By:
Chris Lippert
December 23rd, 2025
If you’re a vendor looking to do business with Microsoft, you may be required to complete the Supplier Security and Privacy Assurance (SSPA) program as part of the procurement process. The SSPA program is Microsoft’s mechanism for evaluating whether suppliers meet its baseline security, privacy, and AI governance expectations outlined in the Microsoft Data Protection Requirements (DPR).
By:
Avani Desai
December 15th, 2025
The new FedRAMP 20x low baseline pilot is the most significant modernization of federal cloud security in more than a decade, and it could represent a big opportunity for cloud service providers looking to enter or expand within the federal marketplace.
By:
Matt Hungate
November 17th, 2025
FedRAMP 20X is emerging as one of the most significant changes to federal cloud security authorization in years. Designed to streamline how cloud service providers (CSPs) work with the U.S. government, 20X introduces a faster, more accessible alternative to the traditional FedRAMP Rev5 authorization path. For organizations looking to enter or expand within the federal market, understanding this new model is essential.
Cybersecurity Assessments | Privacy Assessments
By:
Chris Lippert
November 13th, 2025
As data privacy expectations continue to rise, organizations operating in the cloud are facing growing pressure to prove compliance with the EU’s General Data Protection Regulation (GDPR). For cloud service providers (CSPs), one of the most relevant and practical ways to demonstrate that compliance is through the EU Cloud Code of Conduct—a voluntary, sector-specific framework designed specifically for the cloud industry.
By:
Danny Manimbo
October 29th, 2025
Danny Manimbo, principal and ISO practice leader at Schellman, answers the most frequently asked questions about ISO 20000-1 Certification, including its importance, who should consider adopting it, and how it relates to ISO 9001.
By:
Danny Manimbo
September 30th, 2025
Danny Manimbo, Principal and ISO practice leader at Schellman, answers the most frequently asked questions about ISO Certifications, including insights about the process, how to select a certification body, and the costs involved.
By:
Danny Manimbo
September 9th, 2025
Danny Manimbo, principal and ISO practice leader at Schellman, answers the most frequently asked questions about ISO 50001 Certification, including its importance, key elements, and implementation.
By:
Danny Manimbo
September 2nd, 2025
Danny Manimbo, principal and ISO practice leader at Schellman, answers the most frequently asked questions regarding ISO 45001 Certification, including its key elements, importance, and benefits.
By:
Danny Manimbo
July 15th, 2025
Danny Manimbo, principal and ISO practice leader at Schellman, answers the most frequently asked questions about ISO 22301 Certification, including key benefits, who should consider adopting it, and how it relates to DORA and NIS2.
By:
Danny Manimbo
June 30th, 2025
Danny Manimbo, principal and ISO practice leader at Schellman, explores the ISO 9001 Certification, including its importance, key benefits, and which businesses should consider adopting it.