Skip to content

C2 Risk

London-based third-party and supply-chain risk management platform (formerly branded C2 Cyber), whose RiskStore platform helps public and private sector organizations assess, remediate and monitor vendor cyber, privacy, project and ESG risk.

Visit Website ↗ + Add to Compare
45/100Emerging / Unranked

Overview

C2 Risk, founded in 2015 and headquartered in Shoreditch, London, builds a risk management platform originally launched as C2 Cyber and now operating under the C2 Risk brand. Its core product, RiskStore, is a third-party and supply-chain risk management platform that lets organizations assess, remediate and continuously monitor the security posture of vendors and partners, alongside adjacent modules covering privacy, project risk and ESG.

The company’s positioning centers on third-party risk, a category that has grown in priority as regulators and large enterprises push visibility requirements further down the supply chain, and RiskStore has been recognized at the UK’s National Cyber Awards. C2 Risk works with both public and private sector customers in the UK, including through G-Cloud, the UK government’s cloud services procurement framework, giving it a foothold in public-sector vendor risk assessment work.

C2 Risk is a small, UK-focused scaleup that has raised approximately $2 million to date from investors including Grow London, DivisionX Global and Winton Ventures. For CISOs and procurement/GRC teams managing growing vendor ecosystems, particularly in UK public sector and regulated industries, C2 Risk’s combined cyber, privacy and ESG third-party risk platform is a practical consolidation play; its small size and funding base limit its ability to compete with larger, better-capitalized third-party risk management vendors internationally.

Innovation Matrix Assessment

Innovation Velocity 4/10

The platform has expanded from a cyber-focused third-party risk tool (C2 Cyber) into a broader RiskStore product covering privacy, project risk and ESG, but on a small team and roughly decade-long timeline, indicating steady rather than fast iteration.

Operational Value 5/10

A National Cyber Awards recognition, a UK G-Cloud procurement listing, and continued operation under a rebranded identity (C2 Risk) after a decade point to a stable, if small, operating business serving UK public and private sector buyers.

Market Momentum 3/10

Total disclosed funding (~$2M) is modest relative to the company's decade of operation, and no recent funding round was found in available sources, suggesting slow growth momentum.

Category Disruption 4/10

Bundling third-party cyber risk assessment with privacy, project risk and ESG modules in one platform is a useful consolidation for buyers but is not a technically novel approach relative to established third-party risk management vendors.

Real-World Efficacy 5/10

RiskStore's National Cyber Awards recognition is an independent third-party signal; beyond that, efficacy claims (e.g., supplier assessments completed 'in as little as 10 minutes') are company-stated marketing language not independently verified.

Enduring Relevance 6/10

Third-party and supply-chain risk management is an active, regulator-driven priority for UK organizations, and public-sector procurement access via G-Cloud keeps C2 Risk positioned in a relevant buying channel.

Why CISOs Should Care

UK-focused CISOs and procurement/GRC teams needing to assess and monitor vendor cyber, privacy and ESG risk across a supply chain get a single platform and, through G-Cloud, a straightforward public-sector procurement path rather than assembling separate tools for each risk domain.

What Makes It Different

Combines third-party cyber risk, privacy, project risk and ESG assessment in one platform with direct UK public-sector procurement access (G-Cloud), rather than specializing narrowly in one risk domain.

The Matrix Verdict

45/100 — EMERGING / UNRANKED

A small, durable, UK-centric third-party risk management vendor with a decade of operating history and a real public-sector procurement channel; its modest funding and scale limit its competitiveness against larger, internationally focused TPRM platforms.

Editorial Note: Claims vs. Verified Findings

Funding total (~$2M from Grow London, DivisionX Global, Winton Ventures) and founding year (2015) are drawn from Crunchbase and Companies House-adjacent aggregator sources; the company's rebrand from 'C2 Cyber' to 'C2 Risk' is reflected on its current site and was used here to profile the current operating entity rather than the superseded name from the source list.

Sources