From first gap analysis to the day the auditor arrives.
First, where you actually stand.
Every requirement of the standard, measured against how your company runs today: what would fail an audit, what it takes to fix, and who owns each fix.
Your risks, scored and ruled on.
The two documents every certification auditor opens first: your real risks scored before and after treatment, and a defensible ruling on all 93 controls. Stage 1 is largely a read of those two.
Policies your team will actually follow.
The full policy suite and operating registers, written around the way your company actually works. Short, specific, and owned by named people.
A rehearsal, and somebody else signs the real one.
I walk the whole system the way a certification body would, grade what I find, and we close it. What I will not do is sign that off as your Clause 9.2 internal audit, because nobody can audit their own work. That one is run by someone independent of me: a named person inside your company, who I train and hand the programme to, or an outside auditor if you would rather.
Leadership signs it, the auditor receives it.
Management review with your leadership, the closing engagement report, and a clean handover to the certification body of your choice. You walk into Stage 1 with the whole system already exercised once.