Schellman
Schellman is a Top 50 US CPA firm focused exclusively on IT compliance and cybersecurity, serving federal, financial, healthcare, cloud, and AI clients with independent SOC, FedRAMP, ISO, PCI, HITRUST, and AI governance assessments. It is the #1 FedRAMP 3PAO and first ANAB-accredited ISO 42001 certification body.
- Company typePrivate
- Founded2004
- HeadquartersTampa, United States
- Headcount—
- GTM typeB2B
- OfferingServices
What Schellman does
Schellman & Company, LLC is a Top 50 US CPA firm focused exclusively on IT compliance and cybersecurity assessments and attestations, headquartered in Tampa, Florida. Founded in 2004 as a SOC audit firm, Schellman has grown into a multi-practice compliance provider issuing more than 2,000 SOC reports per year across 60 distinct audit and assessment types. The firm is the #1 FedRAMP Third Party Assessment Organization (3PAO) with 200+ assessed offerings, an accredited CMMC C3PAO, an authorized assessor for DoD IL6, and the world's first ANAB-accredited certification body for ISO 42001 (AI Management Systems). It also issues PCI DSS, HITRUST, HIPAA, ISO 27001/27701/9001/22301/20000-1/14001/45001/50001, GDPR, SOC 1/2/3, FedRAMP, CMMC, FISMA, ITAR, CJIS, IRAP, and AIUC-1 certifications, in addition to running a full penetration testing practice (including AI Red Teaming), crypto and digital trust assessments, and a practitioner-led training business.
Schellman sells compliance services primarily through an enterprise direct sales motion supported by inside sales for mid-market. Engagement is quote-based (no published price list) and delivered by certified assessors (CPA, CISA, QSA, 3PAO, ISO lead auditors). Customer concentration is diversified across five primary verticals: US Federal Government and Defense Contractors, Financial Services and Fintech, Healthcare, Cloud Computing and Data Centers, and emerging AI/ML organizations. Named enterprise clients include OpenAI, Oracle, Meta, Walmart, VMware, and Iron Mountain, alongside case-study deployments with Vanta, Sisense, UiPath, Coupa, Greenhouse, Clario, and Fieldguide.
The business model is professional services revenue: per-engagement fees for assessments plus recurring annual engagements (e.g., SOC 2 Type II, ISO 27001 surveillance, FedRAMP continuous monitoring). Go-to-market combines direct field sales for large enterprise with thought leadership, webinars, and industry events for demand generation. Marketing is anchored on regulatory expertise and first-mover positioning in emerging frameworks. In 2026, Goldman Sachs Alternatives acquired a majority stake from Lightyear Capital, with stated intent to fund international expansion and capability growth in AI governance, federal compliance, and digital trust. The firm operates an alternative practice structure with Schellman & Company, LLC (the licensed CPA entity) and Schellman Compliance, LLC (non-CPA advisory services), is B Corp certified, and employs an undisclosed number of assessors.
Schellman firmographics
Firmographics- Name
- Schellman
- Legal name
- Schellman & Company, LLC
- Website
- https://schellmanco.com
- Company type
- Private
- Founded year
- 2004
- Operating status
- Operating
- Short description
- Schellman is a Top 50 US CPA firm focused exclusively on IT compliance and cybersecurity, serving federal, financial, healthcare, cloud, and AI clients with independent SOC, FedRAMP, ISO, PCI, HITRUST, and AI governance assessments. It is the #1 FedRAMP 3PAO and first ANAB-accredited ISO 42001 certification body.
- Ownership category
- akta.pro rank
Where Schellman is headquartered
LocationHeadquarters
- HQ city
- Tampa
- HQ country
- United States
- HQ region
- North America
Offices1 record
Markets served
Schellman business model
Business model- GTM type
- B2B
- Offering type
- Services
- Cost components
- Personnel, Operations, Marketing or Sales, Technology or R&D, Others
Revenue model
- Compliance Assessment Services: Professional services revenue generated from conducting independent assessments and certifications including SOC examinations, ISO certifications, FedRAMP assessments, PCI DSS validations, HIPAA compliance, and other cybersecurity attestations. Services are delivered by certified auditors and assessors.
- Training Services: World-class training and certification services delivered directly to cybersecurity professionals by expert practitioners.
Go-to-market motion2 records
Distribution channels2 records
Marketing channels5 records
Schellman product offering
Product offeringCore offering
Schellman is an ANAB-accredited certification body that conducts independent IT compliance and cybersecurity audits and assessments across nearly 60 frameworks including SOC, ISO, PCI DSS, FedRAMP, CMMC, HIPAA, GDPR, and AI governance standards. The firm issues attestations and certifications that enable organizations to demonstrate regulatory compliance, secure federal authorizations to operate, and build trust with customers. Complementary services include penetration testing, cybersecurity assessments, AI Red Teaming, AIUC-1 certification, and training for cybersecurity professionals.
Product overview
Schellman is a Top 50 CPA firm focused exclusively on IT Compliance and Cybersecurity, and the #1 service provider for FedRAMP Assessments. The firm offers nearly 60 types of audits and assessments organized into a comprehensive suite of services including: SOC & Attestations (SOC 1, SOC 2, SOC 3, SOC for Supply Chain, SOC for Cybersecurity, SOC Essentials, C5 Attestation, CSA STAR Programs), Payment Card Assessments (PCI DSS, PCI SSF, PCI P2PE, PCI PIN, PCI 3DS), ISO Certifications (ISO 27001, ISO 42001, ISO 27701, ISO 9001, ISO 22301, ISO 20000-1, ISO 14001, ISO 45001, ISO 50001), Privacy Assessments (Global CBPR & PRP, GDPR, International Privacy, US State Privacy, Microsoft SSPA/DPR, FERPA, EU Cloud Code of Conduct), Federal Assessments (FedRAMP, CMMC/NIST SP 800-171, FISMA/NIST, ITAR, CJIS, IRAP, FTC Consent Decrees, DoD IL6), Healthcare Assessments (HITRUST, HIPAA, HIPAA Express, EPCS-DEA, HDS), Penetration Testing (Application, Network, Mobile, Red Teaming, Social Engineering, Cloud, Physical, Hardware and IoT, Advanced, AI Red Teaming), Cybersecurity Assessments (Cloud Configuration, Ransomware, NIST CSF, S3A, TISAX, SWIFT CSP, Internal Audit Co-Sourcing, MTCS, ENS), Crypto and Digital Trust, Schellman Training, Sustainability Services, and AI Governance (including ISO 42001 and AIUC-1 certification services). Schellman is the world's first ANAB-accredited ISO 42001 certification body.
Differentiator
Problem solved
Functional benefit
Products and services
- SOC & Attestations
Quantifiable outcome
- Over 2,000 SOC reports issued annually
- +2 more outcomes
Companies that use Schellman
Customer profileNamed customers6 records
Segments7 records
Ideal customer profiles5 records
Schellman technology and API
TechnologyTechnology focussed No
API detail
- Has API
- No
- API docs
- API detail
Core technology
AI maturity
App detail
AI capability2 records
Feature4 records
Schellman partnerships and signals
Strategic signalScale indicators8 records
Recent moves6 records
Expansion highlights6 records
Schellman competitors and assessment
Company assessmentDirect peers
- KirkpatrickPrice: KirkpatrickPrice is a direct competitor offering SOC, ISO, PCI, and HIPAA audits with a focus on IT compliance and cybersecurity attestation. It targets a similar client profile of service organizations needing recurring compliance certifications.
- BARR Advisory: BARR Advisory is a direct competitor providing SOC, ISO, PCI, HITRUST, and FedRAMP readiness and attestation services. It serves a similar mid-market and enterprise client base and competes for the same compliance frameworks.
- Coalfire: Coalfire is a direct competitor providing FedRAMP 3PAO assessments, SOC audits, PCI QSA services, and cybersecurity advisory. It is one of the most prominent FedRAMP assessors competing with Schellman for federal cloud authorization engagements.
- 360 Advanced: 360 Advanced is a direct competitor providing SOC, ISO, PCI, HITRUST, and cybersecurity assessments. It competes with Schellman for similar mid-market and enterprise compliance engagements across regulated industries.
- A-LIGN: A-LIGN is a direct competitor offering SOC, ISO, PCI, HITRUST, and FedRAMP assessments with a similar compliance-focused professional services model. Headquartered in Tampa, FL, it competes head-to-head with Schellman across the same enterprise customer base and framework set.
Broad incumbents
- PwC (Cybersecurity and Privacy): PwC is a broad incumbent with a significant cybersecurity, privacy, and risk assurance practice that includes IT compliance attestation services. It competes with Schellman for large multinational clients needing globally delivered compliance work.
- Deloitte (Cyber & Strategic Risk): Deloitte is a broad incumbent that operates a large global cybersecurity and risk advisory practice including FedRAMP and SOC assessment services. It competes with Schellman for large enterprise and federal mandates and offers a broader advisory portfolio.
- KPMG (Cyber Security Services): KPMG is a broad incumbent with a significant cybersecurity and IT advisory practice covering ISO, SOC, and regulatory compliance assessments. It competes with Schellman for large enterprise and regulated-industry engagements.
- EY (Cybersecurity): EY is a broad incumbent with a substantial cybersecurity and technology risk practice offering SOC, ISO, and IT compliance services. It competes with Schellman for large enterprise and global client mandates requiring integrated advisory offerings.
Emerging players
- HITRUST: HITRUST is an emerging player that develops and maintains the HITRUST CSF framework, an external assessor program on which Schellman relies for healthcare compliance certifications. It is adjacent to Schellman as both a standards body and ecosystem participant enabling assessor services.
Market position
Strengths5 records
Weaknesses5 records
Competitive moat5 records
Key risks5 records
Key highlights7 records
Customer concentration
Schellman social profiles
Digital presenceSchellman compliance and trust
Trust signalCompliance28 records
Schellman financial estimates
Financial estimateRevenue estimate
Valuation estimate
Schellman leadership team
Management profileNumber of profiles
Profiles1 record
Schellman funding detail
Funding detailFunding overview
Funding rounds
Investors
Funding detail is available on the Subscription and Enterprise plan.Contact sales →
Schellman M&A and investment
M&A and investmentM&A
Investments
M&A and investment is available on the Subscription and Enterprise plan.Contact sales →
Frequently asked questions about Schellman
What does Schellman do?
Schellman is an ANAB-accredited certification body that conducts independent IT compliance and cybersecurity audits and assessments across nearly 60 frameworks including SOC, ISO, PCI DSS, FedRAMP, CMMC, HIPAA, GDPR, and AI governance standards. The firm issues attestations and certifications that enable organizations to demonstrate regulatory compliance, secure federal authorizations to operate, and build trust with customers. Complementary services include penetration testing, cybersecurity assessments, AI Red Teaming, AIUC-1 certification, and training for cybersecurity professionals.
Is Schellman a public or private company?
Schellman is a private company. It is classified as private equity controlled and is currently operating.
When was Schellman founded?
Schellman was founded in 2004.
Where is Schellman based?
Schellman is headquartered in Tampa, United States, in the North America region.
How does Schellman make money?
Two revenue lines are on record. Compliance Assessment Services are the primary driver. The others are training Services.
Who are Schellman's main competitors?
Direct peers on record are KirkpatrickPrice, BARR Advisory, Coalfire, 360 Advanced and A-LIGN. Broad incumbents are PwC (Cybersecurity and Privacy), Deloitte (Cyber & Strategic Risk), KPMG (Cyber Security Services) and EY (Cybersecurity). HITRUST is listed as an emerging player.
Does Schellman have an API?
No public API is recorded for Schellman.