Authoritative sources for every regime E2ERisk is built around - the standards your assessments, evidence and reporting map to.
These are the regimes E2ERisk is built around - not a reading list, but the frameworks the platform assesses against natively.
UK assurance is a patchwork. The CAF and GovAssure for government, ICO expectations for privacy, Cyber Essentials in contracts, the NIS Regulations for operators of essential services, and NIST as the international reference. Most teams answer each one separately, collecting the same evidence three or four times in three or four different shapes.
E2ERisk maps one body of assessment answers and controls to all of them at once. Capture evidence once and it satisfies many regimes - a supplier answer, a CAF contributing outcome or a DPIA control reused wherever it is relevant, with the mapping shown rather than asserted. The frameworks below each link to the authoritative source; under each, how E2ERisk supports it.
Every assessment answer and control in E2ERisk maps to the frameworks below, so evidence captured once satisfies many regimes at the same time. Each card links to the authoritative source, with a note on how the platform supports it.
The NCSC framework behind GovAssure and our CAF module. In E2ERisk: assessed natively at IGP level, with contributing-outcome judgements, evidence inheritance and a GovAssure-ready pack.
Read more ↗Government SecurityHow government is assured against the CAF. In E2ERisk: Stage 1-4 evidence packs assembled from your live CAF position, not rebuilt each cycle.
Read more ↗Government SecurityThe mandate for building security into government services. In E2ERisk: every principle tracked across design, build, test, release and operate, with evidence and sign-off.
Read more ↗ICOWhen and how to run a data protection impact assessment. In E2ERisk: Article 35 screening and an ICO-aligned DPIA register linked to suppliers, assets and your ROPA.
Read more ↗NCSCThe UK baseline certification and supplier flow-down standard. In E2ERisk: captured in supplier assessments and flowed down to subcontractors as a contractual requirement.
Read more ↗NCSCThe NCSC 12 principles of supply chain security. In E2ERisk: operationalised across discovery, assessment, monitoring and remediation - the doctrine behind the platform.
Read more ↗GOV.UKDuties on operators of essential services. In E2ERisk: OES-aligned supplier assurance across OT and IT, with concentration risk and dependencies surfaced.
Read more ↗NISTThe international reference framework our answers map to. In E2ERisk: every assessment answer cross-maps to CSF 2.0 functions and categories.
Read more ↗We’ll show one assessment answer satisfying CAF, ISO, Cyber Essentials and NIST at once.