Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

The Schellman Blog

Stay up to date with the latest compliance news from the Schellman blog.

Blog Feature

Penetration Testing

By: Austin Bentley
November 2nd, 2021

Make pen testing easier while delivering a better report to your client. For testers in the application security (AppSec) arena, you know that we examine a lot of different areas, including authentication, authorization, encryption, logging, and so on, making for what’s become a staple in this job—the large lists of technical checks that grow even longer every time new issues are discovered and then added for testing. If you’ve worked in AppSec, you know that these tests can make for quite the effort, depending on the complexity of the app you’re working in.

Blog Feature

Cybersecurity Assessments

By: Schellman
October 28th, 2021

We all know that cybercriminals are now a thing.

Blog Feature

Federal Assessments | CMMC

By: Schellman
October 19th, 2021

Schellman becomes the first compliance services firm authorized by the CMMC AB and the 5th C3PAO Overall October 19, 2021 (Tampa, FL) – Schellman is pleased to announce that we are now an authorized Cybersecurity Maturity Model Certification (CMMC) Third Party Assessment Organization (C3PAO). Overseen by the Department of Defense (DoD) alongside the CMMC Accreditation Body (CMMC AB), the CMMC program is designed to enforce consistent cybersecurity practices across the hundreds of thousands of defense contractors that participate in and make up the Defense Industrial Base (DIB). A group that now includes Schellman, C3PAOs are the independent assessment organizations that work alongside advisory and training providers to improve cybersecurity practices and protect the sensitive information maintained by the DIB participants.

Blog Feature

FedRAMP | Compliance and Certification | Federal Assessments

By: Matt Hungate
September 15th, 2021

As a Third Party Assessment Organization (3PAO), Schellman has been performing FedRAMP security assessments for Cloud Service Providers (CSPs) since 2014. During this time, we have seen our CSP clients pioneer technologies that provide federal agencies an opportunity to leverage new and innovative cloud services, all while modernizing their approach to building, deploying, and managing applications through containerization. Though this gradual shift to containerizing system components has increased CSPs’ operational efficiency and scale, it has also introduced new security risks to FedRAMP systems.

Blog Feature

SchellmanLife

By: Schellman
September 9th, 2021

Every year, millions of people donate to nonprofit organizations with the hope of making a positive impact in their local and greater communities. These statistics speak for themselves:

Blog Feature

News

By: Schellman
August 17th, 2021

Chris Smith from Schellman & Company, LLC Selected to Attend AICPA’s 2021 Leadership Academy Tampa, FL – August 3, 2021 – Schellman & Company, LLC, a leading provider of attestation and compliance services, is proud to announce that Chris Smith, CPA, CISSP, CISA, CIPP/US, ISO 27001 LA is one of only 30 CPAs to be honored by the American Institute of CPAs (AICPA) with a place as part of the Leadership Academy’s 13th graduating class. Chris was selected based on his exceptional leadership skills and professional experience for the four-day Leadership Academy program, which will take place virtually October 25-28, 2021.

Blog Feature

Cybersecurity Assessments | Payment Card Assessments | NIST | PCI DSS

By: Sully Perella
June 30th, 2021

These days, you can never have too many cybersecurity measures in place, particularly given how regularly threats continue to escalate and grow in sophistication. Now, many organizations are turning to, or considering adopting, Zero Trust (ZT)—a less traditional security model based on the principle of "never trust, always verify.”

{