By:
Nick Rundhaug
September 10th, 2026
Insights from a conversation with Nick Rundhaug, Managing Director and Federal Practice Leader at Schellman. See his full interview here.
By:
Matt Hungate
August 31st, 2026
FedRAMP's modernization effort, known as FedRAMP 20x, is continuing to advance. On August 31, 2026, the FedRAMP 20x program opened Class B and Class C as the next phase of its rollout. Under the program's official Consolidated Rules for 2026 (CR26), Class B pipeline replaces the old Low impact level for small-scale cloud services, and the Class C pipeline replaces the old Moderate impact level for common enterprise services.
By:
Nick Rundhaug
August 25th, 2026
This article was drafted based on a LinkedIn Live discussion between Schellman’s Nick Rundhaug and SecureIT's Tim Sandage and Corey Clements. View their full conversation here.
By:
Christian Baer
August 18th, 2026
Insight from Schellman's federal team on the FedRAMP 2026 Consolidated Rule update, featuring the program's biggest overhaul in years.
By:
Matt Hungate
August 3rd, 2026
Highlights from our GovFORWARD 8th Annual Carahsoft Summit on FedRAMP breakout session, featuring Schellman's Matt Hungate.
By:
Douglas Barbin
July 31st, 2026
For the past year, Cybersecurity Maturity Model Certification (CMMC) compliance has mainly focused on self-assessments. Organizations handling Controlled Unclassified Information (CUI) have spent time evaluating their environments, documenting controls, and identifying gaps against required cybersecurity standards. CMMC Phase 2, originally scheduled for November 10, 2026, was set to mandate independent assessments conducted by Certified Third Party Assessment Organizations (C3PAOs) for new DoD solicitations and contracts involving CUI. However, the Department of War (DoW) paused CMMC Phase 2 on July 13, 2026, and launched a 60-day review to lessen the burden of compliance for small and non-traditional businesses.
FedRAMP | Federal Assessments | SOC 2
By:
Matt Hungate
June 29th, 2026
If you’ve heard “FedRAMP” and immediately thought “that’s a year-long, million-dollar project we’re not ready for” — this post is for you. A lot has changed. The program's new Class A certification tier was built specifically for companies that have already done the hard work of achieving SOC 2 Type II. Here’s what your SOC 2 actually gets you, and why the path to the federal marketplace may be shorter than you think.
FedRAMP | News | Federal Assessments
By:
Schellman
June 25th, 2026
Schellman, the nation's No. 1 FedRAMP Independent Assessor, breaks down the most significant restructuring of the federal cloud security program since its 2011 inception.