The profession has spent 2026 talking about quarterly updates, Companies House reform and the arrival of the FCA as AML supervisor. Meanwhile, a change that touches every single person in your firm who logs in to HMRC is now only weeks away.
Between 28th of September and 15th of October 2026, HMRC will activate multi factor authentication (MFA) on all remaining agent accounts that do not already have it. That includes both Agent Services Accounts and the legacy Online Services Accounts many firms still rely on for older filing routes. Two voluntary activation dates were offered earlier in the year, on 15 July and 19 August, and thousands of agents took them. If your firm did not, you are in the final tranche.
Here is the part that matters operationally: HMRC cannot tell you which day your account will be switched over. You will find out when someone tries to sign in and is asked for a code. If that code is going to a mobile number nobody in the office still has, you have an access problem in the middle of filing season.
MFA on agent accounts has been a sore point for years. The functionality existed but was not enforced, and the profession watched the consequences play out in public.
Firms have reported criminals gaining access to their HMRC agent credentials and using them to file fraudulent repayment claims in clients' names, with the refunds redirected to bank accounts the fraudsters controlled. In documented cases this included bogus VAT repayment claims and Self Assessment returns carrying CIS refund claims, with the practice's own credentials used to submit them. One route in was depressingly ordinary: a phone call from a plausible sounding prospective client, followed by an email with what looked like a PDF letter from HMRC. It was a disguised link that quietly installed remote access software and sat undetected for weeks.
The damage in these cases was not only financial. Firms described weeks of unpicking, notifying clients, reporting to HMRC and the Information Commissioner's Office, rebuilding machines, and a level of stress that had owners questioning whether they wanted to continue at all. MFA would not have prevented every one of these incidents, but it closes the single widest gap.
The change itself is small. After entering the user ID and password, the person signing in will be asked for a one time access code. HMRC supports three delivery methods:
Nothing about the filing process changes. What changes is that a physical device now has to be in the room whenever someone needs HMRC access. For most practices, that single fact is where the disruption lives.
Be honest about how your firm signs in to HMRC today. In a great many small and mid sized practices, one set of credentials is used by several people, held in a password manager or, less comfortably, on a note in a drawer. It works because there is no second factor to complicate it.
From October, that arrangement starts to bite. If the code goes to the practice owner's mobile, every VAT submission, every authorisation request and every check of a client's liabilities becomes dependent on that one person being reachable. If it goes to a phone belonging to a member of staff who has since left, you are locked out.
Firms that have already activated MFA report the same lesson. The technical switch takes minutes. Sorting out who signs in, on which device, and what happens when that person is on holiday, is the actual project.
MFA on one government portal is a floor, not a ceiling. The government's Cyber Security Breaches Survey 2025/2026 found that 43% of UK businesses identified a cyber breach or attack in the previous 12 months, with phishing by far the most common at 38% and also the most disruptive. Professional, scientific and technical firms, the category accountancy practices sit in, were among the most likely to be hit, at 54%.
Two findings should give practice owners pause. Only 47% of businesses require any form of two factor authentication across their systems, and only 25% have a formal incident response plan. Among the smallest firms, the proportion able to restore operations within a day of their most disruptive incident has fallen. Attacks are not necessarily more numerous, but they are harder to recover from.
So while you are in the account, deal with the basics that sit outside HMRC's control:
Your clients are receiving the same phishing attempts, often carrying HMRC branding, and many of them have just been pushed into more frequent digital interaction with HMRC than ever before. A short, plain English note from their accountant about what a genuine HMRC message looks like, and what to do if they think their own Government Gateway has been compromised, is the kind of unbilled advisory touch that clients remember at renewal.
It also protects you. When a client's account is compromised, the mess lands on your desk regardless of where the failure occurred.
Activation on all remaining agent accounts happens between the 28th of September and the 15th of October 2026, on a date HMRC will not specify in advance. The firms that will barely notice are the ones that spend an hour this month auditing their logins, confirming who receives the codes, and writing down what to do if access fails. The firms that will notice are the ones still sharing a single credential tied to one person's phone.
Put the audit in the diary this week. Three weeks from now, the choice will have been made for you.