ISO 27001, NIS2, TISAX® and GDPR on one shared control model. Teddy maps every new framework onto what you already have and runs the routine with agents, so a lean team can run a multi-framework program.

ISO 27001 for customers, NIS2 by law, TISAX® for automotive, GDPR for everyone. Mid-sized companies carry the same duties as corporations, with a compliance team of one or two people.
Teddy maps it onto your controls and lists only the new tasks.
Each control is kept once, with one status and one owner.
One view shows where you stand on every framework.
The same control has three different statuses, a consultant quotes 40 days for NIS2, and a chatbot maps clauses without knowing your evidence. With Teddy, every framework runs on one control set, and each new one only adds what is really missing.
Model the company once, keep one control set and let each framework draw from it.
Systems, suppliers, locations and subsidiaries are captured once. Teddy works out which frameworks and laws apply, and explains why.
Each control is defined once and mapped to every framework it serves. One status, one owner, one piece of evidence.
A new framework is mapped onto your controls in minutes. You get the gaps and the tasks, not a new project.
Evidence, policy reviews and supplier checks run on agents. Each result counts for every framework that needs it.
Status per framework, biggest risks, decisions needed and what was done, from one source.
Ask what a new framework means for you and get an answer from your own controls. For migrations and audits, our compliance engineers lead the way.
Ask TeddyWhat does NIS2 add? Which control is shared? Answers from your own program, in seconds.
Agents do the workEvidence, supplier checks and policy reviews run once for every framework.
Our team backs you upCompliance engineers move you off SharePoint and Excel and join your audits.
Usually far less than a new project. Teddy shows exactly which of your controls already count and which tasks are really new.
Our compliance engineers import your documents, controls and evidence and lead the cutover. Your documents can stay where they are.
Each entity is part of the same model. Teddy maps it to the laws of its country, such as the national NIS2 implementations, and shows the differences.
Yes. They keep working with you as before, with better organised evidence.
See your frameworks mapped onto one model in the demo.
Every framework gets its own spreadsheet, consultant and timeline, even though most of the controls already exist.
Each new framework is mapped onto the controls you already run. You only work on what is really missing.
Teddy was built by former CISOs and GRC managers who ran several frameworks with a small team. The second framework should never feel like the first. Most of the work is already done, it just sits in four spreadsheets.
Meet the founders →