Mandatory MFA for SMS: The Guide for Sponsors (2026)

In short

  • The Home Office is making multi-factor authentication (MFA) mandatory for all Sponsorship Management System (SMS) users.
  • The rollout is phased. New groups go live from 3 September 2026 and all sponsors are expected to be covered by November 2026.
  • At login you will need a 6-digit one-time passcode (OTP) in addition to your username and password. Level 1 Users must also enter their date of birth.
  • Three wrong date-of-birth attempts lock the account for 24 hours. A new OTP can be requested only twice.
  • No new Level 2 Users can be added to a licence. Level 1 Users can still be added.

What is MFA in SMS?

MFA adds a second verification layer on top of your password. Even if a password is compromised, someone without access to the device receiving the code cannot get into your SMS account.

The driver is the rise in phishing attacks targeting sponsor accounts. A compromised SMS account can lead to consequences as serious as fraudulent CoS assignments, so the Home Office is tightening login security.

One point worth stressing: MFA changes the login step only. Once you are inside the system, assigning a CoS, reporting and every other function work exactly as before.

Who is affected, and when?

PeriodWhat happens
November 2025Voluntary pilot with a limited number of sponsors
Summer 2026Mandatory MFA starts going live on selected licences
3 September 2026A further phase of the mandatory rollout begins
November 2026MFA expected to be in place for all sponsors

The date MFA is enabled on your licence is stated in the notification the Home Office sends you. The change is applied outside business hours, so you will use the new login method for the first time on the next working day.

What the login will look like

Once MFA is active, every login follows this sequence:

  1. User ID and password
  2. Date of birth, for Level 1 Users
  3. A 6-digit one-time passcode (OTP) sent by text message or email

Two practical details: the OTP is valid for 10 minutes and can take up to 1 minute to arrive. Do not refresh the OTP screen while waiting, as refreshing resets the timer. The “request a new OTP” button only becomes active after 1 minute.

The critical limits: three ways to lock yourself out

This is where most problems occur in practice.

SituationLimitConsequence
Wrong date of birth3 attemptsAccount locked for 24 hours
Wrong OTP entered3 attemptsA new OTP must be requested
“Request New OTP”Only twiceExceeding this triggers a 20-minute lock

A 24-hour lockout is a serious risk in compliance terms. If you need to assign a CoS or file a report close to its deadline, losing a day of access turns straight into a compliance problem.

First MFA login: Level 1 and Level 2

Level 1 Users. At first login you enter your mobile number with its country code, plus your date of birth. The OTP arrives by text message.

Level 2 Users and Level 1 Users without a mobile. Select “I don’t have a mobile number” to switch to the email route. The OTP is sent to the registered email address.

Every user’s registered email must therefore be correct and genuinely accessible to them. A code sent to a shared inbox nobody monitors becomes an access problem.

Changing a registered mobile number or email

The login screen shows only the last four digits of the number on record. If it is wrong, use “Amend” to update it. When a change is made, an automatic notification is sent to the registered email address. If you receive such a notification without having requested a change, treat it as a possible account compromise and report it to the Business Helpdesk immediately.

Level 1 Users who change their phone number or email address must enter their date of birth again at the next login.

No more new Level 2 Users

Under the new functionality, sponsors lose the ability to add new Level 2 Users. Level 1 Users can still be added.

In practice, if your workflow relies on Level 2 Users you need to restructure it before the switch. When a Level 2 User leaves, you cannot appoint a replacement at that level.

What to do:

  • List your Level 2 Users and identify which of them actually use SMS.
  • Consider converting the active ones to Level 1 status where appropriate.
  • Deactivate dormant accounts and accounts belonging to former staff.
  • Keep at least one active Level 1 User on the licence at all times.

Checklist before MFA is enabled

  1. Log in to SMS and verify every user’s email address.
  2. Update the mobile number (including country code) and date of birth for Level 1 Users.
  3. Read the Home Office MFA user guide in full and keep it open during the first login.
  4. Close the accounts of former staff and maintain more than one Level 1 User.
  5. Review your Level 2 arrangements.

If these details are incorrect or incomplete, MFA registration cannot be completed and access to SMS may be lost.

Why this is a compliance issue

Your sponsor duties assume uninterrupted SMS access. Most changes relating to a sponsored worker must be reported within 10 working days, and organisational changes within 20 working days. Being locked out because of MFA is not an acceptable reason for missing those deadlines.

Equally, being unable to assign a CoS brings recruitment to a stop. Treat MFA preparation as part of your sponsor compliance plan rather than as an IT task.

Security reminder

The Home Office will never:

  • Ask for your date of birth, SMS user ID or password.
  • Send you a link or password to log in to SMS.
  • Send you an email with a link to view messages or take action on SMS.
  • Send you a one-time passcode you did not request.

If you receive a suspicious email or phone call, or believe your account has been compromised, report it to BusinessHelpdesk@homeoffice.gov.uk. For MFA queries specifically, the Home Office has opened a dedicated mailbox: MFACOC@homeoffice.gov.uk. Include your organisation name and sponsor licence number in the subject line.

Frequently asked questions

When exactly does MFA become mandatory? The rollout is phased. New groups go live from 3 September 2026, with all sponsors expected to be covered by November 2026. Your own date is in the notification the Home Office sent you.

How long is the OTP valid? 10 minutes. It can take up to a minute to arrive, so wait without refreshing the screen.

What if the OTP does not arrive? The “request a new OTP” button activates after 1 minute. You can use it only twice; exceeding that triggers a 20-minute wait.

What happens if I enter the wrong date of birth? After three failed attempts your account is locked for 24 hours. Check that the date of birth held on the system is correct before the switch.

Do Level 2 Users use MFA? Yes. Level 2 Users receive the OTP by email. However, no new Level 2 Users can be added to a licence.

Does anything else change once MFA is on? No. Only the login step changes. Everything inside the system works as before.

What if I do not have a mobile phone? Select “I don’t have a mobile number” to use the email route. In that case the accuracy of your registered email address becomes critical.

Consequence

MFA is not an optional security improvement for sponsors. It is a near-term requirement. The to-do list is short: verify user details, restructure your Level 2 arrangements, close dormant accounts and maintain more than one Level 1 User.

To assess whether your sponsor licence is ready for MFA, review your user structure or audit your SMS compliance processes, get in touch with the Visavis team.

This article is for general information only and does not constitute legal advice. Home Office announcements and guidance change; rely on the official notification sent to you for the dates and instructions that apply to your licence.

Share your love