Live Webinar | Building AI Governance That's Audit-Ready on September 23 @ 1:00PM ET

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

The Schellman Blog

Blog Feature

FedRAMP | Federal Assessments

By: Christian Baer
September 15th, 2026

In June, FedRAMP released its Consolidated Rules 2026 (CR26), the biggest overhaul to the program since it launched in 2011. Schellman’s Christian Baer and Banu Jagasia from BladeStack.io broke down what's changing and why it matters, whether you're pursuing a new certification or maintaining an existing one.

Blog Feature

Federal Assessments | CMMC

By: Douglas Barbin
September 1st, 2026

When the Department of War (DoW) suddenly paused CMMC Phase 2.0 on July 13, 2026, it caught the defense industry off guard. With the third-party assessment requirements halted just months before their go-live date in November 2026, there’s much speculation that compliance activities will also be held up. However, a few things haven’t changed because of the pause: Phase 1 self-assessment requirements are still due, the False Claims Act exposure for inaccurate attestations hasn’t gone anywhere, and the obligation to protect Controlled Unclassified Information (CUI) under NIST 800-171 remains fully in effect. For the defense industrial base, treating this pause as a reason to slow down is the wrong takeaway.

Blog Feature

FedRAMP | Federal Assessments

By: Nick Rundhaug
August 26th, 2026

FedRAMP is undergoing its biggest structural shift in over a decade. In this conversation, Schellman's Nick Rundhaug, Managing Director and Federal Practice Leader, unpacks what FedRAMP 20x actually changes for cloud service providers (CSPs) and what to prioritize before walking into an assessment.

Blog Feature

FedRAMP | Federal Assessments

By: Nick Rundhaug
August 6th, 2026

FedRAMP's consolidated 2026 rules landed at the end of June, and the shift they represent is significant, featuring new Key Security Indicators (KSIs) for automated, continuous compliance reporting, a leaner but more technical documentation model built around machine-readable CPO and SDR files, and a compressed timeline that's already cutting review periods from years down to about a month.

Blog Feature

Artificial Intelligence

By: Danny Manimbo
July 20th, 2026

The regulatory landscape for AI is evolving and shifting, bringing downstream implications on governance that can't be ignored. Colorado's AI Act has already been rewritten once before even taking effect. States keep introducing new bills. Federal preemption remains more theory than reality. For companies trying to build AI compliance programs, the environment remains complex.

Blog Feature

Federal Assessments | CMMC

By: Douglas Barbin
June 9th, 2026

CMMC certification is mandatory if you want federal contracts, but the journey doesn't end there.

Blog Feature

FedRAMP | Federal Assessments

By: Matt Hungate
May 27th, 2026

The FedRAMP landscape is shifting. With the introduction of FedRAMP 20x, cloud service providers now face a critical decision: pursue the newer 20x authorization pathway, stay the course with Rev 5, or chart a hybrid strategy that positions them for both short-term and long-term success.

Blog Feature

Artificial Intelligence | ISO 42001

By: Danny Manimbo
May 15th, 2026

The regulatory landscape for AI is shifting faster than most organizations can keep up. Federal policies are shifting. States are flooding the zone with new legislation. Implementation timelines keep moving.

Blog Feature

SOC Examinations

By: Ryan Buckner
March 31st, 2026

If your organization has completed a SOC Type 1 report, you've taken a meaningful first step in demonstrating the security and reliability of your systems to customers and partners. But many organizations quickly find themselves facing a follow-up question: When should we move to a Type 2?

Blog Feature

Artificial Intelligence

By: Danny Manimbo
March 10th, 2026

As organizations deploy AI agents to automate complex workflows, trust in their responsible use is just as important as their capabilities. Enterprises want to know not only what AI systems can do, but also how they behave in real-world conditions, how they are governed, and whether they can be trusted with sensitive data and critical business processes.

{