This guide helps you choose the best migration method based on where your compliance program lives today, how much history you need to keep, and how fast you need to be up and running.
Migration methods
| Method | Best For | Program size | Effort | Key benefit |
|---|---|---|---|---|
| Fresh start with gap analysis | First-time compliance, small programs | Starting out | Low | Fastest path, nothing to carry over |
| Document import | Policies and plans in Word or PDF | Any size | Low | OptiTech maps documents to controls |
| Spreadsheet import | Risk registers and control matrices in Excel | Any size | Medium | Keeps your risk and control history |
| Platform export import | Moving from another compliance platform | Any size | Medium | Controls and evidence mapped on import |
| Guided onboarding | Complex programs, groups, regulated entities | Large | Low for you | Our team runs the migration with you |
Quick guidance
If your program lives in spreadsheets and documents, start with Spreadsheets and documents, or load individual registers straight from a file with CSV import. If you're leaving another platform, pick your source below; controls and evidence map on import. If you're starting from scratch, skip migration entirely and run the gap analysis.
Source-specific guides
For step-by-step instructions tailored to where your program lives today, see Spreadsheets and documents, SharePoint and Teams, Consultant deliverables, Swedish GDPR tools, Vanta, Drata, Secureframe, Sprinto, Cyberday, open source GRC tools, enterprise GRC tools, or another OptiTech organization.
What carries over
Whatever the source, the same things map into OptiTech:
- Policies and plans: imported documents keep their content and get version control, review cycles, and e-signing
- Controls: mapped against OptiTech's framework requirements, with cross-mapping applied automatically
- Risk register: risks, scores, and treatment plans, linked to the controls that mitigate them
- Vendor register: suppliers, classifications, and contract dates
- Evidence history: imported as historical records, clearly separated from the continuously collected evidence that starts at cutover
What doesn't need migrating
Evidence collection starts fresh from your integrations at cutover, which is the point: within days, your controls are verified by live checks instead of imported screenshots. Old evidence stays available for audits that cover the earlier period.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.