Most compliance programs don't migrate from a competitor; they migrate from ISO27001_controls_master_v7.xlsx. This guide takes the spreadsheet estate (control trackers, risk tables, supplier lists, policy folders) into OptiTech, where status is computed from evidence instead of typed into cells. The reasoning about why the spreadsheet fails is covered in eliminating the shared compliance spreadsheet; this is the how.
Step 1: Inventory the estate
Find the files that constitute your current program:
- The control tracker (usually one master Excel file with untracked cousins)
- The risk table
- The supplier or vendor list
- The asset register, if one exists
- The policy folder in SharePoint or Drive, with its
final_v3_REALversioning
For each, identify the most current version and its owner. Expect disagreement; that's the problem you're fixing.
Step 2: Prepare the CSV imports
OptiTech imports structured data as CSV. Clean up in the spreadsheet first, where editing is easy:
- Risks: one row per risk with name, description, likelihood, impact, owner, and current treatment. The import maps your scale to the risk register's scoring.
- Suppliers: name, contact, what they process (flag personal data for DPA tracking), and criticality. Lands in the supplier register.
- Assets: systems and services with owner and classification, for the asset inventory. Skip devices; the MDM integration enumerates them automatically.
In the Console, each register's Import button walks through column mapping and previews before committing.
Step 3: Set up the program around the data
- Create the workspace and run the scoping wizard; it generates the control set your spreadsheet was approximating.
- Run the imports from step 2.
- Upload policies. Pick the genuinely current version of each; the platform's version control takes over from here, and employees acknowledge the published versions.
- Assign control owners, mirroring whoever owned the spreadsheet tabs.
Step 4: Connect integrations and watch status become real
Connect identity, cloud, code, devices, and HR. The spreadsheet's "OK" cells get replaced by verified state, and the first sync usually surfaces drift the spreadsheet was hiding: MFA gaps, lingering accounts, an unencrypted volume. Those findings are the migration's first dividend.
Step 5: Retire the spreadsheet
The step teams skip, and shouldn't: make the old files read-only and add a header pointing to the workspace. As long as the spreadsheet accepts edits, it stays alive as a shadow system. Archive the files under your retention rules; they document the program's earlier period, and your auditor may still sample them for history predating the platform.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.