24 hours. 72 hours. One month. One system.

NIS2 requires an early warning to CERT-SE/MSB within 24 hours and a full notification within 72. Personal data breaches must be reported to IMY within 72 hours. We keep track of the clock for you.

Every framework you're covered by

OptiTech maps NIS2, DORA, GDPR, ISO 27001, and the EU AI Act in depth, built from Swedish legal texts and MSB regulations. Cross-mapping means one control satisfies requirements in several frameworks at once, so you do the work once and prove it everywhere.

10,000+

Swedish companies are covered by NIS2

5 frameworks

in depth, built from Swedish legal texts

Book a demo

From yearly project to real time

OptiTech takes you from point-in-time consultant reports to automated, continuous control monitoring. Evidence is collected around the clock from your systems, and your live status is always ready to show: to the board, to auditors, and to customers on your Trust Center.

Book a demo

Alerts you can act on

Controls are verified hourly through integrations with Microsoft 365, Entra ID, AWS, Fortnox, and BankID. When something drifts, you get a concrete action: fix it directly via API, or send a ready-made ticket to the right person, with instructions written by AI.

Hourly

your controls are verified automatically

1 click

from alert to remediation via API

Book a demo

Everything in one platform

From the first gap analysis to a completed audit: a built-in roadmap guides every step. Policies, risk register, training, vendor assessments, and MSB and IMY reporting flows are included, with partners for penetration tests and audits when you need them.

Book a demo

Three authorities, three mandates

  • MSB / CERT-SE

    NIS2 / the Swedish Cybersecurity Act

    National contact point and CSIRT function for NIS2.

  • PTS, Ei, and others

    NIS2, sector supervision

    Sector supervision for NIS2, assigned by industry.

  • IMY

    GDPR, Article 33

    Supervisory authority for personal data breaches under the GDPR.

How the statutory steps work

  1. 0–24hDraft

    Early warning to CERT-SE/MSB

    The system proposes classification and recipient automatically.

  2. 24–72hSubmitted

    Full incident notification

    Assessed severity and pre-filled fields, built from the incident record.

  3. Within 1 monthAcknowledged

    Final report

    Root-cause analysis and an action plan, compiled from the case log.

  4. 72hIn parallel

    Personal data? Notify IMY

    When the incident involves personal data with risk to individuals, a parallel IMY track starts: notification within 72 hours of discovery.

The facts, in numbers

  • 10 M€ / 2%

    Maximum sanction for essential entities under NIS2, Article 34.

  • 7 M€ / 1.4%

    Maximum sanction for important entities.

  • 24 / 72 / 30

    Hours, hours, days: the three statutory NIS2 windows.

  • Article 20

    Management's duty to approve and oversee risk-management measures.

When the clock is already running

An incident is detected outside office hours. Who starts the clock, and when?

The clock starts at awareness, not at the next working day. The system alerts the on-call contact, opens a timestamped case, and counts down toward the 24-hour window.

Escalation path

Detected 02:14On-call alertDraft: early warningCERT-SE/MSB < 24h

We cut the time from discovery to first notification from 14 hours to 25 minutes.

Dana SmithHead of Information Security, Nordic energy group

One obligation, three frameworks

Your organization's reporting obligations
  • NIS2

    24h / 72h / 1 mo

    CERT-SE/MSB and your sector authority

  • GDPR / IMY

    72h

    IMY, when individuals' rights are at risk

  • DORA

    4h / 72h / 30 days

    National competent authority, financial sector

Your questions, answered

  • The duty follows from entity type, essential or important under the Swedish Cybersecurity Act, not from company size in general. The scoping in the platform shows which category you belong to and which windows apply to you.
  • No. Only breaches that pose a risk to data subjects' rights and freedoms must be reported, within 72 hours of discovery. The decision not to report must be documented too, and the system does that automatically.
  • A first message to CERT-SE/MSB that a significant incident is under way, not a complete investigation. Among other things, it states whether the incident is suspected to be caused by unlawful acts and whether it may have cross-border effects.
  • MSB, with CERT-SE as the CSIRT function. Supervision is distributed by sector to authorities such as PTS and the Swedish Energy Markets Inspectorate, depending on your industry.

See your current process through the system's eyes

Request a review of your reporting process