A Deadline Most Practices Have Not Diarised
The profession has spent 2026 talking about quarterly updates, Companies House reform and the arrival of the FCA as AML supervisor. Meanwhile, a change that touches every single person in your firm who logs in to HMRC is now only weeks away.
Between 28th of September and 15th of October 2026, HMRC will activate multi factor authentication (MFA) on all remaining agent accounts that do not already have it. That includes both Agent Services Accounts and the legacy Online Services Accounts many firms still rely on for older filing routes. Two voluntary activation dates were offered earlier in the year, on 15 July and 19 August, and thousands of agents took them. If your firm did not, you are in the final tranche.
Here is the part that matters operationally: HMRC cannot tell you which day your account will be switched over. You will find out when someone tries to sign in and is asked for a code. If that code is going to a mobile number nobody in the office still has, you have an access problem in the middle of filing season.
Why HMRC Has Finally Moved
MFA on agent accounts has been a sore point for years. The functionality existed but was not enforced, and the profession watched the consequences play out in public.
Firms have reported criminals gaining access to their HMRC agent credentials and using them to file fraudulent repayment claims in clients' names, with the refunds redirected to bank accounts the fraudsters controlled. In documented cases this included bogus VAT repayment claims and Self Assessment returns carrying CIS refund claims, with the practice's own credentials used to submit them. One route in was depressingly ordinary: a phone call from a plausible sounding prospective client, followed by an email with what looked like a PDF letter from HMRC. It was a disguised link that quietly installed remote access software and sat undetected for weeks.
The damage in these cases was not only financial. Firms described weeks of unpicking, notifying clients, reporting to HMRC and the Information Commissioner's Office, rebuilding machines, and a level of stress that had owners questioning whether they wanted to continue at all. MFA would not have prevented every one of these incidents, but it closes the single widest gap.
What Actually Changes at Sign In
The change itself is small. After entering the user ID and password, the person signing in will be asked for a one time access code. HMRC supports three delivery methods:
- A code sent by text message to a mobile number
- A code delivered by automated voice call to a mobile or landline
- A code generated by an authenticator app on a phone, tablet or desktop
Nothing about the filing process changes. What changes is that a physical device now has to be in the room whenever someone needs HMRC access. For most practices, that single fact is where the disruption lives.
The Shared Login Problem
Be honest about how your firm signs in to HMRC today. In a great many small and mid sized practices, one set of credentials is used by several people, held in a password manager or, less comfortably, on a note in a drawer. It works because there is no second factor to complicate it.
From October, that arrangement starts to bite. If the code goes to the practice owner's mobile, every VAT submission, every authorisation request and every check of a client's liabilities becomes dependent on that one person being reachable. If it goes to a phone belonging to a member of staff who has since left, you are locked out.
Firms that have already activated MFA report the same lesson. The technical switch takes minutes. Sorting out who signs in, on which device, and what happens when that person is on holiday, is the actual project.
Five Jobs to Do Before Activation Begins
- Audit every HMRC login your firm holds. Not just the Agent Services Account. List the legacy Online Services Accounts too, plus any credentials sitting inside software you no longer use. Old and abandoned accounts are a genuine risk, and firms hit by fraud have pointed to exactly this.
- Decide your access model now. Where practical, move away from one shared credential towards individual logins for the people who genuinely need HMRC access, each with their own second factor. Where a shared account has to remain, make sure the phone number or authenticator is on a device the practice controls rather than a personal handset.
- Update the contact details on file. Check that the mobile numbers and authenticator setups attached to your accounts are live, accessible and belong to current staff. Do this before activation, not after.
- Brief the whole team, including part time and seasonal staff. Anyone who might need to sign in during October should know that a code request is expected and legitimate. This also matters for scam resistance, because a workforce that is surprised by a security prompt is a workforce that can be talked into approving one.
- Write down what happens if you are locked out. Who calls the HMRC online services helpdesk, which deadlines are exposed, and what you tell affected clients. A single page is enough. Most firms do not have it.
Use This as the Trigger for a Wider Security Review
MFA on one government portal is a floor, not a ceiling. The government's Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses identified a cyber breach or attack in the previous 12 months, with phishing by far the most common at 38% and also the most disruptive. Professional, scientific and technical firms, the category accountancy practices sit in, were among the most likely to be hit, at 54%.
Two findings should give practice owners pause. Only 47% of businesses require any form of two factor authentication across their systems, and only 25% have a formal incident response plan. Among the smallest firms, the proportion able to restore operations within a day of their most disruptive incident has fallen. Attacks are not necessarily more numerous, but they are harder to recover from.
So while you are in the account, deal with the basics that sit outside HMRC's control:
- Enforce MFA on email, cloud accounting platforms and your practice management system, not just on HMRC
- Test that your backups actually restore, and keep a copy that an intruder with your credentials cannot reach
- Remove credentials from software you have stopped renewing, and close dormant accounts
- Treat unexpected password reset emails, out of hours authentication texts and unrecognised calls as connected signals rather than isolated oddities
- Know your reporting route in advance: HMRC's online services helpdesk, the ICO where personal data is involved, your professional body and your PII insurer
There Is a Client Conversation Here Too
Your clients are receiving the same phishing attempts, often carrying HMRC branding, and many of them have just been pushed into more frequent digital interaction with HMRC than ever before. A short, plain English note from their accountant about what a genuine HMRC message looks like, and what to do if they think their own Government Gateway has been compromised, is the kind of unbilled advisory touch that clients remember at renewal.
It also protects you. When a client's account is compromised, the mess lands on your desk regardless of where the failure occurred.
The Bottom Line
Activation on all remaining agent accounts happens between the 28th of September and the 15th of October 2026, on a date HMRC will not specify in advance. The firms that will barely notice are the ones that spend an hour this month auditing their logins, confirming who receives the codes, and writing down what to do if access fails. The firms that will notice are the ones still sharing a single credential tied to one person's phone.
Put the audit in the diary this week. Three weeks from now, the choice will have been made for you.