Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

The Schellman Blog

Stay up to date with the latest compliance news from the Schellman blog.

Blog Feature

Federal Assessments | CMMC

By: Tim Walsh
August 13th, 2024

Looking back, December 2023 was a big month for the Department of Defense (DoD), as they released the both memorandum titled Federal Risk and Authorization Management Program (FedRAMP) Moderate Equivalency for Cloud Service Provider’s Cloud Service Offerings, as well as the 32 CFR Part 170 - Cybersecurity Maturity Model Certification (CMMC) Proposed Rule.

Blog Feature

Cybersecurity Assessments

By: COLLIN VARNER
August 8th, 2024

Back in 2017, the New York State Department of Financial Services (NYDFS) took a significant step to enhance the cybersecurity defenses of financial institutions operating in New York by introducing the NYDFS Cybersecurity Regulation. Through its set of requirements—since amended in 2023—the Regulation aims to better safeguard the sensitive information processed through these organizations which must adhere to its mandates.

Blog Feature

Healthcare Assessments

By: GARY NELSON
August 7th, 2024

Source: Pharmaceutical Compliance Monitor On March 31, 2010 the Drug Enforcement Agency’s (DEA) rule, “Electronic Prescriptions for Controlled Substances” has revised its regulations to give physicians the choice of writing prescriptions for controlled substances the traditional method or through the electronic system. Originally, the regulation restricted physicians and practitioners from writing electronic prescriptions for controlled substances (EPCS).

Blog Feature

By: GARY NELSON
August 7th, 2024

Is there a period of time that the DEA-EPCS Third Party audit is valid? On March 31, 2010 the Drug Enforcement Agency's (DEA) rule, "Electronic Prescriptions for Controlled Substances" has revised its regulations to give physicians the choice of writing prescriptions for controlled substances the traditional method or through the electronic system. Originally, the regulation restricted physicians and practitioners from writing electronic prescriptions for controlled substances (EPCS).

Blog Feature

ISO Certifications | ISO 9001

By: JORDAN HICKS
August 6th, 2024

GettiWhen you commit to getting ISO 9001 certified, you commit to meeting the needs of customers and other stakeholders regarding your product or service through a comprehensive quality management system (QMS). But it’s not enough to meet the standard—you have to get ISO 9001 certified, which involves an initial certification audit, further surveillance audits, and recertification in order to maintain an accredited certification.

Blog Feature

Privacy Assessments

By: CHRIS LIPPERT
August 1st, 2024

When Microsoft released version 9 of their Data Protection Requirements (DPR) back in October 2023, the new framework contained several important updates, as well as a few brand new requirements, including the addition of new considerations for suppliers processing protected health information (PHI).

Blog Feature

Payment Card Assessments | PCI DSS

By: Jeff Lasker
July 30th, 2024

Since the sunsetting of PCI DSS v3.2.1 on March 31, 2024, PCI DSS v4.0 has become effective, as have some of its new requirements (though future-dated requirements will be effective March 31, 2025). While v4.0 has introduced some major changes in various areas, for service providers—including some that include additional nuance for colocation providers in particular—multiple new requirements are now effective as well as some that are future-dated.

{