Ask a UK practice owner what is on their compliance calendar this autumn and you will hear about quarterly updates, the January rush and Companies House reform. Very few will mention September 28th 2026. They should.
Between September 28th and October 15th 2026, HMRC will switch on multi-factor authentication (MFA) for every remaining agent account that does not already have it. That covers both the Agent Services Account (ASA) and the older HMRC online services for agents account (OSA) that most firms still use for Self Assessment and Corporation Tax. The voluntary opt in phases closed on 31 July, with just over 20,000 accounts switched on early. Everyone else is now in the mandatory tranche.
The catch is that HMRC will not tell you your exact date. Activation happens between 8am and 9am, Monday to Thursday, across that three week window. If you log in one morning and get an access code challenge, that is your day. If you are not ready, that is also the morning you lose access to your client records.
Agent accounts have been a soft target for years. Fraudsters have used hijacked agent credentials to file fabricated VAT returns and Self Assessment CIS repayment claims, redirecting refunds to bank accounts they control. Firms have described weeks of undetected remote access, clients to apologise to, ICO notifications to make and reputations to rebuild. Small practices have been hit just as hard as large ones, in some cases because the approach was tailored to them using the name of a genuine local business.
MFA has protected personal tax accounts and business tax accounts for years. Agent accounts, which hold the keys to hundreds or thousands of taxpayer records, did not. This change closes that gap. It is not a nuisance dressed up as security. It is the single most effective control available, and it blocks the overwhelming majority of credential based attacks.
The journey becomes the same one your clients already use. You enter your user ID and password, then you enter a six digit access code. Nothing more exotic than that.
Two important points of reassurance:
Also note that activation is applied at Government Gateway Identifier level. When the main account is switched on, every linked staff and admin account underneath it is switched on at the same moment.
Before the switch on, you need to decide how your team will access HMRC. There are two workable models.
Option one, individual logins for every member of staff. This is HMRC's preferred approach and it is the more secure one. Each person sets their own password and their own access code method, and administrators can remove a leaver's access cleanly. The friction is client allocation. On the legacy OSA, clients do not appear automatically for a new standard user. An administrator has to allocate them, and there is currently no bulk allocation tool. If you have 4,000 clients and 20 staff who all need full access, do the maths before you commit. On the ASA the picture is better, because Access Groups let you manage which staff see which clients. Access Groups is still in private beta, so if the invitation banner is not showing in your ASA you will need to ask HMRC to enable it, and allow about a week.
Option two, keep shared credentials and use time based codes. HMRC does not prefer this, but it is explicitly supported. Multiple staff can use the same credentials at the same time provided each of them has an authenticator app set up from the same secret key. It avoids the allocation problem entirely. The trade off is governance. When someone leaves, you must change the password and refresh the MFA method, or they can still get in.
HMRC recommends setting up at least two methods so there is always a fallback. Without one, a lost phone means a call to the online services helpdesk.
Here is the trap. Some firms already have MFA settings sitting on their accounts from years ago, perhaps set up by someone during MTD for VAT. If those settings point at a mobile number belonging to a former employee, or a device nobody still has, you will be challenged for a code you cannot receive. That is a lockout on the first morning, not an inconvenience later.
The second trap concerns shared logins. If you do nothing before your activation date, the first person to log in that morning is the one HMRC asks to choose the access code method. That could be a junior member of staff tying your firm wide credentials to their personal mobile. Set it up deliberately, in advance, or give your team crystal clear instructions about what to do if they are prompted.
There is a commercial angle here that is easy to miss. Your owner managed clients are being targeted by the same phishing campaigns, and many of them have never enforced MFA on their own email, cloud accounting or banking. A short note explaining what your practice has just done, and why they should do the same, positions you as the adviser who takes their data seriously. Firms that treat security as a service rather than an IT chore find it is one of the easier advisory conversations to start.
This is a small piece of admin with a disproportionate downside if you ignore it. Twenty minutes spent in your ASA and OSA this week is the difference between a smooth transition and a morning spent on hold to the online services helpdesk while client work stalls. The window opens on the 28th of September. Treat that as your deadline, not the 15th of October, and get it done before the pre January workload closes in.