Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Services
AI Services
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

The Schellman Blog

Blog Feature

Privacy Assessments

By: Chris Lippert
December 23rd, 2025

If you’re a vendor looking to do business with Microsoft, you may be required to complete the Supplier Security and Privacy Assurance (SSPA) program as part of the procurement process. The SSPA program is Microsoft’s mechanism for evaluating whether suppliers meet its baseline security, privacy, and AI governance expectations outlined in the Microsoft Data Protection Requirements (DPR).

Blog Feature

FedRAMP | Federal Assessments

By: Avani Desai
December 15th, 2025

The new FedRAMP 20x low baseline pilot is the most significant modernization of federal cloud security in more than a decade, and it could represent a big opportunity for cloud service providers looking to enter or expand within the federal marketplace.

Blog Feature

FedRAMP | Federal Assessments

By: Matt Hungate
November 17th, 2025

FedRAMP 20X is emerging as one of the most significant changes to federal cloud security authorization in years. Designed to streamline how cloud service providers (CSPs) work with the U.S. government, 20X introduces a faster, more accessible alternative to the traditional FedRAMP Rev5 authorization path. For organizations looking to enter or expand within the federal market, understanding this new model is essential.

Blog Feature

Cybersecurity Assessments | Privacy Assessments

By: Chris Lippert
November 13th, 2025

As data privacy expectations continue to rise, organizations operating in the cloud are facing growing pressure to prove compliance with the EU’s General Data Protection Regulation (GDPR). For cloud service providers (CSPs), one of the most relevant and practical ways to demonstrate that compliance is through the EU Cloud Code of Conduct—a voluntary, sector-specific framework designed specifically for the cloud industry.

Blog Feature

ISO Certifications

By: Danny Manimbo
October 29th, 2025

Danny Manimbo, principal and ISO practice leader at Schellman, answers the most frequently asked questions about ISO 20000-1 Certification, including its importance, who should consider adopting it, and how it relates to ISO 9001.

Blog Feature

ISO Certifications

By: Danny Manimbo
September 30th, 2025

Danny Manimbo, Principal and ISO practice leader at Schellman, answers the most frequently asked questions about ISO Certifications, including insights about the process, how to select a certification body, and the costs involved.

Blog Feature

ISO Certifications

By: Danny Manimbo
September 9th, 2025

Danny Manimbo, principal and ISO practice leader at Schellman, answers the most frequently asked questions about ISO 50001 Certification, including its importance, key elements, and implementation.

Blog Feature

ISO Certifications

By: Danny Manimbo
September 2nd, 2025

Danny Manimbo, principal and ISO practice leader at Schellman, answers the most frequently asked questions regarding ISO 45001 Certification, including its key elements, importance, and benefits.

Blog Feature

ISO Certifications

By: Danny Manimbo
July 15th, 2025

Danny Manimbo, principal and ISO practice leader at Schellman, answers the most frequently asked questions about ISO 22301 Certification, including key benefits, who should consider adopting it, and how it relates to DORA and NIS2.

Blog Feature

ISO Certifications | ISO 9001

By: Danny Manimbo
June 30th, 2025

Danny Manimbo, principal and ISO practice leader at Schellman, explores the ISO 9001 Certification, including its importance, key benefits, and which businesses should consider adopting it.

{