Vanta is a capable platform for US-framework compliance. Teams in the Nordics switch to OptiTech for what Vanta doesn't do: NIS2 built from the Swedish Cybersecurity Act and MSB regulations rather than a generic mapping, incident reporting to MSB and IMY with real deadlines and forms, Swedish integrations like Fortnox and BankID, EU data residency under EU ownership, and public pricing in SEK instead of a sales call.
This guide moves your program without losing what you built.
Before you start
- Keep your Vanta subscription active through the migration; you want overlap, not a gap.
- Inventory what you have in Vanta: active frameworks, connected integrations, policy documents, and any audit in flight. Mid-audit is a bad time to switch; migrate after the report lands.
- Read the general playbook in switching platforms without losing audit history.
Step 1: Export from Vanta
Collect from Vanta while everything still works:
- Policies: download every policy with its approval state. Get source files where possible, not just PDFs.
- Evidence archive: export the evidence attached to controls, plus any uploaded documents (pentest reports, review records).
- Personnel data: the people list with training and policy acceptance status.
- Vendor list: your vendor inventory with security review status.
- Audit artifacts: completed SOC 2 or ISO reports and their evidence packages.
Step 2: Set up the OptiTech workspace
- Create your workspace and run the scoping wizard; it rebuilds your applicable-framework picture from your actual situation, which often differs from what was configured in Vanta years ago.
- Activate your frameworks. SOC 2 and ISO 27001 map directly; cross-mapping means your control set unifies instead of duplicating per framework.
- Import structured data: vendors into the supplier register and personnel baseline via CSV.
- Upload policies with their version history noted; publication and acknowledgment start fresh in OptiTech.
Step 3: Reconnect integrations
Connect the same sources Vanta monitored, plus the ones it couldn't:
- Microsoft Entra ID or Google Workspace
- AWS and Azure
- GitHub or GitLab, Jira, Slack
- Intune or Jamf, CrowdStrike or Defender
- New ground: Fortnox or Visma for employment-driven checks, and BankID for signing
Evidence collection starts immediately on connection, so your new trail begins before you disconnect anything.
Step 4: Cut over and archive
- Run both platforms in parallel for two to four weeks, comparing check results and tuning routing and severity.
- Point your team's daily work (findings, reviews, questionnaires) at OptiTech.
- Export a final full archive from Vanta and store it under your document retention rules; auditors can ask about pre-migration periods for years.
- Downgrade or cancel Vanta once your first monitoring cycle in OptiTech has run clean.
What changes operationally
- Trust Center: rebuild your public page in OptiTech's Trust Center and update the URL wherever it's published.
- Questionnaires: inbound questionnaires now run through the AI-assisted workflow against your live control data.
- Incidents: your incident process gains the 24-hour MSB early warning flow; rehearse it once so the first real incident isn't the first run.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.