Home / Insights / Compliance
Compliance

HMRC's Agent MFA Deadline: What 28 September 2026 Means for Your Practice

Every agent account without multi-factor authentication is being switched on in daily batches from today until 15 October — and an out-of-date access code setting means locked out on day one, not day fifteen.

Practice Group · 9 min read · September 2026

General information for practice owners, current at the time of writing (September 2026). Details are as published by HMRC and the professional bodies as at 28 September 2026; this is not a substitute for HMRC's own Tax Agent Handbook guidance, which should be your working reference during switch-on.

Today, 28 September 2026, is the first day HMRC begins switching on mandatory multi-factor authentication (MFA) for every agent account that has not already opted in. By 15 October, every Agent Services Account (ASA) and legacy Online Services Account (OSA) in the country will require a one-time code on top of the usual Government Gateway sign-in — not as an option, but as a condition of getting into the system at all. If your firm did not take one of the two voluntary windows in July and August, your accounts are now in the mandatory queue, and the switch happens without further individual notice beyond the daily batch it lands in.

This is not a deadline to file away for later. It is live now, and firms that leave their access code settings out of date find that out the hard way: unable to reach a client's VAT return or PAYE dispute in the exact week it is due. Here is what is actually changing, what the three ways of receiving a code mean in practice, and the checklist to run through today.

What's switching on, and when

HMRC has been building towards this for months. Two voluntary phases let agents choose their own switch-on date ahead of the mandatory rollout; both have now closed, and HMRC reports that more than 20,000 agent accounts, across roughly 13,000 firms, were switched on through them voluntarily. Everyone else moves automatically.

WindowWhat happens
Opt-in by 30 Jun 2026Voluntary phase 1 — accounts went live 15 Jul 2026
Opt-in by 31 Jul 2026Voluntary phase 2 — accounts went live 19 Aug 2026
28 Sep – 15 Oct 2026Mandatory switch-on for every remaining ASA and OSA, in daily batches activated 8–9am, Monday to Thursday
THE MFA SWITCH-ON TIMELINE Voluntary phase 1 live 15 Jul 2026 Voluntary phase 2 live 19 Aug 2026 Mandatory switch-on 28 Sep – 15 Oct 2026 TODAY More than 20,000 accounts already switched on voluntarily. Every remaining ASA and legacy OSA follows in daily batches, 8–9am Monday to Thursday.
If your firm skipped both voluntary windows, your accounts are now in the mandatory queue — switching on without further individual notice.

Which accounts are caught — and who else is logged into them

Both account types agents rely on are in scope. The ASA handles Making Tax Digital, trust registration and a growing share of VAT and PAYE work; the older OSA is still where a lot of firms file Self Assessment and Corporation Tax returns for their longest-standing clients. HMRC has not carved out an exemption for either, and there is no smaller-firm threshold that keeps a sole practitioner out of the rollout.

The detail that catches firms out is that MFA switches on for every login tied to a given Government Gateway identifier at once, not account by account or user by user. If your practice has historically used one shared Government Gateway ID for filing across several staff, every one of them loses access in the same instant that identifier's batch is activated — not gradually, and not with a warning to whoever happens to be mid-filing at the time.

The three ways to receive a code

Once MFA is live, signing in means entering a one-time access code in addition to the existing user ID and password. HMRC offers three delivery methods, and firms are expected to have at least one primary and one backup configured on every login before their batch activates.

MethodHow it worksHMRC's guidance
Authenticator appGenerates a time-based code on a smartphone; no phone signal needed once set upRecommended primary method
SMS text messageSix-digit code sent to a mobile, valid for 15 minutes; not available to all countriesSuitable backup
Automated voice callCall from 01749 608007 reads out a six-digit code, valid for 15 minutesBackup for landlines or staff without a smartphone

The app is the method HMRC steers firms towards, largely because it works without signal and does not depend on a text or call reaching the right person at the right desk. But the voice-call option matters more than it might first look: not every member of staff in a practice, particularly older or part-time employees working from a landline, will have a smartphone set up for an authenticator app on day one, and HMRC's own guidance treats the call-back number as a legitimate permanent route, not a stopgap.

The decision most firms haven't actually made yet

Underneath the mechanics sits a bigger question: does your firm move to individual logins for every member of staff, or keep a shared login secured with MFA? HMRC's stated preference is the former — named credentials for each person, with client work allocated to individual users — and it is testing a bulk client-allocation tool for legacy OSAs, expected before the end of 2026, specifically to make that migration less punishing for firms with large client banks split across several staff.

Worked example: an eight-partner, 30-staff general practice choosing a login model

The individual-login route. Every one of the 30 staff gets their own Government Gateway credentials and their own MFA method. Client work is allocated by name rather than by whoever happens to be signed in. It is the more secure model and the one that survives a staff departure cleanly — remove one person's access, and nobody else is affected. The cost is upfront: reallocating several hundred clients across 30 named users by hand, on an OSA that was never built for bulk reassignment, is realistically a multi-day admin project this autumn.

The shared-login route. The firm keeps its existing shared Government Gateway ID, adds an authenticator app as the MFA method, and installs it on two or three trusted managers' phones. Set-up takes an afternoon rather than days. The trade-off shows up later: every time someone with access to that shared login leaves the firm, the password and the MFA method both have to change immediately, or that person retains the ability to sign in indefinitely.

Illustrative figures based on a firm of this size; the right call depends on staff turnover and how your client base is currently split across logins.

Most firms under about 15 staff find the shared-login route pragmatic for now. Larger firms with real staff turnover tend to find the one-off admin cost of individual logins cheaper than the ongoing discipline a shared login demands every time someone hands in their notice.

What happens if your firm does nothing

The most common failure mode is not fraud or hacking — it is a firm arriving at its batch's activation window with access code settings that are simply out of date: a mobile number that changed two years ago, an authenticator app nobody ever installed. HMRC has been explicit that outdated options can lock an account out the moment MFA switches on, and there is no grace period built into the process to fix it retrospectively once that has happened.

The second failure mode is organisational rather than technical. Firms running shared logins that forget to update the MFA method when a member of staff leaves are not creating an MFA problem — they are leaving a security gap that MFA was supposed to close, because the departed employee's device or number can still generate a valid code.

Both failure modes land at an awkward moment. The mandatory window overlaps directly with MTD for Income Tax's ongoing quarterly filing cycle and the run-up to Self Assessment season, so a lockout is not an abstract inconvenience — it is a client return that cannot be filed on the day it is due, through an account fault entirely inside the firm's own control.

The short version

The checklist for this week

  1. List every ASA and OSA login your firm holds, and which Government Gateway identifier each sits under. This is the step most firms skip, and the one that makes everything else possible.
  2. Appoint at least two administrators per account, so a reset is possible if the usual person is unavailable, or is the one locked out.
  3. Decide individual or shared logins for each account, based on staff numbers and turnover, not on which is quicker to set up this week.
  4. Set an authenticator app as the primary method on every login, with at least one backup delivery method configured alongside it.
  5. Remove access for anyone who has left the firm, and check that shared credentials were rotated when they went.
  6. Check third-party and practice-management software that logs into HMRC systems automatically — bulk filing tools and integrations may need reconfiguring once a code is required at sign-in.
  7. Check access again the morning your batch activates, between 8 and 9am on a weekday, rather than assuming the switch happened cleanly in the background.

None of this is complicated, but it is precisely the kind of unglamorous admin that gets pushed down the list in a season already carrying mandatory tax adviser registration and HMRC's own auto sign-up drive for MTD. Treat MFA the same way: as a scheduled task this week, not a live incident next month.

Frequently asked questions

What exactly is changing on 28 September 2026?

HMRC has begun switching on mandatory multi-factor authentication (MFA) for every Agent Services Account and legacy Online Services Account that hasn't already opted in during the two voluntary phases in July and August. From 28 September to 15 October, HMRC is enabling MFA on all remaining accounts in daily batches, activated between 8am and 9am, Monday to Thursday. From the moment your account's batch runs, signing in requires a one-time code — from an authenticator app, a text message, or an automated voice call — on top of the usual Government Gateway user ID and password. There is no way to opt out or defer once your slot arrives; the only choice left is whether your access code settings are ready before it does.

Which HMRC accounts does this affect?

Both of the account types agents use: the Agent Services Account (ASA), which handles Making Tax Digital, trust registration and some VAT and PAYE work, and the older HMRC Online Services for Agents Account (OSA), still used for Self Assessment and Corporation Tax filing on many firms' longest-standing client lists. MFA switches on for every login tied to the same Government Gateway identifier at once, not account by account. If several members of staff share one set of credentials to file client work, all of them lose access simultaneously the moment that identifier's batch activates, unless the new access code settings have already been configured and communicated to the team.

We missed both voluntary phases — what happens now?

Nothing extra: your accounts simply sit inside the mandatory window running from 28 September to 15 October 2026, alongside every other agent account that did not opt in. HMRC is not sending individual notice of which day your batch activates, so the practical approach is to treat every account as due at any point in that fortnight. If your current access code options are out of date — a landline nobody answers, an old mobile number — that is the setting to fix first, since HMRC has been explicit that outdated options can lock an account out the moment MFA switches on, with no grace period to sort it out afterwards.

Can we carry on using one shared login across the team after MFA switches on?

Yes, and many smaller firms will. HMRC's preference is individual staff logins with client work allocated to named users, which is the more secure model and the one the department is nudging firms towards, including a bulk client-allocation tool it is testing for legacy OSAs before the end of 2026 to make that switch less painful. A shared login secured with an authenticator app or password manager remains a valid route, provided the password and MFA method are changed the moment anyone with access leaves the firm. The administrative risk of a shared login is not MFA itself — it is forgetting to lock a leaver out afterwards.

What should we do if our firm gets locked out?

Contact HMRC's Online Support Helpdesk, using an alternative registered contact method if the one on file is now the thing you cannot access. This is exactly why HMRC recommends every firm nominate at least two administrators before switch-on: a second person who can reset settings if the first is unavailable, travelling, or happens to be the one who is locked out. Prevention is the lower-effort route: check your access code options today, confirm at least two delivery methods are current on every login your firm holds, and do not leave that check until the week your batch is due to activate.

One more thing landing on an already-crowded calendar?

MFA, mandatory tax adviser registration and MTD's rollout are all asking for the same scarce resource: partner time. If it's time to talk about freeing up capacity, bringing in fractional support, or what your practice is worth, start with a confidential, no-obligation call.

Book a confidential call