E2ERisk helps departments and arm’s-length bodies manage CAF, GovAssure, Secure by Design and supplier assurance across large, complex supplier estates - with one evidence base instead of another spreadsheet cycle.
Departments and arm's-length bodies carry some of the largest, most scrutinised supplier estates in the country. GovAssure made the NCSC CAF the measure of departmental cyber resilience, and Secure by Design made assurance a condition of spend - and both push the hard problem down into the supply chain, where hundreds or thousands of suppliers have to be assessed, evidenced and kept current, often by a small central team reporting up to a lead department.
E2ERisk gives government organisations one platform for that whole picture: CAF and GovAssure, Secure by Design, supplier assurance and DPIA on one evidence model, deployable in your own UK Azure tenant for OFFICIAL-SENSITIVE work and available through G-Cloud. Evidence is captured once and reused across every regime, then rolled up into department-level reporting.
Built for UK public-sector assurance environments - customer-tenant deployment, role-based access, an append-only audit trail and UK data residency. See the security model →
GovAssure, Secure by Design and the CAF all ask for the same underlying facts about your suppliers - but in different shapes, on different timelines, for different audiences. Run separately, they become three parallel spreadsheet exercises that never quite agree, each one rebuilt from scratch every cycle.
E2ERisk puts one evidence base behind all of them. A fact captured once - a supplier's control, a piece of evidence, a CAF judgement - answers every regime that needs it, so the effort is spent once and reported everywhere.
Every supplier follows the same path, from the moment they are first engaged through to continuous monitoring long after sign-off. Criticality decides how deep the assessment goes, so a stretched team spends its effort where the risk actually is rather than treating every vendor the same.
Evidence is captured once and inherited across overlapping requirements, and findings become owned actions with dates. Nothing falls into the gap between annual reviews, because there is no gap - the lifecycle never stops running.
The next cycle is a review, not a rebuild - the evidence is already there.
The obligations do not change; the work behind them does. Instead of rebuilding evidence by hand each cycle, reconciling inconsistent assessor judgements and chasing suppliers over email, the same activity runs as one connected, auditable process.
The comparison below shows, line by line, what moves from a spreadsheet-and-SharePoint scramble to a living evidence base - and why the difference compounds with every GovAssure cycle.
| What you do | Spreadsheets & SharePoint | E2ERisk |
|---|---|---|
| GovAssure evidence | Rebuilt by hand every cycle | Captured once, inherited across stages |
| Supplier assurance | A separate, manual exercise | Tied to the CAF outcomes they support |
| CAF judgements | Inconsistent between assessors | IGP-level and defensible |
| Secure by Design | Claimed, hard to evidence | Backed by live assurance |
| Reporting to the lead dept | A document scramble | A current pack on demand |
| Next cycle | Start from scratch | A review, not a rebuild |
The result is not just faster reporting - it is a more defensible position. Every judgement carries its evidence, every gap has an owner, and every cycle starts from the last verified state rather than a blank page.
You do not have to adopt everything at once. Most central-government teams start where the pressure is highest - usually CAF and Supplier Assurance ahead of an imminent GovAssure cycle - and bring in Secure by Design and GRC as the shared evidence base proves its value.
Because every module runs on one engine and one register, what you build for the first carries straight into the next. There is no migration and no second source of truth to keep in sync.
NCSC CAF v4.0 native, IGP-level - the spine of GovAssure.
Assess the suppliers behind your essential services, by criticality.
Evidence security is built into delivery, not bolted on after.
Carry risk, controls and compliance into one board-ready register.
The case for E2ERisk in central government comes down to fewer moving parts behind the same obligations. All four GovAssure stages run on one platform end to end, the NCSC CAF is assessed natively at v4.0 down to indicator level, and every regime you answer to draws on a single shared evidence base rather than its own parallel spreadsheet.
That is why the next cycle starts from zero rebuilds. Nothing is re-collected from scratch, because last cycle's evidence, judgements and owners are already in place - the work becomes a review of what changed, not a reconstruction of everything.
A department answers to more than one framework at a time, and an assessor for one will not accept evidence shaped only for another. E2ERisk maps a single body of assessment answers to every regime it touches - GovAssure, the CAF, Secure by Design, ISO 27001, Cyber Essentials and the NIS Regulations.
So the evidence holds up whichever framework is asking, and a control proven once is reported against all of them - without being re-collected each time the question is phrased differently.
A 30-minute walkthrough on your suppliers and your frameworks - no slides.