OptiTech is compliance automation for the Nordics.
Getting started
OptiTech automates regulatory compliance for Nordic businesses. Run a gap analysis, generate your documentation, connect your systems for continuous evidence collection, and report incidents to Swedish authorities directly from the platform.
OptiTech covers the regulations that matter for Nordic businesses. Controls are cross-mapped between frameworks, so evidence you collect once counts everywhere it applies. The Nordic core is built from the source texts; the rest cover what your customers and auditors most often ask for. For who each framework applies to and what it costs to ignore, see the framework catalog.
NIS2 and the Swedish Cybersecurity Act
Built from the Swedish legal text and MSB regulations (MSBFS), with automatic scoping, controls, and the full incident reporting flow.
DORA
For financial institutions and their ICT providers: controls, testing requirements, and an ICT contract register ready for supervisory review.
GDPR
Records of processing, breach reporting to IMY within 72 hours, and data protection controls mapped to your real systems.
ISO 27001:2022
The full control catalog with policy templates, continuous evidence collection, and a read-only auditor portal for certification audits.
EU AI Act
Scoping for high-risk AI systems, plus the documentation and governance requirements that phase in through 2027.
CRA
Security requirements for products with digital elements sold in the EU, phasing in through 2027. The next wave after NIS2 for product companies.
SOC 2
Show customers you meet the leading standard for managing and protecting customer data, common in B2B deals with US buyers.
ISO 27701
Extend your ISO 27001 program with privacy controls that align with GDPR and other privacy regulations.
ISO 22301
A structured, auditable business continuity management system, covering the continuity requirements NIS2 also demands.
TISAX
The automotive industry's information security standard, required by major European OEMs and their Nordic supply chains.
Platform capabilities
Gap analysis
Answer 20 questions about your industry, size, systems, and customers. OptiTech maps which laws apply, which NIS2 category you fall into, and builds a prioritized action list.
Policies and documentation
50+ Swedish templates, AI-generated drafts based on your real environment, version control with review cycles, and employee e-signing with read receipts.
Continuous evidence collection
Integrations with Microsoft 365, Entra ID, Google Workspace, AWS, Azure, GitHub, and Swedish systems like Fortnox, Visma, BankID, and Kivra verify controls around the clock: MFA coverage, offboarding, backups, encryption, and patch levels.
Incident reporting
A guided MSB flow with early warning in 24 hours, incident report in 72 hours, and final report within one month. Pre-filled forms, deadline countdowns, and communication templates. The matching IMY flow handles personal data breaches.
Vendor risk management
Supplier register, automated security questionnaires, risk classification, and contract monitoring, including the DORA ICT register.
AI copilot
Ask questions in Swedish and get answers grounded in the legal text and your own data, with citations. Draft policies and answer incoming security questionnaires in a fraction of the time.
Plans and support
OptiTech publishes its prices openly: see plans for what each tier includes, or pricing for current rates. If you need help, support explains the options on each plan, and our team can walk you through a free gap analysis.
Need help?
Join our Discord Server to ask questions or see what others are doing with OptiTech. For paid plan support options, see Support.