LOADING…
Platform  /  Civil nuclear  ·  Sector
Civil nuclear

Sovereign by design,for civil nuclear.

E2ERisk helps civil nuclear organisations manage supplier assurance, cyber evidence, regulatory scrutiny and sovereign deployment in one controlled evidence model - built for sensitive assurance environments where evidence control matters.

See the platform
ONR regulatedSovereign deploymentOFFICIAL-SENSITIVE
The challenge

Civil nuclear leaves no room for 'trust us'.

The sector operates under ONR scrutiny and the highest expectations for classification, personnel control and auditable evidence. Supplier risk, the handling of sensitive information and the deployment of any assurance tooling all have to satisfy a regulator that expects precision, not marketing.

E2ERisk is built for that environment: sovereign deployment in your own tenant or fully air-gapped, customer-managed keys, an append-only audit trail and supplier-assurance evidence mapped to the ONR SyAPs expectations. See the security model →

The brief

Assurance for civil nuclear.

Civil nuclear sits under some of the most demanding regulation in the country. The ONR's Security Assessment Principles set the bar for how licensees and their supply chains protect sensitive nuclear information and technology, and the evidence behind any claim has to withstand regulatory scrutiny rather than a supplier's say-so.

That extends to the assurance tooling itself: anything handling OFFICIAL-SENSITIVE supply-chain evidence has to be deployable on sovereign ground, with the licensee in control of both the data and the keys.

Without E2ERisk
ONR expectations across a regulated supply chain
OFFICIAL-SENSITIVE data you cannot put in just any SaaS
Suppliers assessed inconsistently against SyAPs
Assurance evidence scattered and hard to defend
With E2ERisk
Supply-chain assurance aligned to ONR SyAPs
Sovereign deployment: your tenant, your data residency
Consistent, control-level judgements across suppliers
A defensible evidence base, ready for the regulator
How it works

One lifecycle, end to end.

Every supplier follows the same path, from the moment it is engaged through to continuous monitoring long after sign-off. How deep the assessment goes is set by the sensitivity of the information and the role the supplier plays, so a regulated team concentrates its effort on the suppliers that genuinely matter to nuclear security.

01 Onboard
It starts at intake
New suppliers captured the moment they are engaged.
No more supplier dependencies discovered only at review.
02 Profile
Right depth
Criticality and data exposure set the assessment depth.
Effort lands where the risk actually is.
03 Assess
Native to your frameworks
Assessed against ONR SyAPs, the CAF and NISR, at control level.
Defensible judgements, not a tick-box.
04 Evidence
Capture once
Evidence inherits across every overlapping requirement.
Re-used, not re-collected, each cycle.
05 Remediate
Close the gap
Findings become owned actions with dates.
Progress tracked, not forgotten.
06 Monitor
Stay current
Outside-in signals and review dates keep it live.
You see supplier exposure before it becomes an assurance finding.
NUCLEAR SUPPLY CHAIN Live
Onboard
Supplier & scope captured
Classify
By sensitivity & role
auto
Assess
SyAPs, CAF and NISR evidence
Review
Evidence reviewed and challenged
review
Evidence
Held in your tenant
Monitor
Kept current, defensible

Regulated assurance, deployable in your own sovereign environment.

The difference

Regulated assurance, made defensible.

The obligations do not change; what changes is whether the evidence is defensible and where it lives. Run on spreadsheets and email, deployment drifts offshore, SyAPs is interpreted differently by each assessor, and sensitive evidence ends up scattered across inboxes.

What you doSpreadsheets + emailE2ERisk
DeploymentShared SaaS, data offshoreSovereign: your tenant, your residency
SyAPs alignmentInterpreted per assessorConsistent and control-level
Supplier evidenceScatteredOne defensible base
SensitivityHandled ad hocSensitivity classified and access-controlled
Regulator requestA scrambleA current, defensible pack
Next assessmentFrom scratchA review of what is already there

The result is regulated assurance you can actually defend: consistent against SyAPs, held in your own tenant, and ready the moment the ONR or your board asks.

Where to start

The modules that matter most here.

Most nuclear licensees start with Supplier Assurance and CAF Assessment: the regulated supply chain and the control-level evidence behind it, then add Secure by Design and Business Resilience as the shared evidence base proves itself. Because every module runs on one engine, what you build for the first carries straight into the next.

By the numbers

What it adds up to under regulation.

For a nuclear licensee the payoff is regulated assurance that never leaves sovereign ground. The platform deploys in your own tenant, supplier assessment is aligned to ONR SyAPs, the CAF is assessed natively at v4.0, and every regime draws on one defensible evidence base.

Sovereign
deployment in your own tenant
SyAPs
aligned assurance
1
defensible evidence base
v4.0
NCSC CAF assessed natively
Native to your regimes

One evidence base for every regime.

A licensee answers to the ONR's SyAPs, the Nuclear Industries Security Regulations and the CAF at once, and an assessor for one will not accept evidence shaped only for another. E2ERisk maps a single body of assessment answers to every regime it touches, so a control proven once is reported against all of them.

ONR SyAPsNISR 2003NCSC CAF v4.0ISO 27001:2022NIS RegulationsOFFICIAL-SENSITIVE-ready
Next step

Regulated assurance, on your own ground.

A 30-minute walkthrough on regulated supply-chain assurance and sovereign deployment - no slides.