Quick answer
Pick a platform built on cross-mapping: one control satisfies requirements in several frameworks at once. In OptiTech, the control "MFA enforced for all users" simultaneously feeds ISO 27001, NIS2, SOC 2, and DORA requirements, with the same automated evidence behind all of them. When a new framework arrives, you activate it and see immediately how much you've already covered, typically 60 to 80 percent if you started with ISO 27001.
The regulatory waves are predictable
The frameworks arrive in a known order for most Nordic companies:
- ISO 27001 or SOC 2 first, because enterprise customers demand it.
- NIS2 when you or your customers land in scope of the Cybersecurity Act.
- DORA if you sell to banks or insurers, since they must put requirements on ICT suppliers.
- The EU AI Act in 2026 to 2027 if you build or embed AI in higher-risk categories.
- CRA if you ship products with digital elements.
Each wave triggers requirements that overlap heavily with the last one. Access control, incident management, backup, logging, and supplier management appear in all of them with different numbering. Without cross-mapping, you rebuild the same program for each framework and maintain them in parallel.
What cross-mapping looks like in practice
- The requirements catalog shows each control with the framework requirements it satisfies: many-to-many, not one-to-one.
- Evidence attaches to the control once, and every mapped framework sees it. See does adding a second framework double your work.
- Activating a new framework runs a delta analysis: covered requirements go green, and you get a gap list for what's genuinely new (for DORA, that's mostly the ICT contract register and resilience testing; for the AI Act, risk classification of your AI systems).
Plan sizing as you grow
Start covers one framework, which fits the first year. Professional covers three frameworks and adds supplier risk management and the Trust Center, which is where most scale-ups live. Enterprise removes the framework cap and adds the DORA package and auditor portal. The point of transparent pricing is that you can see the upgrade path before you need it.

Get a personalized walkthrough of automated compliance for your team. No commitment required.