- As of 1 July 2026, all Supported Independent Living (SIL) providers and NDIS platform providers must be registered with the NDIS Commission. Until 1 July 2026, both provider types could operate without registration.
- The NDIS Practice Standards have three module types: Core, Supplementary, and Verification. Which modules apply depends on the supports and services you deliver.
- There are two audit types: Verification audits for lower-risk supports, and Certification audits for higher-risk and complex supports.
- NDIS Worker Screening Checks are valid for five years from date of issue. If a worker's check expires, they must be removed from risk-assessed roles immediately.
- A major non-conformity finding gives the provider three months to remediate. Major findings affect registration standing.
1 July 2026 marked the biggest change to NDIS provider registration since the scheme commenced. Mandatory registration for Supported Independent Living providers and NDIS platform providers has begun, new SIL-specific Practice Standards have commenced, and the assessment process is tightening across the board. Providers preparing for their first registration audit or their next renewal need to move now.
The announcement came in December 2025 from Senator Jenny McAllister, Minister for the NDIS. It responds to recommendations from the NDIS Review, the Disability Royal Commission, and the NDIS Provider and Worker Registration Taskforce. The Commission flagged that more guidance on transition arrangements would follow, and issued further detail through the first half of 2026.
This article covers what changed on 1 July 2026, the Practice Standards module structure, the two audit types and how the Commission decides which applies, Worker Screening obligations, what auditors actually look for, the 30-day pre-audit preparation worth doing, and the considerations for providers operating across both NDIS and aged care.
What changed on 1 July 2026
As of 1 July 2026, all SIL providers and all NDIS platform providers must be registered with the NDIS Commission. Until 1 July 2026, both provider types could operate unregistered, which produced an uneven safety profile across the sector. The Commission has framed mandatory registration as a baseline quality and safeguards lift.
Registered providers are subject to:
- Compliance with the NDIS Practice Standards
- Independent quality audits
- Suitability assessments of key personnel
- Reporting requirements to the NDIS Commission
- NDIS Worker Screening Check requirements for all workers in risk-assessed roles
Alongside mandatory registration, new SIL-specific Practice Standards commenced on 1 July 2026. They focus on quality and safety in shared accommodation and daily supports, with stronger worker training requirements and refined SIL-specific audit processes. The Commission published the final SIL Practice Standards in late June 2026, so they are settled in substance; the evidence expectations may still be refined in guidance, so confirm the current version on ndiscommission.gov.au.
Existing SIL providers that apply to register by 1 October 2026 can keep operating while their application is assessed; miss that date and they must stop delivering SIL. Some transition detail was still being finalised close to commencement, so confirm current dates on the Commission's site. New entrants must be registered before they start, and because a certification audit takes months to complete, the practical deadline to begin is now.
The NDIS Practice Standards structure
The Practice Standards are how the Commission measures quality and safety. The structure has three module categories, applied differently depending on the supports and services the provider delivers.
Core module
The Core module applies to all registered providers delivering higher-risk supports and services. It covers the universal expectations: rights of participants, provider governance, provision of supports, and the support environment. Most registered providers delivering active supports will be measured against the Core module.
Supplementary modules
Supplementary modules apply on top of the Core module, depending on the specific types of supports delivered. They cover more specialised support areas with their own standards: for example, supports requiring specialist expertise, supports for participants with complex needs, and behaviour support.
A provider delivering multiple support types is assessed against the Core module plus each Supplementary module relevant to their service mix. The combination determines the scope of the audit.
Verification module
The Verification module applies to providers delivering only lower-risk supports and services. Many providers in this category are already covered by professional regulation (for example, AHPRA registration for clinical professionals) or other recognised bodies, so the Verification module is lighter than the Core module.
Which module set applies is determined by the provider's registration group, which the Commission sets at the point of registration application. The applicable group determines whether the provider needs a Verification or Certification audit.
Verification versus Certification audits
There are two audit types under the NDIS Practice Standards framework. The Commission tells the provider which type applies based on the registration groups they hold.
Applies to providers delivering lower-risk or lower-complexity supports. Often providers already covered by professional regulation. Assessed against the Verification module.
Applies to providers delivering more complex or higher-risk supports. Assessed against the Core module plus any relevant Supplementary modules.
An audit produces a finding rating per Practice Standard and per quality indicator. A major non-conformity (rating 0) on any standard requires the provider to remediate within three months. The Commission has the power to revoke or suspend registration where remediation is not delivered within that window. Minor non-conformities and observations do not affect registration but should still be tracked and closed.
Providers preparing for their first audit should expect the assessment to take several days at the site. The auditor's scope includes interviews with workers and participants, observation of supports being delivered, and review of documentation. A provider operating across multiple service types or sites should expect a longer audit window.
NDIS Worker Screening obligations
NDIS Worker Screening Checks are valid for five years from the date of issue. Workers in risk-assessed roles cannot operate without a current check.
The practical obligations on registered providers:
- Verify each worker's NDIS Worker Screening Check before they begin in a risk-assessed role
- Monitor expiry dates and prompt renewals before lapse
- Workers can apply to renew up to 90 days before expiry; renewal is via the worker screening unit in their current state or territory
- If a check expires, the worker must be removed from all risk-assessed roles immediately
- Maintain a register of all worker screening checks, expiry dates, and renewal status
The Commission notifies the employer when a linked worker's check is approaching expiry. Do not rely solely on those notifications. Maintain your own internal monitoring with a renewal trigger at 90 days, 60 days, and 30 days. Workforce planning around expiries is an operational risk most providers underestimate until their first lapse.
What auditors actually look for
Audit findings cluster around the same patterns year on year.
Incident management evidence. Auditors look for a complete record of incidents, the response, the timeline of action taken, and lessons applied. Patterns of incidents that suggest systemic causes are scrutinised more closely than isolated events.
Complaints handling. A complaints register that is complete and current is one of the cleanest signals of a functioning quality system. Gaps in the register, or complaints that are logged without resolution recorded, are findings.
Worker training and competency. Training records that demonstrate currency for every worker in risk-assessed roles, with renewal dates tracked. Generic training certificates without dated competency assessments are weak evidence.
Restrictive practices authorisations. For providers using restrictive practices, complete authorisation chains, behaviour support plans where required, and reporting against the relevant state or territory framework. The interaction between NDIS Practice Standards and state-based restrictive practices regimes can trip up providers operating across multiple jurisdictions.
Governance evidence. Board or management committee minutes that name quality and safety as a standing agenda item. The same governance pattern that the Aged Care Act 2024 expects under Section 180 applies operationally to NDIS providers: documented risk awareness, named owners, dated actions.
The 30-day pre-audit checklist
Most NDIS providers do not need a full re-architecture before their audit. They need a focused 30-day preparation cycle, with named owners and dated tasks. The pattern that works:
Week 4 (days −30 to −22)
- Confirm audit date, scope, and assessor with the Commission-approved Quality Auditor
- Brief executive leadership and the board on the audit
- Pull 12 months of incident, complaints, and worker screening data into a single brief
- Identify the registration groups in scope and the Practice Standards modules being assessed
Week 3 (days −21 to −15)
- Walk each applicable Practice Standard and identify the evidence for each quality indicator
- Refresh any policy documents older than 12 months
- Audit Worker Screening Check expiries; remediate any approaching lapse
- Update behaviour support plans for any participant where they apply
Week 2 (days −14 to −8)
- Run a mock audit on the most exposed Practice Standard
- Brief frontline workers on assessor expectations and participant-facing interviews
- Confirm interpreter and accessibility arrangements for participant interviews
- Print or organise digital access to all evidence files
Week 1 and audit day
- Final walkthrough with the senior team
- Confirm reception arrangements for assessor arrival
- Brief the board chair on potential findings before the audit begins
- Maintain a daily debrief during the on-site audit window
For providers operating across NDIS and aged care
Providers operating in both sectors face overlapping but not identical compliance regimes. The NDIS Practice Standards and the Strengthened Aged Care Quality Standards share themes (governance, rights, clinical care, environment) but the assessment cadence, the audit format, and the regulatory authorities are different.
The practical implications:
- Maintain separate evidence files for each regime, even where the underlying evidence overlaps. Auditors expect to see evidence formatted to their framework.
- Map your evidence types to both frameworks early. A care plan that satisfies an aged care Strengthened Standard outcome may also satisfy a corresponding NDIS Practice Standard, but the linkage needs to be explicit.
- Watch for integrated Commonwealth guidance. The Department has indicated it will issue cross-sector guidance for providers operating across both. Until that lands, treat each regime as independent.
- Section 180 of the Aged Care Act 2024 applies to responsible persons of aged care providers. Equivalent governance expectations apply under the NDIS Practice Standards, even if the personal liability mechanism is not identical.
What is still being clarified
Most of the 2026 NDIS changes are now locked in. A few areas are still settling or scheduled for later, and these are the points to confirm with the Commission before you rely on them.
The new SIL Practice Standards are final. The Commission published the final SIL Practice Standards in late June 2026 and they apply from 1 July 2026. They set four outcomes: supported decision-making, safeguarding, practice governance, and agreements about tenancy, housing and support. The evidence expectations may still be refined in guidance, so work from the current version.
New change-of-ownership obligations. From 1 July 2026 every registered provider must notify the Commission as soon as it becomes aware that a sale or change of control is going to happen, and significant changes to governance or operations can trigger a change-of-ownership audit. Event-notification timeframes have also been shortened.
What is scheduled next. Digital platform providers register under a separate group (0137) and face extra conditions from 1 January 2027. Mandatory registration is funded to extend to higher-risk supports from 1 July 2027, with full rollout by the end of 2030. Support coordination registration was paused; the government has signalled it will instead directly appoint providers for a new support coordination and connection service from 1 July 2028.
Transition arrangements for SIL and platform providers. The date that matters is 1 October 2026: existing providers that have applied to register by then can keep operating while assessed. Confirm current detail on the Commission's site.
Auditor capacity through the transition. The pool of NDIS Commission-approved Quality Auditors is finite. Higher demand around 1 July 2026 is foreseeable. Book audit slots earlier than usual, particularly for providers seeking certification audits.
The Australian compliance picture, in one checklist
The Aged Care Act 2024 Readiness Checklist covers the seven Strengthened Quality Standards, Section 180 personal liability, the eight SIRS reportable incident types, Star Ratings sub-categories, and a 30-day pre-audit checklist. For providers operating across both aged care and NDIS, it pairs cleanly with this guide. Nine pages. Free, no follow-up sequence.
Get the checklist →Sources
NDIS Commission, Mandatory registration for SIL and platform providers
NDIS Commission, NDIS Practice Standards
NDIS Commission, The quality audit process
NDIS Commission, Worker screening
This article is operational guidance, not legal advice. Confirm transition arrangements with the NDIS Commission as they are published, and refer to current Commission guidance before relying on the figures or interpretations.