Guided tools that build your NDIS policies and procedures from your answers. Created by an NDIS auditor.
Explore the tools →Registering as an NDIS provider involves a fair few steps, and the timeline at each stage varies depending on factors that aren’t always very clear. This article breaks the process down stage by stage so you can plan realistically rather than work backwards from an optimistic guess.
For a Certification pathway provider starting from scratch with no major delays, budget nine to twelve months from beginning the process to actually getting your Certificate of Registration. Verification providers can move faster, but it’s still rarely quick.
Reforms have been announced to the NDIS which impact how this works in the future, but the below information is accurate as of writing.
Here’s what’s involved at each stage.
1. Preparing and submitting your application
Before you start working through your registration application through the Commission’s online portal, you should make sure you have a few things ready: your business details, your registration group selections, and your self-assessment responses.
The self-assessment is where many providers underestimate the work involved. Each outcome in the relevant Practice Standards requires a genuine, specific response describing how your organisation meets that requirement. For the Verification pathway that’s around four outcomes. For the Core Module of the Certification pathway, it’s 22 or more.
Very important: these responses need to reflect your actual business! Generic answers are flagged by the Commission and can create problems down the track, including having your entire application cancelled.
You’ll also be prompted to upload your documentation (i.e. policies, procedures, qualifications, etc), though many providers provide this directly to their auditor later in the process rather than uploading everything upfront.
Realistic time to prepare and submit: 2–8 weeks, depending on how much work you’ve done on your systems and documentation. Providers who already have solid policies and procedures in place will likely move through this faster, while providers starting from scratch may need longer.
2. Receiving your Initial Scope of Audit and selecting an auditor
Once you submit your application, the Commission sends you an Initial Scope of Audit document. This sets out which Practice Standards you’ll be assessed against and which audit pathway applies. This is what you need to send to Approved Quality Auditors to request quotes.
Don’t sit on this document, contact auditors as soon as you get it.
Allow roughly a week to receive quotes once you’ve contacted auditors, and another week to review them and make your decision. Ask each auditor how they determine audit duration, how many auditors will be on your team, and what their approach is to non-conformances. The answers tell you a lot about what you’re buying.
Realistic time from receiving scope to booking an auditor: 2 weeks
Once you’ve selected an auditor, you need to book your audit dates. Auditor availability is a real constraint, particularly for Certification audits, and especially as the SIL mandatory registration deadline approaches and demand increases. To give yourself sufficient preparation time, I’d suggest booking your Stage 1 for approximately one month from when you engage the auditor, and your Stage 2 for three months after that. Shorten this timeframe if you’re confident that you’re ready, but the extra prep time makes a difference in my experience.
3. Stage 1 audit
The Stage 1 is a desktop review of your documentation. It’s typically completed in a day or less of auditor work, and some auditors hold opening and closing meetings with you.
The Stage 1 is not a formality, and its purpose is to identify gaps in your documentation before the Stage 2 site visit. If significant gaps are found, your auditor may require you to address them before scheduling the Stage 2, as there’s no point in conducting a site visit when your documentation that doesn’t meet the standard.
The period between Stage 1 and Stage 2 is productive time. Use it to work through any gaps identified in the Stage 1 report, and your auditor will be working with their team to finalise the audit plan (including confirming the sample of staff, participants and sites to be included, scheduling interview times, and confirming logistics for the site visit).
Realistic time: Stage 1 approximately 1 month after engaging auditor
4. Stage 2 audit
The Stage 2 is the on-site visit. For a small provider, expect a minimum of one full day (any auditor quoting you less than that for a Certification audit should be looked at with some scepticism). Larger providers with more staff, more participants, and more sites can run for a week or more with sizeable audit teams.
At the end of the Stage 2, your auditor will hold a closing meeting and present any non-conformances identified. From that point, the clock starts on your corrective action obligations:
- You have 7 calendar days to present a corrective action plan to the auditor for any non-conformance
- Major non-conformances must be downgraded or closed within 3 calendar months of written notification
- If a major non-conformance is not closed within 3 months, the certification decision can be suspended if you’re already registered
- Minor non-conformances must be closed within 18 calendar months (or before your mid-term audit, whichever comes first)
- If a minor non-conformance is not closed within 18 months, it escalates to a major
For initial registrations, major non-conformances mean the registration process cannot proceed until they’re resolved. This is where timelines can blow out significantly, as a follow-up desktop review or on-site audit adds weeks or months to the process.
The auditor then has up to 28 calendar days to submit the completed audit report to the Commission.
Realistic time: Stage 2 approximately 3 months after Stage 1, plus up to 28 days for report submission. Add additional time to close out major non-conformances if any are identified.
5. Commission processing
Once the auditor submits their report, the decision moves entirely to the NDIS Quality and Safeguards Commission. This part is completely outside your control (and honestly outside of your auditor’s control, as much as they’d love to speed it up for you).
The Commission reviews the audit report and recommendation, and conducts a suitability assessment of your organisation and key personnel. They may contact your auditor for additional information, and in some cases may contact you directly. If they do, respond as quickly as possible, as delays in responding are one of the few things that can slow this stage down from your end.
The Commission’s own quarterly performance data shows the median processing times for January to March 2026:
- New application, Verification audit: 49 days
- New application, Certification audit: 34 days
These are medians, so half of applications take longer than this. And it’s worth noting that renewal applications are taking 56 and 34 days on average for Verification and Certification accordingly. If you’re renewing, plan accordingly.
Realistic time: 34 to 49 days on average for new applications, potentially longer if there are information requests.
Putting it all together
Here’s what a realistic timeline looks like for a new Certification provider who starts from scratch and has no major non-conformances:
| Stage | Realistic timeframe |
|---|---|
| Prepare application and self-assessment | 2–8 weeks |
| Receive scope, get quotes, select an auditor | 2 weeks |
| Wait for Stage 1 date | 4 weeks |
| Stage 1 audit and addressing gaps | 1–2 weeks |
| Wait for Stage 2 date and prepare for audit visit | ~10 weeks |
| Stage 2 audit and corrective actions (if any) | 1–4 weeks |
| Auditor report submission | Up to 28 days |
| Commission processing | 34 to 49 days (median) |
| Total | Approximately 9–12 months |
For Verification providers, the process is faster, as there is no Stage 2, no site visit, and Commission processing currently sits at around 47 days. A motivated Verification provider with documentation ready could complete the process in four to six months. But many take longer, particularly if your documentation needs work and non-conformances are identified.
When is my next audit?
Your registration period, and your mid-term audit clock, doesn’t start when your audit is completed or when the report is submitted. It actually starts when the Commission approves your registration, which can be six to twelve months after your audit, depending on processing times.
This means your mid-term audit (due 18 months into your registration period) arrives 18 months from Commission approval, not 18 months from when you finished your audit. And your recertification is due before your registration expires, which is again measured from the approval date.
Once you receive your Certificate of Registration, contact your auditor to book a tentative mid-term date. The 18-month window approaches faster than providers expect.
The practical takeaway
If you’re planning to register, start earlier than you think you need to. The audit process alone takes months, Commission processing adds more, and auditor availability (particularly for Certification providers) is limited. Providers who contact auditors early and book dates promptly consistently have a smoother experience than those who leave it until the last minute.
For SIL providers facing mandatory registration, this timeline is particularly important to understand. Even if transition arrangements give you time from 1 July 2026, the process from starting preparation to holding a Certificate of Registration takes the better part of a year, so get started now.
About the author
Penny Halpin
Penny is an NDIS Lead Auditor who has worked in certification since the first audits in 2018, and was previously a Senior Manager at an Approved Quality Auditor with technical review across thousands of audit reports. She built the Paperbark tools to help providers create documentation that reflects how they actually work.
More about Penny →