Start with an inventory, because everything else depends on it: systems, repositories, cloud accounts, data stores holding personal data, third parties with access, and the people who hold administrative credentials. Auditors probe the edges of the inventory, and so do attackers.
Then gather evidence rather than intentions. A policy document proves nothing; an access review with dates and names, a ticket showing a patch deployed within SLA, a log retention configuration screenshot and a completed onboarding checklist do. Decide where evidence lives before you start collecting it.
Finally, buy your bad news early. A gap assessment or penetration test before the audit converts findings into a remediation plan you control. The same findings discovered by the auditor become exceptions in a report your customers will read.
In short
- Inventory first — you cannot secure or evidence what you have not listed.
- Evidence beats policy: dated artefacts, not documents describing intent.
- Run your own gap assessment before the auditor does.
- Have a current penetration test report and retest record ready to attach.