Audit-readiness checklist
0%Answer the scoping questions so OptiTech tells you which frameworks apply and where your gaps are. This is the baseline everything else builds on.
Turn on NIS2, DORA, GDPR, ISO 27001, or the EU AI Act as they apply to you. Controls are cross-mapped, so work done for one carries over to the others.
A control without an owner is a control that drifts. Give each one a responsible person and a due date.
Wire up Microsoft 365, Entra ID, cloud, GitHub, and Swedish systems so evidence is collected automatically instead of gathered by hand before the audit.
Use the AI copilot to draft policies from the legal text, then review and publish them with an approval trail.
Confirm the NIS2 24-hour, 72-hour, and one-month flows to MSB, and the GDPR 72-hour flow to IMY, are ready with owners and templates.
Add the suppliers the law makes you responsible for, and send them the questionnaires you need for supply-chain controls.
NIS2 requires active governance. Set up the one-click board report so you can show it on demand.
Work down the findings list and resolve any drift alerts so your posture is green before the auditor looks.
Generate the audit export so an assessor can review your controls, evidence, and framework status in one place.
Run your gap analysis
Start with the scoping questions. OptiTech uses your answers to determine which frameworks apply and produces a gap analysis that shows, control by control, where you stand today. Everything else on this checklist works against that baseline.
Keep reading: Why OptiTech?
Activate the frameworks that apply
Turn on the frameworks that apply to your organization. Controls are cross-mapped between NIS2, DORA, GDPR, ISO 27001, and the EU AI Act, so the work you do for one framework satisfies the overlapping controls in the others.
Keep reading: Compliance frameworks
Connect integrations for continuous evidence
Connect the systems where your evidence already lives — Microsoft 365, Entra ID, Google Workspace, AWS, Azure, GitHub, and Swedish systems like Fortnox, Visma, and BankID. OptiTech then verifies controls around the clock instead of you gathering screenshots before the audit.
Keep reading: Connecting OptiTech to your stack
Document your policies and procedures
Draft the policies each framework requires with the AI copilot, grounded in the legal text and your own data. Every draft goes through human review, and published documents keep an approval trail.
Keep reading: Get started with the AI copilot
Set up incident reporting
Make sure the incident flows are ready before you need them: the NIS2 early warning within 24 hours, incident report within 72 hours, and final report within one month to MSB, and the GDPR 72-hour flow to IMY. Each comes with pre-filled forms, deadline countdowns, and communication templates.
Export your audit package
When you're ready, generate the audit export. It gives an assessor your controls, evidence, and per-framework status in one place, so the review is a read-through rather than a scramble.
Keep reading: Tour the OptiTech Console
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.