Agentic compliance for Mid-Market

Several frameworks. One control set. One small team.

ISO 27001, NIS2, TISAX® and GDPR on one shared control model. Teddy maps every new framework onto what you already have and runs the routine with agents, so a lean team can run a multi-framework program.

One control setFor all your frameworks
Collected onceEvidence counts for every framework
Small teamSeveral frameworks in parallel
The mid-market problem

Four frameworks.
Four spreadsheets.

ISO 27001 for customers, NIS2 by law, TISAX® for automotive, GDPR for everyone. Mid-sized companies carry the same duties as corporations, with a compliance team of one or two people.

01A new framework

Teddy maps it onto your controls and lists only the new tasks.

02The same control in four places

Each control is kept once, with one status and one owner.

03The overall picture

One view shows where you stand on every framework.

04Four trackers, a consultant quote and a chatbot. Still no single answer.

The same control has three different statuses, a consultant quotes 40 days for NIS2, and a chatbot maps clauses without knowing your evidence. With Teddy, every framework runs on one control set, and each new one only adds what is really missing.

How it works

From four programs to one model

Model the company once, keep one control set and let each framework draw from it.

01 Teddy

Model the company once

Systems, suppliers, locations and subsidiaries are captured once. Teddy works out which frameworks and laws apply, and explains why.

Company modelAcme Inc.
NIS2 · important entityApplies
TISAX® · automotive customerRequired
ISO 27001 · certifiedIn place
02 Gap Audit Agent

One control set for every framework

Each control is defined once and mapped to every framework it serves. One status, one owner, one piece of evidence.

Shared controls4 frameworks
Controls in the shared set120
Used by more than one framework96
Conflicting statuses resolved3
03 Gap Audit Agent

Add a framework, see only what is missing

A new framework is mapped onto your controls in minutes. You get the gaps and the tasks, not a new project.

NIS2 addedToday
Covered by existing controls80%
Early warning within 24 hours (Art. 23)Missing
Teddy: Your ISO incident process has no 24-hour deadline. I drafted the early warning step for NIS2.
04 Evidence Agent

Agents run the routine once, for all frameworks

Evidence, policy reviews and supplier checks run on agents. Each result counts for every framework that needs it.

This weekAll frameworks
Microsoft 365 evidenceCollected
Supplier security checks18 of 30
Policy reviews due2
05 Teddy

One report for management

Status per framework, biggest risks, decisions needed and what was done, from one source.

Management reportOctober
Status per framework4
Decisions for management2
Tasks closed this month17
Never stuck

Ask Teddy. Agents do it. People back you up.

Ask what a new framework means for you and get an answer from your own controls. For migrations and audits, our compliance engineers lead the way.

1

Ask TeddyWhat does NIS2 add? Which control is shared? Answers from your own program, in seconds.

2

Agents do the workEvidence, supplier checks and policy reviews run once for every framework.

3

Our team backs you upCompliance engineers move you off SharePoint and Excel and join your audits.

TeddyAcme Inc.
Do we need to register for NIS2?
Yes. As a logistics provider of your size you are an important entity and must register with the authority.
  • Registration with the authorityOpen
  • Security measures under Art. 2180% covered
Shall I prepare the registration data and assign it to Anna?
Prepare registrationAsk our team
CEYour compliance engineer leads the migration and joins audits.
FAQ

Questions mid-market teams ask

How much does a second framework add?

Usually far less than a new project. Teddy shows exactly which of your controls already count and which tasks are really new.

How do we move away from SharePoint and Excel?

Our compliance engineers import your documents, controls and evidence and lead the cutover. Your documents can stay where they are.

What about subsidiaries and other countries?

Each entity is part of the same model. Teddy maps it to the laws of its country, such as the national NIS2 implementations, and shows the differences.

Do we keep our existing auditors?

Yes. They keep working with you as before, with better organised evidence.

Every framework. One control set. One small team.

See your frameworks mapped onto one model in the demo.

What changes with Teddy

Your next framework, without a new project

TypicalA new project

Every framework gets its own spreadsheet, consultant and timeline, even though most of the controls already exist.

With TeddyWithin weeks

Each new framework is mapped onto the controls you already run. You only work on what is really missing.

Why Teddy

Teddy was built by former CISOs and GRC managers who ran several frameworks with a small team. The second framework should never feel like the first. Most of the work is already done, it just sits in four spreadsheets.

Meet the founders →