Developer docs
API playgroundTry for free, no card

Search company profiles

Schellman

Full company profile

uuid00xixxg

Namestring
Schellman
Legal namestring
Schellman & Company, LLC
Websiteurl
schellmanco.com
Company typeenum
Private
Founded yearint
2004
Descriptiontext

Schellman & Company, LLC is a Top 50 US CPA firm focused exclusively on IT compliance and cybersecurity assessments and attestations, headquartered in Tampa, Florida. Founded in 2004 as a SOC audit firm, Schellman has grown into a multi-practice compliance provider issuing more than 2,000 SOC reports per year across 60 distinct audit and assessment types. The firm is the #1 FedRAMP Third Party Assessment Organization (3PAO) with 200+ assessed offerings, an accredited CMMC C3PAO, an authorized assessor for DoD IL6, and the world's first ANAB-accredited certification body for ISO 42001 (AI Management Systems). It also issues PCI DSS, HITRUST, HIPAA, ISO 27001/27701/9001/22301/20000-1/14001/45001/50001, GDPR, SOC 1/2/3, FedRAMP, CMMC, FISMA, ITAR, CJIS, IRAP, and AIUC-1 certifications, in addition to running a full penetration testing practice (including AI Red Teaming), crypto and digital trust assessments, and a practitioner-led training business.

Schellman sells compliance services primarily through an enterprise direct sales motion supported by inside sales for mid-market. Engagement is quote-based (no published price list) and delivered by certified assessors (CPA, CISA, QSA, 3PAO, ISO lead auditors). Customer concentration is diversified across five primary verticals: US Federal Government and Defense Contractors, Financial Services and Fintech, Healthcare, Cloud Computing and Data Centers, and emerging AI/ML organizations. Named enterprise clients include OpenAI, Oracle, Meta, Walmart, VMware, and Iron Mountain, alongside case-study deployments with Vanta, Sisense, UiPath, Coupa, Greenhouse, Clario, and Fieldguide.

The business model is professional services revenue: per-engagement fees for assessments plus recurring annual engagements (e.g., SOC 2 Type II, ISO 27001 surveillance, FedRAMP continuous monitoring). Go-to-market combines direct field sales for large enterprise with thought leadership, webinars, and industry events for demand generation. Marketing is anchored on regulatory expertise and first-mover positioning in emerging frameworks. In 2026, Goldman Sachs Alternatives acquired a majority stake from Lightyear Capital, with stated intent to fund international expansion and capability growth in AI governance, federal compliance, and digital trust. The firm operates an alternative practice structure with Schellman & Company, LLC (the licensed CPA entity) and Schellman Compliance, LLC (non-CPA advisory services), is B Corp certified, and employs an undisclosed number of assessors.

Short descriptiontext

Schellman is a Top 50 US CPA firm focused exclusively on IT compliance and cybersecurity, serving federal, financial, healthcare, cloud, and AI clients with independent SOC, FedRAMP, ISO, PCI, HITRUST, and AI governance assessments. It is the #1 FedRAMP 3PAO and first ANAB-accredited ISO 42001 certification body.

Operating statusenum
Operating
Ownership categoryenum
akta.pro rankint
HeadquartersTampa, United States
HQ citystring
Tampa
HQ countrystring
United States
HQ regionstring
North America
Markets served

Serves global market

Offices1 record

Each record includes

City, Country, Type, Description, Source

Keyword5 values
IT compliance assessments, cybersecurity attestation services, FedRAMP third-party assessments, ISO certification body, SOC examination services
Industry1 code
1Proof of Reserves, Attestations & On-Chain Audit/Assurance
CodeFSADALAKPrimaryNo
NAICS code2 codes
  • Offices of Certified Public Accountants541211
  • Computer Systems Design and Related Services54151
SIC code2 codes
  • Services-Management Services8741
  • Services-Services, Nec8900
Product category
IT Compliance & Cybersecurity Attestation Services
GTM motion2 records

Each record includes

Type, Description, Source

Revenue model2 records
1Compliance Assessment Services
TypeProfessional Services
Description

Professional services revenue generated from conducting independent assessments and certifications including SOC examinations, ISO certifications, FedRAMP assessments, PCI DSS validations, HIPAA compliance, and other cybersecurity attestations. Services are delivered by certified auditors and assessors.

schellman.com
2Training Services
TypeProfessional Services
Description

World-class training and certification services delivered directly to cybersecurity professionals by expert practitioners.

schellman.com
Marketing channels5 records

Each record includes

Title, Type, Stage, Description, Source

Distribution channels2 records

Each record includes

Title, Type, Scope, Target buyer, Description, Source

Cost components5 values
Personnel, Operations, Marketing or Sales, Technology or R&D, Others
GTM typeB2B
B2B
Offering typeServices
Services
Core offering1 text field

Schellman is an ANAB-accredited certification body that conducts independent IT compliance and cybersecurity audits and assessments across nearly 60 frameworks including SOC, ISO, PCI DSS, FedRAMP, CMMC, HIPAA, GDPR, and AI governance standards. The firm issues attestations and certifications that enable organizations to demonstrate regulatory compliance, secure federal authorizations to operate, and build trust with customers. Complementary services include penetration testing, cybersecurity assessments, AI Red Teaming, AIUC-1 certification, and training for cybersecurity professionals.

Differentiator
Functional benefit
Problem solved
Quantifiable outcome1 of 3 values shown
  • Over 2,000 SOC reports issued annually
+2 more records
Product overview1 text field

Schellman is a Top 50 CPA firm focused exclusively on IT Compliance and Cybersecurity, and the #1 service provider for FedRAMP Assessments. The firm offers nearly 60 types of audits and assessments organized into a comprehensive suite of services including: SOC & Attestations (SOC 1, SOC 2, SOC 3, SOC for Supply Chain, SOC for Cybersecurity, SOC Essentials, C5 Attestation, CSA STAR Programs), Payment Card Assessments (PCI DSS, PCI SSF, PCI P2PE, PCI PIN, PCI 3DS), ISO Certifications (ISO 27001, ISO 42001, ISO 27701, ISO 9001, ISO 22301, ISO 20000-1, ISO 14001, ISO 45001, ISO 50001), Privacy Assessments (Global CBPR & PRP, GDPR, International Privacy, US State Privacy, Microsoft SSPA/DPR, FERPA, EU Cloud Code of Conduct), Federal Assessments (FedRAMP, CMMC/NIST SP 800-171, FISMA/NIST, ITAR, CJIS, IRAP, FTC Consent Decrees, DoD IL6), Healthcare Assessments (HITRUST, HIPAA, HIPAA Express, EPCS-DEA, HDS), Penetration Testing (Application, Network, Mobile, Red Teaming, Social Engineering, Cloud, Physical, Hardware and IoT, Advanced, AI Red Teaming), Cybersecurity Assessments (Cloud Configuration, Ransomware, NIST CSF, S3A, TISAX, SWIFT CSP, Internal Audit Co-Sourcing, MTCS, ENS), Crypto and Digital Trust, Schellman Training, Sustainability Services, and AI Governance (including ISO 42001 and AIUC-1 certification services). Schellman is the world's first ANAB-accredited ISO 42001 certification body.

Product and service1 record
1SOC & Attestations
Scale indicator8 records

Each record includes

Type, Value, Description, Source

Recent move6 records

Each record includes

Date, Type, Title, Description, Source

Expansion highlight6 records

Each record includes

Type, Description

Peers10 records
TypeDirect peer
Description

KirkpatrickPrice is a direct competitor offering SOC, ISO, PCI, and HIPAA audits with a focus on IT compliance and cybersecurity attestation. It targets a similar client profile of service organizations needing recurring compliance certifications.

TypeBroad incumbent
Description

PwC is a broad incumbent with a significant cybersecurity, privacy, and risk assurance practice that includes IT compliance attestation services. It competes with Schellman for large multinational clients needing globally delivered compliance work.

TypeBroad incumbent
Description

Deloitte is a broad incumbent that operates a large global cybersecurity and risk advisory practice including FedRAMP and SOC assessment services. It competes with Schellman for large enterprise and federal mandates and offers a broader advisory portfolio.

TypeBroad incumbent
Description

KPMG is a broad incumbent with a significant cybersecurity and IT advisory practice covering ISO, SOC, and regulatory compliance assessments. It competes with Schellman for large enterprise and regulated-industry engagements.

TypeDirect peer
Description

BARR Advisory is a direct competitor providing SOC, ISO, PCI, HITRUST, and FedRAMP readiness and attestation services. It serves a similar mid-market and enterprise client base and competes for the same compliance frameworks.

TypeDirect peer
Description

Coalfire is a direct competitor providing FedRAMP 3PAO assessments, SOC audits, PCI QSA services, and cybersecurity advisory. It is one of the most prominent FedRAMP assessors competing with Schellman for federal cloud authorization engagements.

TypeEmerging player
Description

HITRUST is an emerging player that develops and maintains the HITRUST CSF framework, an external assessor program on which Schellman relies for healthcare compliance certifications. It is adjacent to Schellman as both a standards body and ecosystem participant enabling assessor services.

TypeDirect peer
Description

360 Advanced is a direct competitor providing SOC, ISO, PCI, HITRUST, and cybersecurity assessments. It competes with Schellman for similar mid-market and enterprise compliance engagements across regulated industries.

TypeDirect peer
Description

A-LIGN is a direct competitor offering SOC, ISO, PCI, HITRUST, and FedRAMP assessments with a similar compliance-focused professional services model. Headquartered in Tampa, FL, it competes head-to-head with Schellman across the same enterprise customer base and framework set.

TypeBroad incumbent
Description

EY is a broad incumbent with a substantial cybersecurity and technology risk practice offering SOC, ISO, and IT compliance services. It competes with Schellman for large enterprise and global client mandates requiring integrated advisory offerings.

Market position
Strengths5 records

Each record includes

Headline, Details, Source

Weaknesses5 records

Each record includes

Headline, Details, Source

Competitive moat5 records

Each record includes

Type, Details

Key risks5 records

Each record includes

Headline, Details, Source

Key highlights7 records

Each record includes

Headline, Details, Source

Customer concentration

Classification, Details

Named customers6 records

Each record includes

Name, Industry, Type, Use case, Source, UUID

Segment7 records

Each record includes

Title, Type, Primary, Description, Pain point addressed, Use case, Source

Ideal customer profile5 records

Each record includes

Profile, Firmographic size, Sales motion, Sales cycle length, Buying structure, Purchase trigger, Buyer persona, Geography, Industry vertical, Primary use case, Description, Pain points, Evidence proof points, Target buyer

Technology focused
No
API detail
Has APIbool
No

Docs URL, Description

AI capability2 records

Each record includes

Type, Description, Source

AI maturity
App detail

Has app

Feature4 records

Each record includes

Title, Differentiator, Description, Source

Core technology
Revenue estimate
Valuation estimate
Number of profiles
Profiles1 record

Each record includes

Name, Designation, Designation category, Overview, Profile commentary, Source

No data
Compliance28 records

Each record includes

Name, Class, Description

Funding overview

Funding stage, Last funding date, Total funding USD

Funding rounds

Each record includes

Round, Amount USD, Date, Pre money valuation, Total investors, Investors, News

Investors

Each record includes

Name, Type, Date of entry, Rounds participated, Website

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

M&A

Each record includes

Name, Acquisition type, Announced date, Completed date, Status, Website, News

Investment

Each record includes

Name, Round, Announced date, Lead investor, Website, News

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Schellman

IT Compliance & Cybersecurity Attestation Servicesschellmanco.com

Schellman is a Top 50 US CPA firm focused exclusively on IT compliance and cybersecurity, serving federal, financial, healthcare, cloud, and AI clients with independent SOC, FedRAMP, ISO, PCI, HITRUST, and AI governance assessments. It is the #1 FedRAMP 3PAO and first ANAB-accredited ISO 42001 certification body.

What Schellman does

Schellman & Company, LLC is a Top 50 US CPA firm focused exclusively on IT compliance and cybersecurity assessments and attestations, headquartered in Tampa, Florida. Founded in 2004 as a SOC audit firm, Schellman has grown into a multi-practice compliance provider issuing more than 2,000 SOC reports per year across 60 distinct audit and assessment types. The firm is the #1 FedRAMP Third Party Assessment Organization (3PAO) with 200+ assessed offerings, an accredited CMMC C3PAO, an authorized assessor for DoD IL6, and the world's first ANAB-accredited certification body for ISO 42001 (AI Management Systems). It also issues PCI DSS, HITRUST, HIPAA, ISO 27001/27701/9001/22301/20000-1/14001/45001/50001, GDPR, SOC 1/2/3, FedRAMP, CMMC, FISMA, ITAR, CJIS, IRAP, and AIUC-1 certifications, in addition to running a full penetration testing practice (including AI Red Teaming), crypto and digital trust assessments, and a practitioner-led training business.

Schellman sells compliance services primarily through an enterprise direct sales motion supported by inside sales for mid-market. Engagement is quote-based (no published price list) and delivered by certified assessors (CPA, CISA, QSA, 3PAO, ISO lead auditors). Customer concentration is diversified across five primary verticals: US Federal Government and Defense Contractors, Financial Services and Fintech, Healthcare, Cloud Computing and Data Centers, and emerging AI/ML organizations. Named enterprise clients include OpenAI, Oracle, Meta, Walmart, VMware, and Iron Mountain, alongside case-study deployments with Vanta, Sisense, UiPath, Coupa, Greenhouse, Clario, and Fieldguide.

The business model is professional services revenue: per-engagement fees for assessments plus recurring annual engagements (e.g., SOC 2 Type II, ISO 27001 surveillance, FedRAMP continuous monitoring). Go-to-market combines direct field sales for large enterprise with thought leadership, webinars, and industry events for demand generation. Marketing is anchored on regulatory expertise and first-mover positioning in emerging frameworks. In 2026, Goldman Sachs Alternatives acquired a majority stake from Lightyear Capital, with stated intent to fund international expansion and capability growth in AI governance, federal compliance, and digital trust. The firm operates an alternative practice structure with Schellman & Company, LLC (the licensed CPA entity) and Schellman Compliance, LLC (non-CPA advisory services), is B Corp certified, and employs an undisclosed number of assessors.

Schellman firmographics

Firmographics
Name
Schellman
Legal name
Schellman & Company, LLC
Website
https://schellmanco.com
Company type
Private
Founded year
2004
Operating status
Operating
Short description
Schellman is a Top 50 US CPA firm focused exclusively on IT compliance and cybersecurity, serving federal, financial, healthcare, cloud, and AI clients with independent SOC, FedRAMP, ISO, PCI, HITRUST, and AI governance assessments. It is the #1 FedRAMP 3PAO and first ANAB-accredited ISO 42001 certification body.
Ownership category
akta.pro rank

Where Schellman is headquartered

Location

Headquarters

HQ city
Tampa
HQ country
United States
HQ region
North America

Offices1 record

Markets served

Schellman business model

Business model
GTM type
B2B
Offering type
Services
Cost components
Personnel, Operations, Marketing or Sales, Technology or R&D, Others

Revenue model

  1. Compliance Assessment Services: Professional services revenue generated from conducting independent assessments and certifications including SOC examinations, ISO certifications, FedRAMP assessments, PCI DSS validations, HIPAA compliance, and other cybersecurity attestations. Services are delivered by certified auditors and assessors.
  2. Training Services: World-class training and certification services delivered directly to cybersecurity professionals by expert practitioners.

Go-to-market motion2 records

Distribution channels2 records

Marketing channels5 records

Schellman product offering

Product offering

Core offering

Schellman is an ANAB-accredited certification body that conducts independent IT compliance and cybersecurity audits and assessments across nearly 60 frameworks including SOC, ISO, PCI DSS, FedRAMP, CMMC, HIPAA, GDPR, and AI governance standards. The firm issues attestations and certifications that enable organizations to demonstrate regulatory compliance, secure federal authorizations to operate, and build trust with customers. Complementary services include penetration testing, cybersecurity assessments, AI Red Teaming, AIUC-1 certification, and training for cybersecurity professionals.

Product overview

Schellman is a Top 50 CPA firm focused exclusively on IT Compliance and Cybersecurity, and the #1 service provider for FedRAMP Assessments. The firm offers nearly 60 types of audits and assessments organized into a comprehensive suite of services including: SOC & Attestations (SOC 1, SOC 2, SOC 3, SOC for Supply Chain, SOC for Cybersecurity, SOC Essentials, C5 Attestation, CSA STAR Programs), Payment Card Assessments (PCI DSS, PCI SSF, PCI P2PE, PCI PIN, PCI 3DS), ISO Certifications (ISO 27001, ISO 42001, ISO 27701, ISO 9001, ISO 22301, ISO 20000-1, ISO 14001, ISO 45001, ISO 50001), Privacy Assessments (Global CBPR & PRP, GDPR, International Privacy, US State Privacy, Microsoft SSPA/DPR, FERPA, EU Cloud Code of Conduct), Federal Assessments (FedRAMP, CMMC/NIST SP 800-171, FISMA/NIST, ITAR, CJIS, IRAP, FTC Consent Decrees, DoD IL6), Healthcare Assessments (HITRUST, HIPAA, HIPAA Express, EPCS-DEA, HDS), Penetration Testing (Application, Network, Mobile, Red Teaming, Social Engineering, Cloud, Physical, Hardware and IoT, Advanced, AI Red Teaming), Cybersecurity Assessments (Cloud Configuration, Ransomware, NIST CSF, S3A, TISAX, SWIFT CSP, Internal Audit Co-Sourcing, MTCS, ENS), Crypto and Digital Trust, Schellman Training, Sustainability Services, and AI Governance (including ISO 42001 and AIUC-1 certification services). Schellman is the world's first ANAB-accredited ISO 42001 certification body.

Differentiator

Problem solved

Functional benefit

Products and services

  • SOC & Attestations

Quantifiable outcome

  • Over 2,000 SOC reports issued annually
  • +2 more outcomes

Companies that use Schellman

Customer profile

Named customers6 records

Segments7 records

Ideal customer profiles5 records

Schellman technology and API

Technology

Technology focussed No

API detail

Has API
No
API docs
API detail

Core technology

AI maturity

App detail

AI capability2 records

Feature4 records

Schellman partnerships and signals

Strategic signal

Scale indicators8 records

Recent moves6 records

Expansion highlights6 records

Schellman competitors and assessment

Company assessment

Direct peers

  • KirkpatrickPrice: KirkpatrickPrice is a direct competitor offering SOC, ISO, PCI, and HIPAA audits with a focus on IT compliance and cybersecurity attestation. It targets a similar client profile of service organizations needing recurring compliance certifications.
  • BARR Advisory: BARR Advisory is a direct competitor providing SOC, ISO, PCI, HITRUST, and FedRAMP readiness and attestation services. It serves a similar mid-market and enterprise client base and competes for the same compliance frameworks.
  • Coalfire: Coalfire is a direct competitor providing FedRAMP 3PAO assessments, SOC audits, PCI QSA services, and cybersecurity advisory. It is one of the most prominent FedRAMP assessors competing with Schellman for federal cloud authorization engagements.
  • 360 Advanced: 360 Advanced is a direct competitor providing SOC, ISO, PCI, HITRUST, and cybersecurity assessments. It competes with Schellman for similar mid-market and enterprise compliance engagements across regulated industries.
  • A-LIGN: A-LIGN is a direct competitor offering SOC, ISO, PCI, HITRUST, and FedRAMP assessments with a similar compliance-focused professional services model. Headquartered in Tampa, FL, it competes head-to-head with Schellman across the same enterprise customer base and framework set.

Broad incumbents

  • PwC (Cybersecurity and Privacy): PwC is a broad incumbent with a significant cybersecurity, privacy, and risk assurance practice that includes IT compliance attestation services. It competes with Schellman for large multinational clients needing globally delivered compliance work.
  • Deloitte (Cyber & Strategic Risk): Deloitte is a broad incumbent that operates a large global cybersecurity and risk advisory practice including FedRAMP and SOC assessment services. It competes with Schellman for large enterprise and federal mandates and offers a broader advisory portfolio.
  • KPMG (Cyber Security Services): KPMG is a broad incumbent with a significant cybersecurity and IT advisory practice covering ISO, SOC, and regulatory compliance assessments. It competes with Schellman for large enterprise and regulated-industry engagements.
  • EY (Cybersecurity): EY is a broad incumbent with a substantial cybersecurity and technology risk practice offering SOC, ISO, and IT compliance services. It competes with Schellman for large enterprise and global client mandates requiring integrated advisory offerings.

Emerging players

  • HITRUST: HITRUST is an emerging player that develops and maintains the HITRUST CSF framework, an external assessor program on which Schellman relies for healthcare compliance certifications. It is adjacent to Schellman as both a standards body and ecosystem participant enabling assessor services.

Market position

Strengths5 records

Weaknesses5 records

Competitive moat5 records

Key risks5 records

Key highlights7 records

Customer concentration

Schellman social profiles

Digital presence

Schellman compliance and trust

Trust signal

Compliance28 records

Schellman financial estimates

Financial estimate

Revenue estimate

Valuation estimate

Schellman leadership team

Management profile

Number of profiles

Profiles1 record

Schellman funding detail

Funding detail

Funding overview

Funding rounds

Investors

Funding detail is available on the Subscription and Enterprise plan.Contact sales →

Schellman M&A and investment

M&A and investment

M&A

Investments

M&A and investment is available on the Subscription and Enterprise plan.Contact sales →

Frequently asked questions about Schellman

What does Schellman do?

Schellman is an ANAB-accredited certification body that conducts independent IT compliance and cybersecurity audits and assessments across nearly 60 frameworks including SOC, ISO, PCI DSS, FedRAMP, CMMC, HIPAA, GDPR, and AI governance standards. The firm issues attestations and certifications that enable organizations to demonstrate regulatory compliance, secure federal authorizations to operate, and build trust with customers. Complementary services include penetration testing, cybersecurity assessments, AI Red Teaming, AIUC-1 certification, and training for cybersecurity professionals.

Is Schellman a public or private company?

Schellman is a private company. It is classified as private equity controlled and is currently operating.

When was Schellman founded?

Schellman was founded in 2004.

Where is Schellman based?

Schellman is headquartered in Tampa, United States, in the North America region.

How does Schellman make money?

Two revenue lines are on record. Compliance Assessment Services are the primary driver. The others are training Services.

Who are Schellman's main competitors?

Direct peers on record are KirkpatrickPrice, BARR Advisory, Coalfire, 360 Advanced and A-LIGN. Broad incumbents are PwC (Cybersecurity and Privacy), Deloitte (Cyber & Strategic Risk), KPMG (Cyber Security Services) and EY (Cybersecurity). HITRUST is listed as an emerging player.

Does Schellman have an API?

No public API is recorded for Schellman.

Unlock the full company data

50 free credits on sign-up, no credit card required.

Contact sales
Live signals
FinancialContent Business PageSchellman Appoints Marshall Lux to Board of DirectorsMarshall Lux joined Schellman's Board of Directors, bringing over 20 years of experience at McKinsey and JPMorgan Chase. The appointment follows Goldman Sachs Alternatives' strategic investment and expanded leadership hires. Lux adds risk governance expertise as Schellman builds toward its next phase.GlobalfintechseriesSchellman Appoints Marshall Lux to Board of DirectorsMarshall Lux joined Schellman's Board of Directors, bringing over 20 years at McKinsey and a prior role as Global Chief Risk Officer at JPMorgan Chase. The appointment follows a Goldman Sachs Alternatives investment and expanded leadership, including new COO and C-suite roles.AccountingtodayRogue agents: When AI won't listenThe article details various instances where AI agents in the accounting sector exhibited unintended behaviors, such as auto-refunding legitimate payments, deleting invoices, and overwriting user edits. Industry experts from firms including Edgefield Group, Schellman, Sage, Karbon, and Caseware describe implementing governance measures like human-in-the-loop validation, least-privilege access, and rigorous performance testing to mitigate these risks.Var IndiaAI Governance: From Investment to ExecutionSchellman's 2026 report highlights a significant execution gap in AI governance, revealing that while most organizations fund these initiatives, only 27% have achieved true operational maturity. The article outlines four key pillars for effective governance: automated tools, documented processes, independent audits, and enterprise-wide training. It further emphasizes the need for strict security measures and human oversight for high-risk agentic AI decisions.ItbriefSchellman finds AI governance gap amid regulatory pressureSchellman published research showing 74% of enterprises believe they are ready for an AI audit, but only 27% describe their AI governance programs as fully mature, based on a survey of 525 US-based professionals involved in AI governance. The report highlights that while 86% of organizations have tested or piloted AI agents, only 46% have them in production, with organizations possessing mature governance being significantly more likely to deploy AI agents live (78%) compared to those with developing programs (22%). The findings also reveal uneven regulatory preparation, with 89% of organizations acting on US regulations but only 29% preparing for the EU AI Act, suggesting companies are prioritizing domestic requirements over international obligations.CIO DiveMost US companies lack mature AI governance frameworksCompliance services firm Schellman surveyed 525 U.S.-based professionals involved in AI governance and found a significant gap between confidence and actual maturity, with only 27% describing their programs as fully mature despite 90% having allocated funding to governance. The report revealed that while 86% of organizations are testing AI agents and nearly half have them in production, most lack essential safeguards, with only 44% having AI-specific incident response procedures and just one in five having a mature model for governing autonomous agents. Companies with mature governance programs reported improved internal efficiency, easier AI scaling, increased customer trust, and better preparedness for regulations including the EU AI Act.ScanXIEC 42001:2023 certification for Responsible AIHCLTech has achieved the ISO/IEC 42001:2023 certification for its Enterprise Artificial Intelligence Management System (AIMS), validating its capability to support enterprises in scaling AI adoption with robust governance. The certification was issued by Schellman Compliance, LLC and covers AI lifecycle processes including the AI Force platform, software engineering, IT operations and business process services. The framework aligns with global regulations such as the EU AI Act, ensuring responsible AI development.FinancialContent Business PageFedRAMP's Biggest Modernization in a Decade Opens New Doors for Cloud Service ProvidersSchellman, the nation's top FedRAMP Independent Assessor, published an analysis on June 25, 2026 of the FedRAMP Consolidated Rules for 2026, which the firm describes as the most consequential modernization of the federal cloud security program since its inception. The new rules eliminate the agency sponsorship requirement and introduce new Class A and Program Certification paths, lowering barriers for cloud service providers seeking to enter or expand within the federal marketplace. Schellman also flagged an immediate compliance deadline under CISA Binding Operational Directive 26-04, with full vulnerability management compliance required by December 7, 2026, ahead of the broader January 1, 2027 deadline.GlobeNewswireFedRAMP's Biggest Modernization in a Decade Opens New Doors for Cloud Service ProvidersSchellman, the nation's leading FedRAMP Independent Assessor, published its analysis of the FedRAMP Consolidated Rules for 2026, released June 24, which represents the most consequential modernization of the federal cloud security program since its inception. The new rules eliminate the agency sponsorship requirement under the Program Certification path and introduce a new Class A Certification path allowing cloud service providers with existing SOC 2 Type II, GovRAMP, or FedRAMP Rev5 assessments to leverage that work toward certification. Organizations must prioritize vulnerability management compliance under CISA Binding Operational Directive 26-04 by December 7, 2026, ahead of the broader January 1, 2027 compliance deadline.Help Net SecurityData discovery gaps that catch enterprises off guardAvani Desai, CEO at Schellman, an interview-based article discusses how enterprises often discover significant gaps between their perceived understanding of data environments and what discovery scans reveal, finding shadow data in abandoned cloud storage, legacy systems, and decommissioned platforms. The article highlights post-merger data duplication creating integration challenges and costs, while arguing that synthetic data is overmarketed as a governance solution and confidential computing remains underappreciated for protecting data in AI-driven shared environments. Desai also notes that smaller companies often outperform larger enterprises on compliance due to having fewer legacy systems and clearer data ownership structures.