Quick answer

Create an account, name your workspace, and run the onboarding wizard: about 20 questions covering your industry, size, systems, customers, and role in the supply chain. From your answers, OptiTech determines which regulations apply (and for NIS2, whether you're likely an essential or important entity), activates the right framework, and generates a prioritized action list. From signup to a scoped program takes under an hour.

What the wizard asks and why

The questions aren't a survey; each one drives scoping logic:

  • Industry and services determine NIS2 sector applicability and whether DORA's supplier obligations reach you.
  • Company size affects entity classification and proportionality of measures.
  • Customer types (banks? municipalities? critical-sector companies?) reveal supply-chain obligations that apply to you indirectly.
  • Systems in use (Microsoft 365 or Google, which cloud, which MDM) prepare the right integration setup.
  • AI usage flags EU AI Act exposure early; see AI Act preparation.

What you get immediately

  1. A scoping verdict: which laws and frameworks apply, with reasoning you can show your board.
  2. A compliance score: your starting point, measured against the applicable requirement set.
  3. A prioritized gap list: what to fix first, ordered by risk and effort, with suggested owners.
  4. Draft policies from templates matched to your environment, ready for review (never auto-published; see the AI guardrails).

The first week after setup

Connect your first integrations (identity provider and cloud first, they feed the most checks), assign control owners so findings route to the right teams, invite your colleagues, and schedule the management training that NIS2 requires. Teams that follow that order are operational, with automated evidence flowing, inside a week. If you're evaluating rather than committing, start in a sandbox instead.

See OptiTech in action

Get a personalized walkthrough of automated compliance for your team. No commitment required.