---
id: KB-IC-004
url: https://app.codecontract.io/help/reports-and-quality/getting-ready-for-a-certification
idioma: en
categoria: informes-y-calidad
subcategoria: calidad
audiencia: usuario
nivel: basico
actualizado: 2026-08-13
tambienEn: [es]
relacionados: [KB-IC-002, KB-CF-003, KB-IC-013]
citadoPor: [KB-IC-005]
---

# Getting ready for a certification

_The six months before, and what can be built meanwhile._

**Responde a:** prepare for an iso certification · first certification audit what do i need · documentation to get certified · how long does certification take

Getting certified for the first time frightens people more than it costs, for one specific reason: they think everything has to be documented. It does not. What is checked is that you do what you say you do, and that it can be proven with dates.

## What actually gets looked at

| What the auditor wants to see | What they do not care about |
| --- | --- |
| That there is a written process and it is followed | That the document looks nice |
| That records are dated and were not filled in afterwards | That there are many records |
| That you detect failures and close them | That there are no failures |
| That people know what they have to do | That they know it by heart |

> [!IMPORTANT]
> What fails most is not missing documents: it is records all filled in the week before the audit. A perfect log in the same handwriting and the same ink across twelve months is spotted by any experienced auditor, and from then on they distrust everything else.

## What to build in the six months before

1. **The records filled in continuously** — Certified periodically, so their date does not depend on you.
2. **Supplier control** — With expiries marked, which is what shows monitoring rather than an annual glance.
3. **The non-conformity register** — Even if nearly empty. An empty one is suspicious; one with three detected and closed is evidence in your favour.
4. **Training for whoever does each thing** — With its date and its expiry.

> [!WARNING]
> Do not build processes you will not follow just to look good at the audit. A written procedure nobody follows is worse than none: the auditor asks the people, not only reads the paperwork.

> [!NOTE]
> The first certification costs; renewals cost much less. If what you build genuinely works, the second audit is showing what is already there.

**Do I need to document everything?**

No. What the standard requires and what you genuinely do; documenting what you do not do only creates problems.

**Are digital records acceptable?**

Yes, and with a trusted date they carry more weight than paper.

**How long does it take?**

It depends on the standard and your starting point; ask your certification body before fixing a date.

## Ejemplos

**A company prepares its first certification by filling in twelve months of records in two weeks.**

- Stops
- Starts certifying the records month by month from now
- Delays the audit by six months

→ Arrives with credible records instead of twelve months in the same ink.

**A month remains before the certification audit and six months of evidence is missing.**

- Checks which controls have no record
- Prioritises what depends on third parties
- Starts recording what is done daily from now

→ The month goes on closing specific gaps rather than generating paper after the fact.

**Certification is prepared by creating documents for the occasion.**

- Records what is actually done

→ The evidence describes the real company.

**Certification passes and the following year starts from zero.**

- Keeps the record current through the year

→ Renewal is a review.

**The auditor asks for evidence of a control and is shown the manual.**

- Shows the log of real operations

→ The control moves from assertion to evidence.

**Nobody knows which controls each record covers.**

- Notes which control each one answers

→ Preparation stops being a search.
