Departments and arm’s-length bodies under the GovAssure regime and the Secure by Design mandate - with supply chains that run into the thousands.
The next cycle is a review, not a rebuild - the evidence is already there.
| What you do | Spreadsheets & SharePoint | E2E Risk |
|---|---|---|
| GovAssure evidence | Rebuilt by hand every cycle | Captured once, inherited across stages |
| Supplier assurance | A separate, manual exercise | Tied to the CAF outcomes they support |
| CAF judgements | Inconsistent between assessors | IGP-level and defensible |
| Secure by Design | Claimed, hard to evidence | Backed by live assurance |
| Reporting to the lead dept | A document scramble | A current pack on demand |
| Next cycle | Start from scratch | A review, not a rebuild |
NCSC CAF v3.2 native, IGP-level - the spine of GovAssure.
Assess the suppliers behind your essential services, by criticality.
Evidence security is built into delivery, not bolted on after.
Carry risk, controls and compliance into one board-ready register.
A 30-minute walkthrough on your suppliers and your frameworks - no slides.