While the profession has spent 2026 absorbed in quarterly updates, AML supervision and accounts filing reform, a change that touches the daily working life of every single UK agent is now only weeks away. Between the 28th of September and the 15th of October 2026, HMRC will enable multi-factor authentication (MFA) on all remaining agent accounts that do not already have it.
This is not a consultation, a pilot or a proposal. It is the final phase of a rollout that has already run through pilots and two voluntary waves. If your firm has not prepared, the first sign you get may be a member of staff unable to log in on a Monday morning with client work waiting.
HMRC has been introducing MFA to agent accounts in stages. Early pilots included volunteers and, tellingly, agents whose accounts had already been compromised. Two voluntary phases followed during July and August 2026, letting firms opt specific accounts in early so they could test their own processes.
Those phases went well. More than 13,000 agents took part, with MFA activated on around 20,000 accounts, and only a very small number needed HMRC to step in and resolve access problems. The common factor among the firms that had a smooth experience was simple: they prepared before switch-on rather than after it.
Now the remaining accounts follow, whether the firm has planned for it or not.
The mechanics of the switch-on matter more than most practices expect:
It is tempting to file MFA under "more admin from HMRC". That would be a mistake, because agent credentials have become a target in their own right.
Practices have reported attackers gaining access to agent credentials and then filing fraudulent VAT and Self Assessment repayment claims for genuine clients, with bank details redirected to accounts the criminals control. In several documented cases the intrusion began with something entirely routine: a phone call from a plausible sounding prospective client, followed by an email carrying a file dressed up as an HMRC letter, which quietly installed remote access software. Weeks passed before anyone noticed.
The damage is not only financial. Firms in that position face client notifications, an ICO conversation, a suspended agent account, rebuilt machines and a reputational hit that is very hard to unwind. Practitioners who have lived through it describe it as the worst experience of their working lives. Set against that, an extra code at login is a bargain.
Work through the following before 28 September:
MFA blocks the overwhelming majority of credential based attacks, but it is one control among several. Use this project as the prompt for a wider tidy up:
For a sole practitioner, preparing for MFA may take twenty minutes. For a firm with multiple accounts, linked staff logins and clients spread across them, it is a small project that deserves an owner and a deadline. The window closes only weeks before the next quarterly update deadline in early November and the start of the Self Assessment run-in, which is precisely the wrong moment to discover your team cannot get into their HMRC accounts.
Put an hour in the diary this week, work through the checklist, and turn a potential disruption into a genuine upgrade to your firm's security. Your clients will never see the work. They would certainly notice the alternative.