By:
Adam Bush
July 27th, 2026
I lead Schellman’s PCI practice, not our CMMC practice, so I'll say upfront: I'm not the person to weigh in on assessment mechanics or how any specific contractor should meet its DFARS and/or NIST 800-171 requirements. But I've spent years watching an eerily similar challenge play out in the PCI landscape that ultimately got solved in payments. The Department of War's (DoW's) recent suspension of CMMC Phase II appears to be approaching the same fork in the road that the card industry faced years ago.
By:
Alexis Smith
July 24th, 2026
For organizations that produce, import, export, or trade hydrofluorocarbons (HFCs), the EPA's annual audit process under the AIM Act is now a structured, recurring review with enforceable compliance requirements. The organizations that understand its mechanics early are consistently better positioned to meet that standard.
By:
Sachin Bansal
July 22nd, 2026
Security leaders have heard the phrase “AI has expanded the attack surface” enough times. The more interesting story is the widening gap between what CISOs say they're doing about it and what's actually happening inside their organizations.
By:
Danny Manimbo
July 16th, 2026
In 2020, Microsoft made a sweeping commitment to be carbon negative by 2030 and remove all the carbon it had ever emitted since 1975. It was ambitious, inspiring, and, as of 2025, slipping further out of reach. Microsoft leaders originally referred to their sustainability goals as a “moonshot,” and in their own words from their 2025 Environmental Sustainability Report, the moon has gotten further away.
By:
Douglas Barbin
July 14th, 2026
On July 13, 2026, the Department of War (DoW) immediately suspended CMMC Phase II — specifically, the requirement for third-party (C3PAO) certification assessments that had been set to take effect November 10, 2026. CMMC Phase I self-assessment requirements for CMMC Levels 1 and 2, and the related NIST SP 800-171 / DFARS 252.204-7012 obligation to safeguard federal data, are unchanged.
By:
Schellman
June 30th, 2026
Schellman, a leading provider of cybersecurity attestation and compliance services, announces that Sachin Bansal has joined the firm as Chief Operating Officer. Bansal leads global operations, global expansion, strategy, and transformation, partnering closely with Chief Executive Officer Avani Desai and the executive leadership team to support the firm’s next phase of growth.
FedRAMP | Federal Assessments | SOC 2
By:
Matt Hungate
June 29th, 2026
If you’ve heard “FedRAMP” and immediately thought “that’s a year-long, million-dollar project we’re not ready for” — this post is for you. A lot has changed. The program's new Class A certification tier was built specifically for companies that have already done the hard work of achieving SOC 2 Type II. Here’s what your SOC 2 actually gets you, and why the path to the federal marketplace may be shorter than you think.
FedRAMP | News | Federal Assessments
By:
Schellman
June 25th, 2026
Schellman, the nation's No. 1 FedRAMP Independent Assessor, breaks down the most significant restructuring of the federal cloud security program since its 2011 inception.