If you deliver supported independent living, the decision has already been made for you. From 1 July 2026, SIL providers and digital platform providers under the National Disability Insurance Scheme must be registered with the NDIS Quality and Safeguards Commission. Unregistered SIL providers have until 1 October 2026 to apply.
The Commission puts the consequence plainly: ‘Providing supported independent living without registration is a serious offence.’
For everyone else, registration is still a decision. This guide walks the path from that decision to the audit. Then it covers the part almost nobody writes about: what has to be live on your own website before an auditor looks at it.
Key takeaways
- If you deliver supported independent living, registration is no longer optional and unregistered SIL providers had to apply by 1 October 2026.
- The registration groups you name in your application decide which Practice Standards apply, which audit you face, and what the process costs.
- One certification group anywhere in your application puts the whole audit on the certification pathway.
- The NDIS Commission charges nothing to register. The audit is paid to an approved quality auditor, and the Commission does not set that price.
- Several obligations land on your own website: registration status, the complaints path, reachable policy documents and correct logo use.
Do you need to register as an NDIS provider
Do you need to register, or do you only need to apply if you want to? Registration is compulsory for some supports and optional for others. SIL and platform providers are now in the first group.
If you are not in it, the choice between registered and unregistered providers is a business decision rather than a rule you are obeying.
An unregistered provider can still deliver services to NDIS participants, but only those who self-manage or use a plan manager, according to legal commentary on the reforms. NDIA-managed participants are closed to you.
The NDIS Code of Conduct binds you either way. Registration does not create your duty to people with disability who use your services. It creates an audited record that you are meeting it.
Registration groups decide everything that follows
This is the chain the rest of the process hangs on, and it runs in one direction.
The registration groups you name in your application decide which NDIS Practice Standards apply. The standards decide which audit you face. The audit decides what the process costs you and how long it runs.
A verification audit applies to providers delivering only lower risk or lower complexity supports, and it assesses documents. A certification audit applies to higher risk or more complex supports, and it assesses documents and then people.
| Verification | Certification | |
|---|---|---|
| Applies to | Lower risk, lower complexity supports | Higher risk or more complex supports |
| Assessed against | The verification module | The core module, plus any supplementary module |
| Stages | One, documents | Two: documents, then an on-site visit |
| Participants interviewed | No | Yes, unless they opt out |
| Mid-term audit | No | Yes |
One rule surprises applicants every year. If your application includes registration groups from both pathways, you complete a certification audit for all of it. There is no partial verification.
Specialist behaviour support is the group that most often does this. A provider adding it to an otherwise low risk scope moves the whole application onto the certification pathway.
Certification providers are assessed against the core module of the Practice Standards, plus any supplementary module relevant to what they deliver. You are audited against the NDIS Practice Standards relevant to your groups, and compliance with the NDIS Practice Standards is what the certificate records.
The NDIS registration process, stage by stage
The NDIS registration process has 4 stages, and they are easier to plan once you know who holds each one. The NDIS Commission registers providers. The NDIA runs the scheme and pays for supports.
Applicants confuse the 2 bodies constantly. The application goes to the Commission.
- Start in the Commission portal. You open a new application, enter your ABN, and the portal pulls your business details from the Australian Business Register.
- Self-assess against the standards. You assess your organisation against the Practice Standards that apply to your groups, with evidence behind each answer. The application also asks about the suitability of your key personnel.
- Read your initial scope of audit. After you submit, the Commission emails an initial scope of audit document. It tells you whether you face a verification or a certification audit, and what that audit will cover.
- Engage your auditor. You take that document to approved quality auditors and ask for quotes. You choose one, and you pay them.
That third step is worth slowing down for. The initial scope of audit is the moment the abstract becomes specific, and it arrives before you have spent anything on the audit itself.
NDIS worker screening comes before your audit
Registration requirements reach your workforce, not only your paperwork. NDIS workers in risk-assessed roles must hold an NDIS worker screening check before they deliver supports to participants.
That includes your key personnel and any support worker in a risk-assessed role. The worker screening check is issued by your state or territory and recorded against your organisation.
Auditors treat the screening register as evidence of whether your systems work. A missing clearance is not a paperwork slip to them. It is a participant who was supported by someone you cannot show was cleared.
What the approved quality auditor asks for
A certification audit runs in 2 stages, and they test different things.
Stage 1 is mostly off site. The auditor reads what you have written. Expect requests for your governance framework, risk management, incident and complaints handling, worker screening records, staff training, service agreements and insurance.
Stage 2 is on site. The auditor looks at whether the documents describe what actually happens, by talking to your staff and to participants. The Commission expects stage 2 to take place in the 3 months after stage 1 is complete.
Participants are included by default. In the Commission’s words, ‘you’ll need to let participants know they are automatically enrolled in the audit unless they opt out’. Telling them is your job, not the auditor’s.
If you pass, you receive a certificate of registration naming the supports and registration groups you are registered to provide.
NDIS policies you must have, and the ones people must reach
Every applicant builds a folder of policies. Fewer notice that 2 different obligations are hiding in that folder.
The first is to have the policy. The second is to make it reachable by the people it protects, and only some documents carry it.
Your complaints and feedback process is the clearest case. The Practice Standards require a complaints management and resolution system.
Its information about how to complain must be, in the Commission’s words, ‘available and accessible to the public’. That covers complaints made to you and complaints made about you to the NDIS Commissioner.
The system also has to make complaining easy, including anonymously. Each participant must be told about avenues outside your organisation and their right to an advocate.
A policy that satisfies the first obligation and fails the second is common, and it is visible from outside. Where those documents live, and what has to be true of them on audit day, is the next section.
What has to be live on your website before the audit
Most guides stop at the audit. This is the part your organisation controls completely, and it is the part an auditor can check without asking you for anything.
Your registration status and details. Say plainly whether you are registered, and do not imply an endorsement that does not exist.
The NDIA is blunt about this. Falsely suggesting an affiliation with the scheme may amount to misleading or deceptive conduct under the Australian Consumer Law, and providers who do it are reported to the ACCC.
The complaints and feedback path. If your website is how people find you, the publicly accessible complaints information has to be findable there. Not in a PDF behind an enquiry form.
Policy documents people can open. The ones that face the public belong on a page, in a format a screen reader can read, with a plain-language summary beside them. What accessible actually means here, in WCAG terms, is covered in our post on accessibility on an NDIS website.
Correct logo use. Only registered NDIS providers may use the ‘I heart NDIS’ and ‘we heart NDIS’ logos with the ‘Registered Provider’ tagline. Unregistered providers may not, in any form.
That last rule has teeth. A targeted campaign began in August 2024. By 4 December 2025 the NDIA had referred:
- 604 instances of concerning practices under the Australian Consumer Law to the ACCC
- 112 instances of likely breaches of the NDIS Provider Code of Conduct to the NDIS Commission
- 6 integrity matters to the Fraud Fusion Taskforce
The first 2 items above are written as rules because the Commission and the NDIA state them. The reasoning about where the duty lands on a website is ours, drawn from the requirement that the information be publicly accessible.
What NDIS registration costs, and how long it takes
Registration costs nothing to apply for. In the Commission’s words, ‘There is no cost to register with the NDIS Commission’. What you do pay for is an approved quality auditor to complete your audit.
The audit is your real expense, and the Commission does not set its price. It encourages you to get quotes from several approved quality auditors and compare them.
Line items and price limits are a separate subject, and the 2026-27 price guide changes are covered in their own post. For registration itself, industry sources in 2026 put verification audits at roughly $900 to $1,800. They put certification audits at roughly $2,800 to $12,000 or more, scaling with your size and participant numbers.
Treat those as indicative. Your quotes are the only numbers that matter.
Time is harder to promise. The Commission publishes no overall duration, and commentary ranges from 3 months to a year, mostly depending on how much of your evidence already exists. The one date that is fixed is the SIL deadline of 1 October 2026.
Keeping registration after it is granted
Registration is a period, not a state. It expires, and renewal repeats the application you have just read about, including the audit.
If you took the certification pathway, a mid-term audit falls partway through the period, commonly reported at around 18 months. Adding or removing registration groups can change your audit type, so a change in what you deliver is a change to your registration.
Where this leaves you
If you deliver SIL and have not applied, you need to apply by 1 October 2026.
If registration is your choice rather than your obligation, work backwards from the audit. Your groups set your standards, your standards set your audit, and your website is the one piece of evidence you can fix this week.
We build NDIS provider websites that carry the registration details, the complaints path and the policy documents where people and auditors can actually find them. If you want a site that will not be the weak point in your audit, ask us for a quote.
About the author. Vasilii Aldukhov is the founder and developer at Web Ways Tech, a Sydney web studio that has been building business websites for 10 years and has delivered more than 50 projects. Read more on the about page.
This article describes NDIS registration requirements as published by the NDIS Quality and Safeguards Commission and the NDIA, checked in September 2026. Where a figure comes from industry commentary rather than the regulator, the article says so. It is general information about a regulatory process, not legal advice, and it is not a substitute for the Commission’s own guidance. Rules and fees change: check the current Commission pages before you apply.