OptiTech documentation

OptiTech is compliance automation for the Nordics.

Getting started

OptiTech automates regulatory compliance for Nordic businesses. Run a gap analysis, generate your documentation, connect your systems for continuous evidence collection, and report incidents to Swedish authorities directly from the platform.

Frameworks

OptiTech covers the regulations that matter for Nordic businesses. Controls are cross-mapped between frameworks, so evidence you collect once counts everywhere it applies. The Nordic core is built from the source texts; the rest cover what your customers and auditors most often ask for. For who each framework applies to and what it costs to ignore, see the framework catalog.

  • NIS2 and the Swedish Cybersecurity Act

    Built from the Swedish legal text and MSB regulations (MSBFS), with automatic scoping, controls, and the full incident reporting flow.

  • DORA

    For financial institutions and their ICT providers: controls, testing requirements, and an ICT contract register ready for supervisory review.

  • GDPR

    Records of processing, breach reporting to IMY within 72 hours, and data protection controls mapped to your real systems.

  • ISO 27001:2022

    The full control catalog with policy templates, continuous evidence collection, and a read-only auditor portal for certification audits.

  • EU AI Act

    Scoping for high-risk AI systems, plus the documentation and governance requirements that phase in through 2027.

  • CRA

    Security requirements for products with digital elements sold in the EU, phasing in through 2027. The next wave after NIS2 for product companies.

  • SOC 2

    Show customers you meet the leading standard for managing and protecting customer data, common in B2B deals with US buyers.

  • ISO 27701

    Extend your ISO 27001 program with privacy controls that align with GDPR and other privacy regulations.

  • ISO 22301

    A structured, auditable business continuity management system, covering the continuity requirements NIS2 also demands.

  • TISAX

    The automotive industry's information security standard, required by major European OEMs and their Nordic supply chains.

Platform capabilities

  • Gap analysis

    Answer 20 questions about your industry, size, systems, and customers. OptiTech maps which laws apply, which NIS2 category you fall into, and builds a prioritized action list.

  • Policies and documentation

    50+ Swedish templates, AI-generated drafts based on your real environment, version control with review cycles, and employee e-signing with read receipts.

  • Continuous evidence collection

    Integrations with Microsoft 365, Entra ID, Google Workspace, AWS, Azure, GitHub, and Swedish systems like Fortnox, Visma, BankID, and Kivra verify controls around the clock: MFA coverage, offboarding, backups, encryption, and patch levels.

  • Incident reporting

    A guided MSB flow with early warning in 24 hours, incident report in 72 hours, and final report within one month. Pre-filled forms, deadline countdowns, and communication templates. The matching IMY flow handles personal data breaches.

  • Vendor risk management

    Supplier register, automated security questionnaires, risk classification, and contract monitoring, including the DORA ICT register.

  • AI copilot

    Ask questions in Swedish and get answers grounded in the legal text and your own data, with citations. Draft policies and answer incoming security questionnaires in a fraction of the time.

Plans and support

OptiTech publishes its prices openly: see plans for what each tier includes, or pricing for current rates. If you need help, support explains the options on each plan, and our team can walk you through a free gap analysis.

Need help?

Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.