Quick answer

OptiTech loads the CRI Profile tier-aware: the impact assessment determines your tier, the applicable diagnostic statements load as requirements, and your existing controls cross-map onto them, with the NIST CSF function structure as the shared skeleton. Evidence collects continuously, and the Profile's maintained mappings mean the same control state renders as a Profile assessment, a 23 NYCRR 500 posture, or a DORA view, whichever the examiner or counterparty speaks.

Tiering as configuration, not negotiation

The impact questionnaire (services, interconnectedness, scale) computes your tier and documents the reasoning, so the scoping conversation with an examiner starts from a defensible record. Tier changes (growth, new critical services) arrive through the same scope-change mechanics as everything else: a reviewed delta of newly applicable diagnostic statements rather than a program rebuild.

One assessment, many audiences

The Profile's harmonization pays off operationally when each audience gets its view from the same data:

The financial-sector control depth

The Profile's heavier expectations run on the platform's standard machinery at financial-grade settings: access and privileged-account checks continuous against your identity provider, incident response with regulatory clocks per applicable regime, third-party risk through the supplier register with DORA-grade contract tracking, and resilience testing on a managed calendar. For technology vendors assessed in Profile terms by financial customers, the same setup answers the diligence without a bespoke project per counterparty.

See OptiTech in action

Get a personalized walkthrough of automated compliance for your team. No commitment required.