Live Webinar | Building AI Governance That's Audit-Ready on September 23 @ 1:00PM ET

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

The Schellman Blog

Blog Feature

FedRAMP | Federal Assessments

By: Nick Rundhaug
September 10th, 2026

Insights from a conversation with Nick Rundhaug, Managing Director and Federal Practice Leader at Schellman. See his full interview here.

Blog Feature

FedRAMP | Federal Assessments

By: Matt Hungate
August 31st, 2026

FedRAMP's modernization effort, known as FedRAMP 20x, is continuing to advance. On August 31, 2026, the FedRAMP 20x program opened Class B and Class C as the next phase of its rollout. Under the program's official Consolidated Rules for 2026 (CR26), Class B pipeline replaces the old Low impact level for small-scale cloud services, and the Class C pipeline replaces the old Moderate impact level for common enterprise services.

Blog Feature

FedRAMP | Federal Assessments

By: Nick Rundhaug
August 25th, 2026

This article was drafted based on a LinkedIn Live discussion between Schellman’s Nick Rundhaug and SecureIT's Tim Sandage and Corey Clements. View their full conversation here.

Blog Feature

FedRAMP | Federal Assessments

By: Christian Baer
August 18th, 2026

Insight from Schellman's federal team on the FedRAMP 2026 Consolidated Rule update, featuring the program's biggest overhaul in years.

Blog Feature

FedRAMP | Federal Assessments

By: Matt Hungate
August 3rd, 2026

Highlights from our GovFORWARD 8th Annual Carahsoft Summit on FedRAMP breakout session, featuring Schellman's Matt Hungate.

Blog Feature

Federal Assessments | CMMC

By: Douglas Barbin
July 31st, 2026

For the past year, Cybersecurity Maturity Model Certification (CMMC) compliance has mainly focused on self-assessments. Organizations handling Controlled Unclassified Information (CUI) have spent time evaluating their environments, documenting controls, and identifying gaps against required cybersecurity standards. CMMC Phase 2, originally scheduled for November 10, 2026, was set to mandate independent assessments conducted by Certified Third Party Assessment Organizations (C3PAOs) for new DoD solicitations and contracts involving CUI. However, the Department of War (DoW) paused CMMC Phase 2 on July 13, 2026, and launched a 60-day review to lessen the burden of compliance for small and non-traditional businesses.

Blog Feature

FedRAMP | Federal Assessments | SOC 2

By: Matt Hungate
June 29th, 2026

If you’ve heard “FedRAMP” and immediately thought “that’s a year-long, million-dollar project we’re not ready for” — this post is for you. A lot has changed. The program's new Class A certification tier was built specifically for companies that have already done the hard work of achieving SOC 2 Type II. Here’s what your SOC 2 actually gets you, and why the path to the federal marketplace may be shorter than you think.

Blog Feature

FedRAMP | News | Federal Assessments

By: Schellman
June 25th, 2026

Schellman, the nation's No. 1 FedRAMP Independent Assessor, breaks down the most significant restructuring of the federal cloud security program since its 2011 inception.

{