Your training platform is changing. Your evidence doesn't have to.
MetaCompliance acquired Junglemap in December 2025. If your program is moving platforms, this is the moment to establish a behavioral baseline you keep — one that reads from Microsoft 365 and survives the change.
What happened
On 10 December 2025, MetaCompliance acquired Junglemap, the Nordic security and compliance awareness provider that pioneered the NanoLearning method. Founded in 2002 with offices in Stockholm and Oslo, Junglemap serves around 1,200 customers across the Nordics and Benelux. The deal is MetaCompliance's third acquisition in three years and is backed by its investor, Keensight Capital.
Junglemap customers keep the NanoLearning approach and gain access to MetaCompliance's wider human risk management platform. This page sticks to what has been announced — it does not speculate about future product roadmaps.
Source: MetaCompliance company announcement · Verified July 2026
What a platform migration does to your evidence
A platform migration moves your content and your logins. It does not move your evidence. Your historical completion records, phishing-simulation results, risk scores and benchmarks live inside the platform you are leaving — and they were calculated by that platform, from its own signals.
When the program moves, the trend line that shows it was working can break at exactly the point an auditor is most likely to ask to see it: across the change. Continuity of evidence is the thing a migration quietly puts at risk, and it is hardest to reconstruct after the fact.
Peer-reviewed field research
29–55%
of the variation in phishing susceptibility is attributable to organizational-level factors, not individual ones.
Measured across 83,269 employees in 510 organizations, using their real responses to phishing campaigns.
Petrič, G., & Roer, K. (2022). The impact of formal and informal organizational norms on susceptibility to phishing. Telematics and Informatics, 67, 101766. Licensed under CC BY 4.0.
Behavioral measurement survives the migration
Praxis Navigator reads security behavior from your own Microsoft 365 tenant, not from your training vendor. That is the difference that matters during a migration. Connect before you move, and you establish a behavioral baseline from data you already generate — including months of history Microsoft already retains. The intervention changes; the measurement does not. Your baseline holds, and your trend line crosses the platform change intact.
What your training records evidence — and what they don't
A migration hands the new platform your completion history. Here is what that history does, and does not, satisfy when an assessor asks whether your measures actually work.
| What your reports show | What the regulation asks for | What closes the gap |
|---|---|---|
| Completion and phishing-simulation records from your training platform | NIS2 CIR Annex §8.1.3 — that awareness and training programs are assessed for effectiveness, not simply delivered | Behavioral evidence read from Microsoft 365 that survives the platform change |
| A risk score calculated inside the platform you are leaving | NIS2 CIR Annex §7 — that the effectiveness of risk-management measures is evaluated | An independent baseline and trend that does not reset when the vendor changes |
| Training records that stay behind in the departing platform | GDPR Art 32(1)(d) — a process for regularly testing, assessing and evaluating effectiveness | A continuous behavioral measure you own, read from your own tenant |
The clause does not ask whether you ran a program. It asks whether the program worked — and that is the evidence a migration puts at risk.
See what NIS2 asks you to evidenceThe Nordic context, and why the timing matters
Junglemap built its NanoLearning method for the Nordic market, and Praxis Security Labs shares those Nordic roots. That matters now because the regulatory ground is shifting underneath the change. Sweden's Cybersecurity Act — cybersäkerhetslagen, SFS 2025:1506 — brought NIS2 into national law and entered into force on 15 January 2026, with the Swedish civil-defense authority (MCF) issuing detailed regulations on security measures and management-body training.
Under NIS2, awareness and training programs have to be assessed for effectiveness — a behavioral question a set of completion records cannot answer on its own. A migration is the moment that question gets harder, and the moment an independent baseline is most valuable.
Source: New Cybersecurity Act enters into force in Sweden (energimyndigheten.se) · Verified July 2026
Questions Junglemap customers ask
What happened to Junglemap?
What does the acquisition mean for Junglemap customers?
Does Praxis Navigator work with MetaCompliance?
Will I lose my training history when I migrate?
Why establish a baseline before migrating?
Baseline before you migrate
A migration is the moment to establish a behavioral baseline you keep. Connect Microsoft 365 in 15 minutes and see the trend that crosses your platform change intact.
Start your free 30-day trialNo credit card. No commitment. Results in 15 minutes, or don't continue.
See the price — published, no sales call required.
Read what the regulation requires — NIS2 now asks whether your training works, not just that you ran it.