From 28 September 2026, HMRC begins rolling out mandatory multi-factor authentication (MFA) across every agent services account and online services account that hasn’t already switched over. The rollout runs through to 15 October, and HMRC has been clear about one detail that matters more than the date itself: no advance warning will be given for exactly when any individual account gets switched on. An accountant could log in on the 29th and find a text message or authenticator code standing between them and a client’s tax return with a deadline that afternoon.

If you run a small business, this is very likely happening to your accountant or bookkeeper right now, not to you directly — but it affects you the moment they can’t access your filings because nobody set up the second factor in advance. Agents had two earlier windows to opt in, on 15 July and 19 August, and anyone who didn’t take them is now in the group being switched on automatically and without notice this fortnight.

What “no warning” actually means in practice

The practical risk isn’t the MFA itself — a text code or an authenticator app is a small friction, not a genuine obstacle. The risk is timing. If your agent’s mobile number on file is out of date, if nobody has an authenticator app installed and configured, or if the person who normally logs in is on leave when the switch flips, HMRC access can freeze at the worst possible moment — mid-VAT-return, mid-payroll run, or in the days before a filing deadline. Given how many September and October deadlines already sit close together for SMEs, an unplanned lockout on top of that isn’t a minor inconvenience.

The fix is genuinely simple and takes minutes: confirm the mobile number or landline registered against the agent account is current, get an authenticator app (Google Authenticator, Microsoft Authenticator, or similar) installed on a device that’s actually reachable during working hours, and make sure more than one person in the practice or business knows how to complete the second factor if the usual person is away. If you use an external accountant, it’s worth a two-line email this week simply asking whether they’re ready, rather than finding out when a filing stalls.

The wider lesson: identity security isn’t optional admin

This HMRC change is a narrow, specific rollout, but it’s part of a much bigger pattern: government and financial systems are steadily closing the gap on single-factor logins because password-only access to anything holding tax, payroll, or financial data has become too easy to compromise. Businesses that treat MFA as a box-ticking annoyance tend to be the ones caught out when a provider — HMRC today, a bank or supplier portal next — makes it mandatory with a tight deadline. Getting ahead of these changes rather than reacting to them is exactly the kind of practical resilience work firms like KeepSafe help UK businesses build into their day-to-day operations, so a mandatory security change never turns into a missed deadline.

What to do this week

Don’t wait to find out the hard way. If you handle your own HMRC filings, check now whether MFA is already active on your agent or online services account and set it up properly if not. If an accountant or bookkeeper handles it for you, ask them directly whether they’re prepared for the 28 September to 15 October window, and whether more than one person at the practice can complete the login if the usual contact is unavailable. Five minutes of checking now is considerably cheaper than a missed filing deadline caused by a login screen nobody was expecting.