LOADING…
Platform  /  Resources  ·  Framework library
UK framework library

The frameworksyou answer to, built in.

Authoritative sources for every regime E2ERisk is built around - the standards your assessments, evidence and reporting map to.

See the platform
8 frameworksUK public sectorMapped natively
Framework library

The regimes E2ERisk is built around.

These are the regimes E2ERisk is built around - not a reading list, but the frameworks the platform assesses against natively.

UK assurance is a patchwork. The CAF and GovAssure for government, ICO expectations for privacy, Cyber Essentials in contracts, the NIS Regulations for operators of essential services, and NIST as the international reference. Most teams answer each one separately, collecting the same evidence three or four times in three or four different shapes.

E2ERisk maps one body of assessment answers and controls to all of them at once. Capture evidence once and it satisfies many regimes - a supplier answer, a CAF contributing outcome or a DPIA control reused wherever it is relevant, with the mapping shown rather than asserted. The frameworks below each link to the authoritative source; under each, how E2ERisk supports it.

The library

Map once, report against everything.

Every assessment answer and control in E2ERisk maps to the frameworks below, so evidence captured once satisfies many regimes at the same time. Each card links to the authoritative source, with a note on how the platform supports it.

NCSC
Cyber Assessment Framework

The NCSC framework behind GovAssure and our CAF module. In E2ERisk: assessed natively at IGP level, with contributing-outcome judgements, evidence inheritance and a GovAssure-ready pack.

Read more ↗
Government Security
GovAssure

How government is assured against the CAF. In E2ERisk: Stage 1-4 evidence packs assembled from your live CAF position, not rebuilt each cycle.

Read more ↗
Government Security
Secure by Design

The mandate for building security into government services. In E2ERisk: every principle tracked across design, build, test, release and operate, with evidence and sign-off.

Read more ↗
ICO
DPIA guidance

When and how to run a data protection impact assessment. In E2ERisk: Article 35 screening and an ICO-aligned DPIA register linked to suppliers, assets and your ROPA.

Read more ↗
NCSC
Cyber Essentials

The UK baseline certification and supplier flow-down standard. In E2ERisk: captured in supplier assessments and flowed down to subcontractors as a contractual requirement.

Read more ↗
NCSC
Supply chain security

The NCSC 12 principles of supply chain security. In E2ERisk: operationalised across discovery, assessment, monitoring and remediation - the doctrine behind the platform.

Read more ↗
GOV.UK
NIS Regulations

Duties on operators of essential services. In E2ERisk: OES-aligned supplier assurance across OT and IT, with concentration risk and dependencies surfaced.

Read more ↗
NIST
Cybersecurity Framework 2.0

The international reference framework our answers map to. In E2ERisk: every assessment answer cross-maps to CSF 2.0 functions and categories.

Read more ↗
Next step

See the mapping in action.

We’ll show one assessment answer satisfying CAF, ISO, Cyber Essentials and NIST at once.

Explore the platform