Workday, UiPath, Iron Mountain, and federal agencies. Revenue is generated through professional services engagements structured as multi-year contracts with recurring annual re-certifications, priced individually based on assessment scope, complexity, and framework; distribution is entirely direct enterprise sales with a consultative, practice-leader-led motion and a content-driven thought leadership engine supporting inbound demand. The firm expanded through strategic acquisitions (Perry in 2022; INSYTE CPAs, Sustas, and Connor Consulting TPRM in 2024) and operates an internal AuditSource platform for engagement management.

Schellman & Company firmographics

Firmographics
Name
Schellman & Company
Legal name
Schellman & Company, LLC
Website
https://schellman.com
Company type
Private
Founded year
2002
Operating status
Operating
Headcount range
501–1,000 employees
Short description
Schellman & Company is a Top 50 CPA firm and global certification body focused exclusively on IT compliance and cybersecurity attestation. It serves highly regulated enterprises and government clients with SOC, ISO, FedRAMP, PCI, HITRUST, and AI governance assessments across nearly 60 service lines.
Ownership category
akta.pro rank

Schellman & Company industry classification

Industry
Product category
Cybersecurity Compliance & Attestation Services
NAICS
Offices of Certified Public Accountants (541211), Professional, Scientific, and Technical Services (541)
SIC
Services-Services, Nec (8900)
akta.pro primary industry
Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX) (BPAKADAC)
akta.pro secondary industries
POS Certification, Testing & Compliance (EMVCo, PCI PTS/PCI DSS) (FSAMADAL), Proof of Reserves, Attestations & On-Chain Audit/Assurance (FSADALAK)

Keywords

  • Cybersecurity compliance services
  • SOC audit examinations
  • ISO certification body
  • FedRAMP 3PAO assessments
  • PCI DSS validation

Where Schellman & Company is headquartered

Location

Headquarters

HQ city
Tampa
HQ country
United States
HQ region
North America

Offices2 records

Markets served

Schellman & Company business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Operations, Technology or R&D, Marketing or Sales, Others

Revenue model

  1. Compliance and Attestation Assessment Services: Professional services revenue generated from conducting compliance assessments, audits, and certifications. Services include SOC examinations, ISO certifications, FedRAMP assessments, PCI DSS validation, HITRUST certification, and AI governance assessments. Revenue is project-based with recurring client relationships as organizations need annual or periodic re-certifications.
  2. Training Services: World-class training and certification services delivered directly to cybersecurity professionals.

Pricing tiers

ModelBillingPrice
OtherMulti-year contractCustom enterprise engagement pricing based on assessment scope and complexity

Go-to-market motion1 record

Distribution channels1 record

Marketing channels5 records

Schellman & Company product offering

Product offering

Core offering

Schellman & Company provides independent IT compliance, cybersecurity, and attestation assessment services, operating simultaneously as a licensed CPA firm and globally accredited certification body. The firm delivers nearly 60 types of audits and assessments, including SOC 1/2/3 examinations, ISO 27001/42001/27701/9001/22301/20000-1/14001/45001/50001 certifications, FedRAMP 3PAO and CMMC C3PAO federal assessments, PCI DSS validation, HITRUST CSF certification, penetration testing, AI Red Teaming, AI governance (ISO 42001, AIUC-1), privacy assessments (GDPR, CCPA), cryptocurrency/digital trust audits, and sustainability assurance.

Product overview

Schellman & Company is the only Top 50 CPA firm focused exclusively on IT Compliance and Cybersecurity, offering nearly 60 types of audits and assessments. The firm operates as both a CPA firm and a globally licensed certification body, providing a unified compliance portfolio through a single assessor model. Their core offerings include SOC & Attestations (SOC 1, SOC 2, SOC 3), Payment Card Assessments (PCI DSS), ISO Certifications (including ISO 42001 for AI governance), Privacy Assessments (GDPR, CCPA), Federal Assessments (FedRAMP, CMMC), Healthcare Assessments (HITRUST, HIPAA), Penetration Testing (including AI Red Teaming), Cybersecurity Assessments, Crypto and Digital Trust services, AI Governance, Training, and Sustainability Services. The firm expanded through strategic acquisitions including INSYTE CPAs, Perry (crypto/digital trust), Connor Consulting's TPRM practice, and Sustas (sustainability). Schellman leverages its AuditSource platform for service delivery.

Differentiator

Problem solved

Functional benefit

Brands

  • Schellman Compliance: Provides non-attest cybersecurity and compliance professional services under the Schellman brand. Not a licensed CPA firm.

Products and services

  • SOC & Attestations Independent SOC 1, SOC 2, SOC 3, SOC for Supply Chain, SOC for Cybersecurity, SOC Essentials, C5, and CSA STAR examinations and attestations providing trust and confidence in service organization controls for service organizations and their customers.
  • Payment Card Assessments

Quantifiable outcome

  • Issues over 2,000 SOC reports annually
  • +3 more outcomes

Companies that use Schellman & Company

Customer profile

Named customers12 records

Segments7 records

Ideal customer profiles4 records

Schellman & Company technology and API

Technology

Technology focussed No

API detail

Has API
Yes
API docs
API detail

Core technology

AI maturity

App detail

AI capability4 records

Feature4 records

Schellman & Company partnerships and signals

Strategic signal

Scale indicators5 records

Recent moves7 records

Expansion highlights6 records

Schellman & Company competitors and assessment

Company assessment

Regional players

  • AssuranceLab: AssuranceLab is a CPA-led compliance firm specializing in SOC 2, ISO 27001, and other IT audits primarily for the Australian and APAC markets. Operates the same multi-framework assessment model as Schellman but does not overlap significantly in North American territory.

Direct peers

  • Linford & Company: Linford & Company is a CPA firm focused on SOC examinations, HITRUST, and PCI DSS assessments for healthcare, financial services, and technology clients. Comparable to Schellman in its narrowly focused CPA compliance posture and similar customer base.
  • A-LIGN: A-LIGN is a technology-enabled compliance firm specializing in SOC 2, ISO 27001, PCI DSS, HITRUST, and FedRAMP assessments. Closely comparable to Schellman in its multi-framework single-assessor model and its focus on the regulated enterprise and SaaS market.
  • 360 Advanced: 360 Advanced is a cybersecurity compliance firm delivering SOC, ISO, PCI, HITRUST, and penetration testing services. Comparable to Schellman as a mid-sized multi-framework assessor targeting similar regulated SaaS and enterprise clients.
  • BARR Advisory: BARR Advisory is a cybersecurity compliance firm delivering SOC, ISO 27001, PCI DSS, HITRUST, and FedRAMP assessments with a similar mid-market and enterprise focus. Headquartered in Kansas City and serves many of the same SaaS and cloud service provider clients as Schellman.
  • Coalfire: Coalfire is a leading cybersecurity advisory and assessment firm providing FedRAMP, PCI DSS, HITRUST, and ISO certifications. Directly competes with Schellman across federal compliance, payment card, and healthcare attestation engagements for the same enterprise and cloud service provider clients.
  • KirkpatrickPrice: KirkpatrickPrice is a CPA-led compliance firm providing SOC, ISO, PCI, HITRUST, and penetration testing services. Operates a similar multi-framework attestation model with comparable customer profiles in regulated industries.

Broad incumbents

  • Deloitte: Deloitte is one of the Big Four and operates a large Risk & Compliance Advisory practice covering SOC, ISO, FedRAMP (via subsidiary), HITRUST, and cyber assessments. Overlaps with Schellman across enterprise compliance work but as part of a vastly broader services portfolio and not specialized to IT compliance alone.
  • KPMG: KPMG is a Big Four professional services firm with a dedicated cyber and IT compliance practice offering SOC, ISO, FedRAMP, and cyber risk assessments. Comparable to Schellman in IT attestation but as part of a diversified audit, tax, and advisory portfolio rather than a focused compliance specialist.
  • EY (Ernst & Young): EY is a Big Four accounting firm with a sizable cybersecurity and IT compliance practice performing SOC, ISO, PCI, and FedRAMP assessments. Competes with Schellman in enterprise IT attestation engagements but as a full-service professional services firm rather than a specialized compliance assessor.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks6 records

Key highlights7 records

Customer concentration

Schellman & Company social profiles

Digital presence

Schellman & Company compliance and trust

Trust signal

Compliance32 records

Schellman & Company financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Schellman & Company leadership team

Management profile

Number of profiles

Profiles9 records

Schellman & Company subsidiaries and ownership

Company hierarchy

Subsidiaries3 records

Schellman & Company funding detail

Funding detail

Funding overview

Funding rounds2 records

Investors2 records

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Schellman & Company M&A and investment

M&A and investment

M&A2 records

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Schellman & Company

What does Schellman & Company do?

Schellman & Company provides independent IT compliance, cybersecurity, and attestation assessment services, operating simultaneously as a licensed CPA firm and globally accredited certification body. The firm delivers nearly 60 types of audits and assessments, including SOC 1/2/3 examinations, ISO 27001/42001/27701/9001/22301/20000-1/14001/45001/50001 certifications, FedRAMP 3PAO and CMMC C3PAO federal assessments, PCI DSS validation, HITRUST CSF certification, penetration testing, AI Red Teaming, AI governance (ISO 42001, AIUC-1), privacy assessments (GDPR, CCPA), cryptocurrency/digital trust audits, and sustainability assurance.

Is Schellman & Company a public or private company?

Schellman & Company is a private company. It is classified as private equity controlled and is currently operating.

When was Schellman & Company founded?

Schellman & Company was founded in 2002. It employs 501 to 1,000 people.

Where is Schellman & Company based?

Schellman & Company is headquartered in Tampa, United States, in the North America region.

How does Schellman & Company make money?

Two revenue lines are on record. Compliance and Attestation Assessment Services are the primary driver. The others are training Services.

Who are Schellman & Company's main competitors?

AssuranceLab is listed as a regional player. Direct peers are Linford & Company, A-LIGN, 360 Advanced, BARR Advisory, Coalfire and KirkpatrickPrice. Broad incumbents are Deloitte, KPMG and EY (Ernst & Young).

Does Schellman & Company have an API?

Yes. Schellman offers an AuditSource platform with Open API Terms of Use referenced in their privacy policy. The platform appears to provide API-based access for audit and compliance services, though specific API documentation URL, authentication methods, rate limits, and versioning details are not publicly specified in available sources.

What industry is Schellman & Company in?

Schellman & Company's product category is Cybersecurity Compliance & Attestation Services. Its primary akta.pro industry code is BPAKADAC, Security Audits & Compliance (ISO 27001, SOC 2, PCI DSS, HIPAA, SOX), with a secondary code of FSAMADAL, POS Certification, Testing & Compliance (EMVCo, PCI PTS/PCI DSS). Its NAICS code is 541211 and its SIC code is 8900.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
GlobalfintechseriesSchellman Appoints Marshall Lux to Board of DirectorsMarshall Lux joined Schellman's Board of Directors, bringing over 20 years at McKinsey and a prior role as Global Chief Risk Officer at JPMorgan Chase. The appointment follows a Goldman Sachs Alternatives investment and expanded leadership, including new COO and C-suite roles.GlobeNewswireSchellman Reaches 200 FedRAMP® Assessed Offerings, Extending Its Lead as the Industry's #1 FedRAMP 3PAOSchellman, the nation's #1 FedRAMP 3PAO, became the first to assess 200 cloud service offerings on the FedRAMP Marketplace. The milestone spans all authorization levels and reflects over a decade of leadership. The company cites over 870 ATOs across 71 federal agencies.GlobeNewswireSchellman Becomes the First Accredited Auditor for AIUC-1, the Security Standard for AI AgentsSchellman became the first authorized auditor of AIUC-1, the security standard for AI agents, on Feb. 3, 2026. The partnership combines AIUC's technical evaluations with Schellman's audit services, covering six principles and adversarial testing. Leading AI companies are adopting both AIUC-1 and ISO 42001 for comprehensive governance.YahooLumen Achieves ISO 42001 Certification, Reaffirming Responsible AI LeadershipLumen Technologies announced it has been awarded ISO 42001 certification for its Artificial Intelligence Management System (AIMS), validating the company's AI governance framework for internal business processes. The certification, conducted by Schellman Compliance as the independent third-party auditor, makes Lumen's AI governance process the first to be certified to this globally recognized standard. The company stated it will continue investing in scalable, responsible AI practices as part of its ongoing innovation roadmap.GlobeNewswireMatrix Applications Completes SOC 1 and SOC 2 Type 2 for TradeBlazer Collateral Management System and Managed ServicesMatrix Applications completed SOC 1 and SOC 2 Type 2 audits for its TradeBlazer collateral management system and managed services, conducted by Schellman & Company. The audits attest to the design and operating effectiveness of its internal controls for financial reporting and information security. The company's compliance reflects its commitment to protecting client data.PR NewswireEIR Completes SOC 2 Type 2 Examination for WORKstream®, Showing Commitment to Security Controls and TrustEnterprise Information Resources Inc. (EIR) announced that its proprietary WORKstream® platform has successfully completed a SOC 2 Type 2 examination in Security, conducted by Schellman & Company, LLC. Unlike a Type 1 review, this examination confirms that EIR's security controls operated effectively over an extended period of time, validating the company's internal controls, software development, and operational processes. The milestone provides HR and IT teams with independent assurance around security, reliability, and operational discipline for the SAP SuccessFactors-focused platform.GlobeNewswireMatrix Applications Completes SOC 1 & SOC 2 Type 2 for TradeBlazer and Managed ServicesMatrix Applications completed its 2024 SOC 1 and SOC 2 Type 2 audits for TradeBlazer and Managed Services, conducted by Schellman & Company. The audits confirm the company's internal controls for financial reporting and information security. The company will continue maintaining high security standards.GlobeNewswireSchellman & Company, LLC Announces Carve Out Acquisition of Connor Consulting’s Third-Party Risk Management (TPRM) PracticeSchellman & Company acquired Connor Consulting's Third-Party Risk Management practice, integrating it into its TPRM offerings. The deal strengthens Schellman's third-party oversight capabilities and complements its existing compliance services. The transition aims to provide uninterrupted service to existing clients.GlobeNewswireMatrix Applications Completes SOC 1 & SOC 2 Type 2 for TradeBlazer and Managed ServicesMatrix Applications completed its 2024 SOC 1 and SOC 2 Type 2 audits for TradeBlazer and Managed Services, conducted by Schellman & Company. The audits confirm the company's internal controls for financial reporting and information security. The firm stated it will continue maintaining high security standards.GlobeNewswireSchellman Compliance Expands Sustainability Reporting Services with Acquisition of Sustas, LLC Practice and ISO 14001 Accreditation by ANABSchellman Compliance acquired Sustas, LLC, a sustainability reporting firm, and obtained ISO 14001 accreditation from ANAB. The move strengthens its sustainability practice to help clients navigate SEC climate disclosure rules, California's Climate Accountability Package, and Europe's CSRD.