/Integrations & tooling/Integrations (3rd party)/Migrate from another platform/Drata

Migrate from Drata to OptiTech

Move your compliance program from Drata with monitoring continuity

Drata automates US-framework compliance well. What it doesn't have is the Nordic layer: NIS2 as codified in the Swedish Cybersecurity Act, the MSB and IMY incident flows, Fortnox, Visma, and BankID integrations, and EU data residency under EU ownership. If those started mattering to your business, this guide moves your program over without losing your history or your monitoring continuity.

Before you start

  • Time the switch between audits, not during one.
  • Keep Drata active through the parallel period.
  • Skim the platform-switch playbook for the principles; this guide is the Drata-specific application.

Step 1: Export from Drata

  1. Policies: download all policies with approval metadata, source formats where available.
  2. Evidence: export control evidence and the document library (pentests, review records, certificates).
  3. Personnel: the people register with policy acceptance and training completion.
  4. Vendors: your vendor list with risk levels and review dates.
  5. Reports: completed audit reports and their evidence packages.

Step 2: Rebuild the program in OptiTech

  1. Create the workspace and let the scoping wizard re-derive your obligations; NIS2 scope in particular is worth a fresh look, since Drata setups rarely modeled it properly.
  2. Activate frameworks: your existing SOC 2 and ISO 27001 plus whatever the scoping adds. One cross-mapped control set serves them all.
  3. Import vendors and personnel baselines from CSV into the supplier register and people records.
  4. Upload policies; new acknowledgment rounds start in OptiTech, optionally BankID-signed for the documents that warrant it.

Step 3: Reconnect integrations

The standard set: Entra ID or Google Workspace, AWS/Azure, GitHub/GitLab, Jira, Slack/Teams, Intune/Jamf, and endpoint protection. Then the ones Drata never offered: Fortnox or Visma so offboarding checks run against employment truth.

Monitoring starts on connection; run two to four weeks in parallel and compare results before you disconnect anything.

Step 4: Cut over and archive

  1. Move daily work (finding triage, reviews, questionnaire answering) to OptiTech.
  2. Take a final full Drata export into your document archive; it remains your proof for the covered period.
  3. Rebuild your public security page on the Trust Center and update published links.
  4. Cancel Drata after your first clean monitoring cycle.

The operational deltas you gain

Need help?

Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.

Was this page helpful?