Preparing for your first audit? Here’s what you should consider.
- May 27
- 4 min read
Updated: Jun 28
Many founders are surprised to learn that an initial certification audit requires far more than a QMS sitting on a shared drive. For those navigating ISO 13485 and/or MDR certification for the first time, the gap between “we have an SOP and a template for that” and “we can show the auditor evidence that the SOP is being followed” is routinely underestimated. This post gives a clear overview of what needs to be in place before your first audit and where teams most commonly run into trouble.
The QMS
First, your QMS documentation, including the Quality Manual, SOPs and templates, must be complete and, equally important, adapted to your company. The purpose of the audit is to verify that your QMS is genuinely in use and not merely documented. If your processes are misaligned with how the business actually operates, that becomes impossible to demonstrate.
If you have purchased or downloaded a standard SOP package, take time to sense-check it against your actual operations. A pure software medical device company, for example, has no need for a packaging procedure. More broadly, your SOPs need to reflect how your team genuinely works. When processes are too far removed from day-to-day reality, people stop using them and the system loses its value.
The result is often an informal “shadow” QMS running in parallel, which is a clear red flag for auditors. A far better approach is to involve the people who own each process in writing or adapting it. They will be more comfortable using the process and explaining it during an audit.
Second, resist the urge to treat audit preparation as a documentation sprint. This is a particularly common temptation for software companies accustomed to working in agile environments. The idea of “we have the QMS in place, we can fill in the records quickly before the audit” rarely works and I would strongly advise against it. Auditors are trained to distinguish a living quality management system from one that has been hastily assembled in the weeks before the audit. Meeting records, corrective actions, training logs, supplier evaluations and objective-tracking all tell that story. A genuine QMS is difficult to fabricate. Attempting to pass the audit with one that is not truly operational is unlikely to succeed.
A Realistic Timeline
For companies targeting an initial certification audit, the typical lead time from “we’ve drafted the QMS” to “we’re audit-ready” is six to nine months for ISO 13485. For MDR certification, the timeline depends heavily on the maturity of your technical documentation.
Months 1–2: Finalise documentation, formalise organizational chart and job descriptions. Train staff.
Months 3–4 (or longer for MDR): Run the system and generate records including quality objectives, technical documentation, supplier evaluations. In parallel, begin preparations with your selected Notified Body for the first audit.
Month 5: Conduct the first internal audit. Take findings seriously and open CAPAs for each one. This will be reviewed during the certification audit.
Month 6: Conduct the first management review.
Month 7+: First Notified Body audit 😊
The Pre-Audit Checklist
Use the following as a minimum requirements checklist when preparing for your initial certification audit. Note that all items must be in place – and actively used – at the same time.
| Requirement | What the Notified Body expects to see |
1 | QMS documentation complete | All SOPs, templates and the Quality Manual in place, signed and approved. The documents need to be adapted to your company! |
2 | Job descriptions written & signed | All relevant roles must have a documented and signed job description. |
3 | Organisational chart available | PRRC (for MDR) and Management Representative clearly identified. |
4 | Training records complete | Evidence that every employee has been trained according to their job description – documented and signed off. |
5 | First internal audit completed | Conducted, documented, and any findings addressed. Engaging an independent consultant for this step will give you valuable feedback to your audit readiness. |
6 | First management review completed | Meeting held, minutes recorded, inputs and outputs documented. |
7 | Quality objectives defined | Measurable objectives documented and communicated to the team. |
8 | Supplier qualification complete | Critical suppliers qualified and listed in an Approved Supplier List. |
9 | Working QMS – min. 6 months | Some Notified Bodies accept 4 months. The system must be demonstrably active, not just on paper. And no – it is not sufficient if just the quality manager knows the SOPs. |
10 | EUDAMED actor registration | Actor registration in EUDAMED must be completed and a number assigned so that the Notified Body can actually start the review process (they need to log the number). Note: If your company is based in Switzerland, you will also have to start the Swissdamed registration in parallel. |
You can also download the pre-audit checklist here.
Final words
The first Notified Body audit is not a documentation exam. It is an assessment of whether your organisation can operate a quality system that consistently produces safe and compliant medical devices. So, in essence, you absolutely require team buy-in and a living quality management system.
And if you’re looking for someone to review your QMS — you know where to find me 😊
As a start-up coach in medtech and with expertise in regulatory affairs, I’m frequently asked the same questions. So, I'm turning the most common ones into a series of posts.
What’s your burning question at the moment? Let me know... it might become the next post!
Nila



Comments