Between 28 September and 15 October 2026, HMRC will activate multi-factor authentication on all remaining agent accounts that do not already have it. The change applies to both the agent services account and the online services account, and HMRC has framed it as an extra layer of security introduced in response to ongoing and evolving online security threats.
Firms had two chances to go early. Submitting the online form by midnight on 30 June 2026 brought activation forward to 15 July 2026, and submitting by midnight on 31 July 2026 set activation for 19 August 2026. The form has been available inside accounts that do not already have MFA since 10 June 2026. Both opt-in deadlines have now passed, which means most practices are in the default autumn window whether they planned for it or not.
This is a small technical change with an awkward date attached, and the firms that treat it as purely an IT task are going to miss the more interesting part.
What is actually changing?
An extra sign-in step on the agent services account and the online services account. Instead of a user ID and password, a practice will need a second factor as well. HMRC is applying it to every remaining agent account in a rolling window between 28 September and 15 October 2026.
The mechanics are not complicated. What makes it disruptive is scale and timing. Every UK practice that has not already switched will hit this inside the same three-week window, and that window sits immediately before the busiest stretch of the self assessment cycle. Whatever access problems a firm has been quietly tolerating will surface at the least convenient moment.
Why does this cause more trouble than it should?
Because a great many practices share HMRC credentials informally. One login used by three people, a password in a spreadsheet, an account still tied to someone who left. MFA does not tolerate that arrangement, so it forces a firm to confront its own account hygiene on HMRC's timetable rather than its own.
The specific failure mode is predictable. The second factor gets attached to one person's device, that person goes on leave or leaves the firm, and nobody else can get in. ATT and CIOT have published joint guidance covering how agents can prepare, including the handling of shared credentials with authenticator apps, and it is worth reading before the window rather than during it.
There is a second, quieter cost. Practices that discover in October that only one person can access an account will lose hours at exactly the point when client work is stacking up. Those hours are not recoverable and they are entirely avoidable.
What has this got to do with marketing?
More than it looks. A whole-profession security change is one of the few moments when clients are receptive to hearing how their accountant handles their data, and almost no firm will say anything about it. Silence is the default, which makes a clear, calm explanation unusually visible.
Think about what a client actually experiences. At some point this autumn their accountant may take longer to file something, or ask them to confirm details differently, and nobody will have explained why. The firm that sent one short note in September explaining that HMRC is strengthening access security and what the practice has done about it looks organised. The firm that says nothing looks slow.
This is not spin. It is the ordinary work of explaining a change before it inconveniences someone, and it is the cheapest trust-building a professional firm can do. We covered the same dynamic when identity verification arrived, in our piece on Companies House identity verification and what it means for accountants.
Is security actually a reason clients switch firms?
Rarely on its own, but it feeds the judgement that drives switching, which is whether the firm feels in control. Clients almost never leave over a single incident. They leave after accumulating small signals that their accountant is reactive, and an unexplained autumn of access problems is exactly that kind of signal.
The reverse is also true and less obvious. A firm that communicates well through a disruption gets credit disproportionate to the effort involved, because the comparison set is so weak. Most practices will send nothing.
Timing matters here too. The autumn is already the period when UK businesses reassess their advisers ahead of the January deadline, which we set out in our analysis of the UK accounting client-switching window. A firm handling a visible change badly during that period is being evaluated, whether it realises it or not.
What should a practice publish about this?
Two things, both short. A client-facing note explaining that HMRC is adding a second sign-in step for agents this autumn and what the firm has done to prepare. And a page on the site setting out, in plain terms, how the practice protects client data.
The second one has a longer life than the first. Security and data-handling pages are among the few pieces of content a professional firm can write once and use for years, and they get read by exactly the prospects who are hardest to win, which are the cautious ones comparing three firms. They also answer a question that comes up in almost every new-client conversation and usually gets answered verbally, inconsistently, by whoever picks up the phone.
Write it without jargon. What systems the firm uses, who has access, what happens if something goes wrong, and how the firm authenticates a request to change bank details. That last one is worth its own paragraph, because it is the fraud that actually costs accounting clients money.
Email and lifecycle marketing is the delivery mechanism for the timely half of this. One well-written note to the client base in September costs almost nothing and is the single highest-return communication a practice will send this quarter.
The durable half belongs on the site. Website design and development work for a practice is largely about making verifiable facts easy to find, and a data-handling page is a good example of a page that quietly closes deals without ever being the reason someone visits.
And it has to be findable. Search engine optimisation for accountants is mostly the discipline of writing the pages that answer what prospects actually search, then linking them properly. Our pillar guide to digital marketing for accounting firms sets out how these pieces fit together across a practice's whole site.
How does this interact with the other changes already in flight?
It stacks. UK practices are already absorbing mandatory agent registration with HMRC and the identity verification regime, and MFA now lands on top of both inside the same autumn. Each change is manageable alone; the load comes from arriving together.
That has a practical consequence for how a firm plans. Treating each announcement as a separate fire drill produces three rushed responses and no cumulative benefit. Treating them as one programme of work, with one client-facing explanation covering how the practice is handling a tightening compliance environment, produces something a prospect can actually read and be reassured by.
It also changes what a firm should say. Individually, each of these is administrative detail that clients do not care about. Together they support a claim that most practices cannot make credibly, which is that the firm anticipates change rather than reacting to it. Our note on the HMRC tax adviser registration deadline covers the registration side of the same picture.
What should a firm do before the window opens?
Five things, none of which take long, and all of which are cheaper now than in October.
First, list every HMRC account the practice uses and who currently signs in to each. Most firms find at least one surprise.
Second, end shared credentials. Give each person their own access where HMRC allows it, and follow the ATT and CIOT guidance where a shared account genuinely cannot be avoided.
Third, decide which device holds each second factor and make sure it is not a single person's personal phone with no fallback. Leave, illness and resignations are ordinary events and the plan has to survive them.
Fourth, brief the team. Everyone who touches an HMRC account should know what is changing and who to tell when something does not work.
Fifth, write the client note now and schedule it for September. It takes twenty minutes and it is the part most likely to be skipped, because it is the only one that is not urgent.
The wider point
Regulatory and administrative changes arrive at UK practices constantly, and most are handled as compliance chores. A minority of firms treat them as scheduled moments when clients are paying attention, and use them to demonstrate competence. Over a few years that difference compounds into a reputation, and reputation is what determines whether a practice competes on fee.
The MFA rollout is a modest example of the pattern. It is genuinely useful security, it will cause genuine friction, and it lands at a moment when your clients are already forming a view about whether you are on top of things.
Triomatic Marketing is an AI-powered, founder-led agency working with accounting firms across the UK and USA, and we keep 82% of our clients by helping practices turn scheduled changes like this into visible competence. Our UK digital marketing agency page covers how we run the programme for British practices. To talk it through, message Aria on WhatsApp via triomaticmarketing.com, or book a free 15-minute discovery call at https://calendly.com/hello-triomaticmarketing/15min.
FAQs
When does HMRC switch on MFA for agent accounts?
Between 28 September and 15 October 2026, HMRC will activate multi-factor authentication on all remaining agent accounts that do not already have it. The change applies to both the agent services account and the online services account, and HMRC has described it as an extra layer of security against evolving online threats.
Could agents opt in to an earlier MFA date?
Yes, and both windows have now closed. Submitting the online form by midnight on 30 June 2026 set activation for 15 July 2026, and submitting by midnight on 31 July 2026 set activation for 19 August 2026. The form has been available inside accounts without MFA since 10 June 2026.
Which HMRC accounts does MFA apply to?
The agent services account and the online services account. Both will require a second factor at sign-in in addition to a user ID and password once MFA is activated on the account.
Why is MFA a problem for practices that share logins?
Because a second factor is tied to a device, a shared credential stops working reliably when the person holding that device is unavailable. Practices using one login across several people, or an account still registered to a former employee, will find access breaks. ATT and CIOT have published joint guidance on preparing, including handling shared credentials.
What should a practice tell clients about the MFA change?
A short note explaining that HMRC is adding a second sign-in step for agents this autumn and what the firm has done to prepare. It costs very little, it explains any delay before clients experience one, and very few competing practices will send anything at all.
Does data security influence whether clients change accountant?
Seldom on its own, but it contributes to the judgement that drives switching, which is whether the firm appears to be in control. Clients accumulate small signals over time, and an autumn of unexplained access problems during the run-up to the January deadline is the kind of signal that counts against a practice.