By:
Douglas Barbin
July 31st, 2026
For the past year, Cybersecurity Maturity Model Certification (CMMC) compliance has mainly focused on self-assessments. Organizations handling Controlled Unclassified Information (CUI) have spent time evaluating their environments, documenting controls, and identifying gaps against required cybersecurity standards. CMMC Phase 2, originally scheduled for November 10, 2026, was set to mandate independent assessments conducted by Certified Third Party Assessment Organizations (C3PAOs) for new DoD solicitations and contracts involving CUI. However, the Department of War (DoW) paused CMMC Phase 2 on July 13, 2026, and launched a 60-day review to lessen the burden of compliance for small and non-traditional businesses.
FedRAMP | Federal Assessments | SOC 2
By:
Matt Hungate
June 29th, 2026
If you’ve heard “FedRAMP” and immediately thought “that’s a year-long, million-dollar project we’re not ready for” — this post is for you. A lot has changed. The program's new Class A certification tier was built specifically for companies that have already done the hard work of achieving SOC 2 Type II. Here’s what your SOC 2 actually gets you, and why the path to the federal marketplace may be shorter than you think.
FedRAMP | News | Federal Assessments
By:
Schellman
June 25th, 2026
Schellman, the nation's No. 1 FedRAMP Independent Assessor, breaks down the most significant restructuring of the federal cloud security program since its 2011 inception.
By:
Matt Hungate
June 25th, 2026
On June 24, 2026, FedRAMP published the Consolidated Rules for 2026, featuring a sweeping overhaul of the policies, requirements, and terminology that govern how cloud service providers (CSPs) obtain and maintain FedRAMP Certification. The rules are effective July 4, 2026, for 20x CSPs and replace a patchwork of legacy guidance documents, memoranda, and program policies with a single machine-readable, structured ruleset. For existing Rev5 CSPs, most requirements become mandatory on January 1, 2027, with optional early adoption available immediately.
By:
Matt Hungate
June 4th, 2026
This article was drafted based on a LinkedIn Live discussion between Schellman’s Matt Hungate (Managing Principal, Federal Practice) and Jacob Karp (VP of Strategic Sales). View their full conversation here.
By:
Matt Hungate
May 18th, 2026
Schellman is the industry’s #1 FedRAMP Third Party Assessment Organization (3PAO) and has become the first to assess over 200 cloud service offerings on the FedRAMP Marketplace. From over a decade of experience, we’ve accumulated a significant amount of firsthand experience and hard-earned insights into what it actually takes to achieve and maintain federal authorization.
By:
Schellman
April 30th, 2026
The most experienced Third Party Assessment Organization in the federal cloud security market reaches a program milestone more than a decade in the making
By:
Andrew Parks
April 28th, 2026
The Cybersecurity Maturity Model Certification (CMMC) has officially shifted from proposed framework to an enforceable requirement for organizations supporting the U.S. Department of Defense (DoD). With the Final Rule now in effect and contractual mandates accelerating, defense contractors and subcontractors can no longer treat CMMC as a future initiative.