C2 Risk
London-based third-party and supply-chain risk management platform (formerly branded C2 Cyber), whose RiskStore platform helps public and private sector organizations assess, remediate and monitor vendor cyber, privacy, project and ESG risk.
Visit Website ↗ + Add to CompareOverview
C2 Risk, founded in 2015 and headquartered in Shoreditch, London, builds a risk management platform originally launched as C2 Cyber and now operating under the C2 Risk brand. Its core product, RiskStore, is a third-party and supply-chain risk management platform that lets organizations assess, remediate and continuously monitor the security posture of vendors and partners, alongside adjacent modules covering privacy, project risk and ESG.
The company’s positioning centers on third-party risk, a category that has grown in priority as regulators and large enterprises push visibility requirements further down the supply chain, and RiskStore has been recognized at the UK’s National Cyber Awards. C2 Risk works with both public and private sector customers in the UK, including through G-Cloud, the UK government’s cloud services procurement framework, giving it a foothold in public-sector vendor risk assessment work.
C2 Risk is a small, UK-focused scaleup that has raised approximately $2 million to date from investors including Grow London, DivisionX Global and Winton Ventures. For CISOs and procurement/GRC teams managing growing vendor ecosystems, particularly in UK public sector and regulated industries, C2 Risk’s combined cyber, privacy and ESG third-party risk platform is a practical consolidation play; its small size and funding base limit its ability to compete with larger, better-capitalized third-party risk management vendors internationally.
Innovation Matrix Assessment
The platform has expanded from a cyber-focused third-party risk tool (C2 Cyber) into a broader RiskStore product covering privacy, project risk and ESG, but on a small team and roughly decade-long timeline, indicating steady rather than fast iteration.
A National Cyber Awards recognition, a UK G-Cloud procurement listing, and continued operation under a rebranded identity (C2 Risk) after a decade point to a stable, if small, operating business serving UK public and private sector buyers.
Total disclosed funding (~$2M) is modest relative to the company's decade of operation, and no recent funding round was found in available sources, suggesting slow growth momentum.
Bundling third-party cyber risk assessment with privacy, project risk and ESG modules in one platform is a useful consolidation for buyers but is not a technically novel approach relative to established third-party risk management vendors.
RiskStore's National Cyber Awards recognition is an independent third-party signal; beyond that, efficacy claims (e.g., supplier assessments completed 'in as little as 10 minutes') are company-stated marketing language not independently verified.
Third-party and supply-chain risk management is an active, regulator-driven priority for UK organizations, and public-sector procurement access via G-Cloud keeps C2 Risk positioned in a relevant buying channel.
Why CISOs Should Care
UK-focused CISOs and procurement/GRC teams needing to assess and monitor vendor cyber, privacy and ESG risk across a supply chain get a single platform and, through G-Cloud, a straightforward public-sector procurement path rather than assembling separate tools for each risk domain.
What Makes It Different
Combines third-party cyber risk, privacy, project risk and ESG assessment in one platform with direct UK public-sector procurement access (G-Cloud), rather than specializing narrowly in one risk domain.
The Matrix Verdict
45/100 — EMERGING / UNRANKED
A small, durable, UK-centric third-party risk management vendor with a decade of operating history and a real public-sector procurement channel; its modest funding and scale limit its competitiveness against larger, internationally focused TPRM platforms.
Editorial Note: Claims vs. Verified Findings
Funding total (~$2M from Grow London, DivisionX Global, Winton Ventures) and founding year (2015) are drawn from Crunchbase and Companies House-adjacent aggregator sources; the company's rebrand from 'C2 Cyber' to 'C2 Risk' is reflected on its current site and was used here to profile the current operating entity rather than the superseded name from the source list.
Sources
Alternatives to C2 Risk
Vanta
Continuous automated compliance monitoring platform that replaces manual audit evidence-gathering with live, integration-based control checks.
AuditBoard (rebranded Optro)
Connected-risk platform for audit, SOX, risk, and compliance, recently rebranded from AuditBoard to Optro under an AI-agent-driven repositioning.
Arcova
Cybersecurity advisory and managed services firm, rebranded from MorganFranklin Cyber, offering GRC, IAM, OT security, and a cloud-based…
Credo AI
AI governance platform that discovers, assesses, and continuously monitors enterprise AI systems and agents against regulations like the…
Level 6 Cyber
CISO ReviewedContinuous decision-intelligence platform (LISN) that replaces point-in-time security audits with a live digital twin of a CISO's program.
Drata
Continuous compliance automation platform, Vanta's closest direct competitor, covering SOC 2, ISO 27001/42001, HIPAA, PCI DSS, DORA, and…