Built for UK public sector, CNI and nuclear. Built sovereign. Built deep. Built to defend you from the breach you didn't see coming.
Your suppliers now hold your data, run your services and sit inside your network - which means their security is your security.
For a UK public-sector or critical-infrastructure organisation, the third-party estate is vast and uneven: thousands of suppliers, sub-processors and connected services, each a potential route in. The traditional answer - an annual questionnaire emailed to a handful of "key" vendors - assures a tiny fraction of that estate, on the day they answered, and says nothing about the months in between.
E2ERisk treats supplier assurance as a continuous operating model rather than a once-a-year form. Discovery, criticality tiering, a deep questionnaire, AI-assisted evidence review, outside-in scanning and remediation all run on one platform - so a stretched team can assure the whole estate, not just the suppliers they had time to chase, and prove it to an auditor at any moment.
You can spend £10m hardening the perimeter and still be breached through a vendor with a £49 SaaS account. The organisations that get owned rarely come through the front door any more - they come through a supplier that was trusted, integrated and then quietly forgotten.
The two columns below are the gap that matters: everything a security team believes it controls, set against everything that is actually exposed through the third-party estate sitting just outside it.
The defining breaches of the decade do not look alike on the surface - different sectors, different malware, different scale - but the entry point is always the same: a trusted supplier, not the target's own perimeter.
Read the six below as one pattern rather than six incidents. In every case a single supplier became the route in, and point-in-time assurance never saw it coming.
A trusted software vendor's signed updates carried an attacker's implant into thousands of organisations at once - government included. One supplier, mass compromise.
Attackers subverted one managed-service provider's tooling and pushed ransomware to every business it managed - thousands encrypted over a single weekend.
A zero-day in a widely used file-transfer product exposed the data of thousands of organisations and tens of millions of people - all through a single supplier.
Stolen credentials at an identity provider's support desk let attackers pivot into the customers that trusted it. The identity layer itself became the way in.
Ransomware through a single healthcare processor took pharmacy and claims systems offline for weeks and exposed data on a vast share of a nation's population.
Ransomware against one NHS pathology supplier cancelled thousands of appointments and forced a national blood appeal. A supplier outage became direct patient harm.
Different sectors, different malware - the same root cause. A trusted supplier became the way in. Point-in-time assurance never sees it coming.
Most public-sector security teams are not under-funded - they are under-staffed by an order of magnitude. The figures below come from a real, anonymised UK central-government department in 2026, and they are not the exception. Four analysts, eight thousand suppliers, and a queue you could never clear by hand.
Two-axis criticality routes Tier-3/4 suppliers to a 30-minute self-attestation. Analyst time freed for the suppliers that matter.
Suppliers complete questionnaires themselves. No chase-ups, no emailed PDFs, no spreadsheet version control.
Multi-provider AI reads policies, certs and pen-test reports and extracts answers. Analysts review and sign off - they don't retype.
Supplier assurance is not one feature; it is discovery, tiering, assessment, evidence, monitoring and remediation working as one loop. Bolt those together from separate tools and the seams are exactly where risk hides.
Everything below runs on one platform, built for HMG, CNI and regulated industries - not a US Fortune-500 suite with a UK content pack bolted on.
205 questions, 21 domains, conditional logic, evidence tracking, follow-up branching.
Multi-provider - Anthropic, Azure OpenAI (UK), Groq, Google. Reads policies, certs, audit reports.
Suppliers complete, upload evidence and track progress. The end of email tag.
Auto-tier suppliers with two-axis scoring. Deep diligence where it actually matters.
Which suppliers are exposed to which threat actors and CVEs - mapped to MITRE ATT&CK.
Every gap becomes a tracked risk with owner, due date and treatment. Closure with audit trail.
Ratings-grade passive scanning - domain hygiene, certs, leaked creds, dark-web exposure.
Azure UK-South/West. Customer-tenant for OFFICIAL-SENSITIVE. Source escrow available.
Most tools ship a fifty-question form and call it assurance - until an auditor asks for the evidence behind a control nobody thought to ask about. We engineered the depth UK regulators actually expect: 205 questions across 21 domains, with conditional follow-ups and evidence tracked against every answer.
Profile · criticality · applicability rules tailor every questionnaire - Tier-3/4 suppliers see ~30 questions; only Tier-1 / critical suppliers see the full depth.
Most TPRM tools ship a generic questionnaire and leave the mapping to you. Ours ties every question to the frameworks it answers, so one response becomes evidence across all of them at once.
The example below is a single access-control question - and the ISO 27001, NIST, CAF, Cyber Essentials, GDPR and DSPT clauses it satisfies in that one answer.
NCSC, NIST SP 800-161r1, ISO/IEC 27036-2 and DORA all describe a full third-party lifecycle - roughly 29 distinct activities from onboarding through to offboarding. Most TPRM tools cover the easy third in the middle and leave the rest to spreadsheets.
We cover all six phases end to end, so nothing falls into the gap between assessment and the next audit - because there is no gap.
Same standards. 3.2× the coverage.
A US-built TPRM suite can be excellent at what it was designed for and still be wrong for UK public sector: the frameworks, the data-residency rules and the classification handling are simply different. The comparison below is an honest, line-by-line read of where that gap shows.
| Capability | Generic US TPRM | E2ERisk Supplier Assurance |
|---|---|---|
| UK CAF / NIS / GovAssure | Bolt-on content pack, partial | Native, audit-ready |
| Question depth | ~50 generic questions | SAQ v30 - 205 Q, 21 domains |
| AI evidence extraction | Single proprietary model | Multi-provider, incl. Azure OpenAI UK |
| Data residency | US SaaS, US data | UK-South / UK-West, customer-tenant |
| OFFICIAL-SENSITIVE | Not designed for it | Air-gap-ready, customer-managed keys |
| Outside-in scoring | Separate, expensive add-on | Built-in threat-centre scanner |
| Pricing | $50-250k, supplier-count tiers | Modular, public-sector-friendly, G-Cloud |
Where your supplier data can live is rarely a detail in UK public sector - it is often the deciding factor. Managed SaaS is the fastest start, but OFFICIAL-SENSITIVE and classified work need the platform inside your own boundary.
The three patterns below are one product, not three: the same platform from managed SaaS, through customer-tenant, to a fully air-gapped classified deployment.
Generic US TPRM tools are SaaS-only. None deploy on-prem. None go classified.
Framework support that is bolted on as a content pack always shows the seams. Ours is built into the assessment model, so mapping and evidence fall out of the work you already do - against the regimes a UK organisation is genuinely held to. This is framework mapping and assurance evidence, not a certification claim.
Get supplier assurance you can prove, defend, and explain to a regulator at 6am on a Saturday.
We map your current supplier portfolio against tiers in one session.
Hands-on access to SAQ v30, AI extraction and the supplier portal.
Procurement-ready. We sit on the right frameworks and route accordingly.