OptiTech offers plans to support you at every stage, from your first framework to a full compliance program across your supply chain. Prices are flat monthly fees, published openly, billed annually. All prices are in SEK and exclude VAT.
Plan overview
Compare OptiTech's Start, Professional, and Enterprise plans.
Managing compliance for clients?
For MSPs, accounting firms, and advisors, OptiTech offers a Partner plan with a multi-tenant console, volume discounts, and white-label options. Contact us for partner pricing.
| Plan feature | Start | Professional | Enterprise |
|---|---|---|---|
| Price | 2,995 kr/month | 7,995 kr/month | From 19,995 kr/month |
| Who it's for | 5–30 employees, first framework | 30–150 employees, several frameworks | 150+ employees and financial institutions |
| Frameworks | 1 | 3 | Unlimited |
| Integrations | 10 | All, including Swedish systems | All, including Swedish systems |
| Gap analysis | ✅ | ✅ | ✅ |
| Policies and documentation | 50+ Swedish templates | 50+ Swedish templates | 50+ Swedish templates |
| Incident reporting | MSB and IMY flows | MSB and IMY flows | MSB and IMY flows |
| Risk register | ✅ | ✅ | ✅ |
| Vendor risk management | — | ✅ | ✅ |
| DORA ICT register | — | — | ✅ |
| Trust Center | — | ✅ | ✅ |
| Security awareness training | — | ✅ | ✅ |
| AI copilot | — | ✅ | ✅ |
| Auto-remediation | — | ✅ | ✅ |
| Auditor portal | — | — | ✅ |
| SSO and SCIM | BankID login | BankID login | BankID, SSO, and SCIM |
| API and CLI | — | — | ✅ |
| Data residency | Sweden and EU | Sweden and EU | Sweden and EU |
| Support | Priority email | Dedicated customer success manager |
Plan features
This section describes the features listed in the Plan overview table.
Price
Every plan is a flat monthly fee, billed annually. There are no usage meters, no per-seat charges, and no hidden costs. The price you see is the price you pay:
- Start: 2,995 kr/month
- Professional: 7,995 kr/month
- Enterprise: from 19,995 kr/month, depending on size and requirements
All prices are in SEK and exclude VAT.
Who it's for
- Start: Companies with 5 to 30 employees getting compliant for the first time, often because a customer or a regulation now requires it.
- Professional: Companies with 30 to 150 employees managing several frameworks at once, with vendors to keep track of.
- Enterprise: Companies with 150+ employees, and regulated financial institutions that need the DORA package, auditor access, and dedicated support.
Frameworks
A framework is a regulation or standard you activate in OptiTech. The Nordic core is NIS2 (the Swedish Cybersecurity Act), DORA, GDPR, ISO 27001:2022, and the EU AI Act. Additional frameworks are available where your customers demand them: CRA, SOC 2, ISO 27701, ISO 22301, and TISAX.
- Start: 1 framework
- Professional: 3 frameworks
- Enterprise: unlimited frameworks
Controls are cross-mapped between frameworks, so one control can satisfy requirements in several frameworks at once. Adding a framework later starts from the controls you already have in place.
Integrations
Integrations connect OptiTech to your systems for continuous evidence collection: MFA coverage, offboarding within 24 hours, backup tests, encryption, and patch levels.
- Start: 10 integrations, including Microsoft 365, Entra ID, Google Workspace, AWS, Azure, and GitHub
- Professional and Enterprise: all integrations, including Fortnox, Visma, BankID, Kivra, and Swedish payroll systems
Gap analysis
All plans include the onboarding wizard: answer 20 questions about your industry, size, systems, and customers, and OptiTech maps which laws apply, which NIS2 category you fall into, and builds a prioritized action list.
Policies and documentation
All plans include 50+ Swedish policy templates (information security policy, incident response plan, continuity plan, and risk analysis following MSB methodology), version control with annual review reminders, and employee e-signing with read receipts.
Incident reporting
All plans include the guided incident flows:
- MSB flow (NIS2): early warning within 24 hours, incident report within 72 hours, and final report within one month, with pre-filled forms, deadline countdowns, on-call contact lists, and communication templates.
- IMY flow (GDPR): the corresponding 72-hour flow for personal data breaches.
Risk and vendors
All plans include a structured risk register: likelihood times impact scoring, links from risk to control to evidence, treatment plans, and management reports.
Professional and Enterprise add vendor risk management: a supplier register, automated security questionnaires, risk classification, and contract monitoring.
Trust Center
On Professional and Enterprise, you get a public security page (for example, security.example.com) where you show customers your certifications and compliance status. It shortens their security reviews and your sales cycles.
Training
Professional and Enterprise include security awareness training in Swedish, with onboarding and offboarding checklists connected to your HR system. NIS2 requires training for boards and management; see add-ons for the board training package.
AI copilot and auto-remediation
On Professional and Enterprise, the AI copilot answers questions grounded in Swedish legal texts and your own data, drafts policies from your real environment, and answers incoming security questionnaires. Auto-remediation fixes failing controls directly via API or creates a ready-made ticket for the right person.
Enterprise features
The Enterprise plan adds:
- DORA package: an ICT contract register and reporting ready for supervisory review
- Auditor portal: read-only access for auditors and supervisory authorities, with a complete time-stamped evidence chain and PDF/CSV export
- SSO and SCIM: centralized login and user provisioning alongside BankID
- API and CLI: run compliance checks in CI/CD and block deploys that break controls
- Custom onboarding and a dedicated customer success manager
Data residency
All customer data is stored in Swedish and EU data centers, under EU ownership, on every plan. We publish our full list of subprocessors and maintain our own ISO 27001 certification.
Support
Support level by plan:
- Start: Email support
- Professional: Priority email support
- Enterprise: Dedicated customer success manager
See Support for details.
Add-ons
Beyond the plans, you can add:
| Add-on | Price | Description |
|---|---|---|
| Onboarding packages | From 25,000 kr | Guided setup with our team, scoped to your environment and frameworks |
| NIS2 board training | 15,000 kr fixed price | Covers the governance and personal liability requirements for boards and management |
| Phishing simulation | 990 kr/month | Recurring simulated phishing campaigns with reporting |
| vCISO hours | Via partner network | Hands-on security expertise when you need more than the platform |
FAQs
- —How does billing work?
- Plans are flat monthly fees billed annually. All prices are in SEK and exclude VAT. There are no usage meters or per-seat charges.
- —What counts as a framework?
- A regulation or standard you activate: NIS2 (the Swedish Cybersecurity Act), DORA, GDPR, ISO 27001:2022, or the EU AI Act, plus additional frameworks like CRA, SOC 2, ISO 27701, ISO 22301, and TISAX. Your plan determines how many you can have active at the same time.
- —Can I switch plans or add frameworks later?
- Yes. You can upgrade at any time, and everything you've done carries over. Because controls are cross-mapped, a new framework starts from the controls you already have in place.
- —Do you offer a free trial?
- Start with the free scoping test: answer 20 questions and get a report showing which laws apply to your business and a prioritized gap list. Book a free gap analysis to go deeper.
- —Where is my data stored?
- In Swedish and EU data centers, under EU ownership, on every plan. AI features run on EU-hosted models, and no customer data is sent to US providers.
- —Is there a plan for consultants and MSPs?
- Yes. The Partner plan gives IT service providers, accounting firms, and advisors a multi-tenant console with volume discounts and white-label options. Contact us for partner pricing.
- —How many team members can I add?
- There's no per-seat pricing. Invite as many team members as you need on every plan.
- —What happens if we have an incident?
- The incident flows are included on all plans. OptiTech guides you through the MSB deadlines (24 hours, 72 hours, one month) or the IMY 72-hour flow with pre-filled forms and communication templates.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.