Blog | TaxCalc

HMRC Is Switching On MFA for Agent Accounts: Your Three Week Checklist

Written by Elizabeth Sullivan | Sep 13, 2026, 7:00:00 AM

While the profession has spent 2026 absorbed in quarterly updates, AML supervision and accounts filing reform, a change that touches the daily working life of every single UK agent is now only weeks away. Between the 28th of September and the 15th of October 2026, HMRC will enable multi-factor authentication (MFA) on all remaining agent accounts that do not already have it.

This is not a consultation, a pilot or a proposal. It is the final phase of a rollout that has already run through pilots and two voluntary waves. If your firm has not prepared, the first sign you get may be a member of staff unable to log in on a Monday morning with client work waiting.

 

What Is Actually Happening

HMRC has been introducing MFA to agent accounts in stages. Early pilots included volunteers and, tellingly, agents whose accounts had already been compromised. Two voluntary phases followed during July and August 2026, letting firms opt specific accounts in early so they could test their own processes.

Those phases went well. More than 13,000 agents took part, with MFA activated on around 20,000 accounts, and only a very small number needed HMRC to step in and resolve access problems. The common factor among the firms that had a smooth experience was simple: they prepared before switch-on rather than after it.

Now the remaining accounts follow, whether the firm has planned for it or not.

 

The Detail That Catches Firms Out

The mechanics of the switch-on matter more than most practices expect:

  • You will not be told which day it happens. HMRC is not notifying firms of their specific activation date within the three week window, so you need to check daily.
  • Firms with several accounts may be switched on across different days. One account going live does not mean the rest have.
  • Activation happens between 8am and 9am, Monday to Thursday. If no MFA challenge has appeared by 9am, that account is not being switched on that day.
  • Once MFA is active, it applies to every account under the same Government Gateway identifier. If staff or admin accounts are linked to your main account, they are all brought in together.
  • Being logged in when it activates can be disruptive. Some firms will prefer to ask staff to stay logged out before 9am during the window.

 

Why Your Firm Should Welcome This

It is tempting to file MFA under "more admin from HMRC". That would be a mistake, because agent credentials have become a target in their own right.

Practices have reported attackers gaining access to agent credentials and then filing fraudulent VAT and Self Assessment repayment claims for genuine clients, with bank details redirected to accounts the criminals control. In several documented cases the intrusion began with something entirely routine: a phone call from a plausible sounding prospective client, followed by an email carrying a file dressed up as an HMRC letter, which quietly installed remote access software. Weeks passed before anyone noticed.

The damage is not only financial. Firms in that position face client notifications, an ICO conversation, a suspended agent account, rebuilt machines and a reputational hit that is very hard to unwind. Practitioners who have lived through it describe it as the worst experience of their working lives. Set against that, an extra code at login is a bargain.

 

Your Three Week Checklist

Work through the following before 28 September:

  • Inventory every account your firm holds. Old accounts, dormant accounts, accounts set up for a single client or a departed employee. You cannot protect what you have not listed.
  • Choose how your firm will receive codes. Review the available methods and pick the one that fits how your team actually works, including hybrid and remote staff.
  • Strip out and replace legacy MFA settings. Existing settings should be removed and reset to the arrangement you want going forward.
  • Set firm level preferences before anyone logs in. If you do not, an early bird on the day of activation may attach MFA to their personal phone number, which becomes a problem the moment they leave or go on holiday.
  • Review administrator roles. Confirm who holds admin rights and whether that still reflects your current team.
  • Start any new staff accounts now. Creating accounts and reassigning clients to them is slow, so leaving this to late September is a false economy.
  • Purge credentials from software you no longer use. Retired tax and payroll products holding live Gateway details are an open door. Remove the credentials, and close the account where you can.
  • Brief the whole team. Everyone should know what the new sign-in looks like, who to contact if a code does not arrive, and that no genuine caller will ever ask them to read a code out.

 

Do Not Stop at MFA

MFA blocks the overwhelming majority of credential based attacks, but it is one control among several. Use this project as the prompt for a wider tidy up:

  • Enforce MFA across your other systems too, including email, cloud bookkeeping and your practice management platform, not just HMRC.
  • Treat email as your primary attack surface, since that is where most incidents begin.
  • Back up daily, store copies securely offsite, and test a restore rather than assuming it works.
  • Agree an internal rule that bank detail changes on any client repayment are verified independently before submission.
  • Write down what you would do in the first hour of a suspected compromise, including changing passwords immediately and reporting it to HMRC's online services helpdesk.

 

The Bottom Line

For a sole practitioner, preparing for MFA may take twenty minutes. For a firm with multiple accounts, linked staff logins and clients spread across them, it is a small project that deserves an owner and a deadline. The window closes only weeks before the next quarterly update deadline in early November and the start of the Self Assessment run-in, which is precisely the wrong moment to discover your team cannot get into their HMRC accounts.

Put an hour in the diary this week, work through the checklist, and turn a potential disruption into a genuine upgrade to your firm's security. Your clients will never see the work. They would certainly notice the alternative.