Drata teams tend to be the most automation-heavy of any platform's customers, and that's exactly what makes the move straightforward: almost everything in Drata is reachable through its API, so the export is scriptable rather than a clicking exercise. What Drata can't give you is the Nordic layer: NIS2 from the Swedish legal text, MSB and IMY reporting, Fortnox and BankID, and a vendor your public sector customers can approve.
Before you export
- Inventory your monitors. Drata's automated monitors are its core. List which ones actually gate your compliance (the rest are noise), so you can verify OptiTech's equivalent checks cover them at cutover.
- Check your audit window. If you're mid-period on a SOC 2 Type II, plan the cutover at a period boundary so one platform's evidence covers each period cleanly.
Map monitors to integrations
Upload the export through Settings, then Import. The assistant maps Drata controls to OptiTech's framework requirements, then shows a monitor-coverage view: which of your Drata monitors correspond to OptiTech's continuous checks, and which were manual in Drata but become automatic here (or the reverse, flagged as tasks).
What changes when you switch
- NIS2 from the source text: Swedish law and MSBFS instead of a translated mapping, with the MSB incident flow built in
- Monitor parity plus the Swedish checks: employee-register verification against Fortnox that no US platform runs
- API continuity: your compliance-as-code setup moves over instead of dying with the subscription
- EU data residency under EU ownership, with pricing published in SEK
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.