{"id":2641,"date":"2026-08-24T13:49:18","date_gmt":"2026-08-24T13:49:18","guid":{"rendered":"https:\/\/visavisuk.com\/uncategorized\/mandatory-mfa-for-sms-the-guide-for-sponsors-2026\/"},"modified":"2026-08-24T14:23:49","modified_gmt":"2026-08-24T14:23:49","slug":"sms-mandatory-mfa-sponsors","status":"publish","type":"post","link":"https:\/\/visavisuk.com\/en\/blog\/sms-mandatory-mfa-sponsors\/","title":{"rendered":"Mandatory MFA for SMS: The Guide for Sponsors (2026)"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\"><strong>In short<\/strong><\/p>\n\n<ul class=\"wp-block-list\">\n<li>The Home Office is making multi-factor authentication (MFA) mandatory for all Sponsorship Management System (SMS) users.<\/li>\n\n\n\n<li>The rollout is phased. New groups go live from 3 September 2026 and all sponsors are expected to be covered by November 2026.<\/li>\n\n\n\n<li>At login you will need a 6-digit one-time passcode (OTP) in addition to your username and password. Level 1 Users must also enter their date of birth. <\/li>\n\n\n\n<li>Three wrong date-of-birth attempts lock the account for 24 hours. A new OTP can be requested only twice. <\/li>\n\n\n\n<li>No new Level 2 Users can be added to a licence. Level 1 Users can still be added. <\/li>\n<\/ul>\n\n<h2 id=\"sms-te-mfa-nedir\" class=\"wp-block-heading\">What is MFA in SMS?<\/h2>\n\n<p class=\"wp-block-paragraph\">MFA adds a second verification layer on top of your password. Even if a password is compromised, someone without access to the device receiving the code cannot get into your SMS account. <\/p>\n\n<p class=\"wp-block-paragraph\">The driver is the rise in phishing attacks targeting sponsor accounts. A compromised SMS account can lead to consequences as serious as fraudulent CoS assignments, so the Home Office is tightening login security. <\/p>\n\n<p class=\"wp-block-paragraph\">One point worth stressing: MFA changes the login step only. Once you are inside the system, assigning a CoS, reporting and every other function work exactly as before. <\/p>\n\n<h2 id=\"kimler-etkileniyor-ve-takvim-nedir\" class=\"wp-block-heading\">Who is affected, and when?<\/h2>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>Period<\/td><td class=\"has-text-align-left\" data-align=\"left\">What happens<\/td><\/tr><tr><td>November 2025<\/td><td class=\"has-text-align-left\" data-align=\"left\">Voluntary pilot with a limited number of sponsors<\/td><\/tr><tr><td>Summer 2026<\/td><td class=\"has-text-align-left\" data-align=\"left\">Mandatory MFA starts going live on selected licences<\/td><\/tr><tr><td>3 September 2026<\/td><td class=\"has-text-align-left\" data-align=\"left\">A further phase of the mandatory rollout begins<\/td><\/tr><tr><td>November 2026<\/td><td class=\"has-text-align-left\" data-align=\"left\">MFA expected to be in place for all sponsors<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<p class=\"wp-block-paragraph\">The date MFA is enabled on your licence is stated in the notification the Home Office sends you. The change is applied outside business hours, so you will use the new login method for the first time on the next working day. <\/p>\n\n<h2 id=\"giriste-adim-adim-ne-olacak\" class=\"wp-block-heading\">What the login will look like<\/h2>\n\n<p class=\"wp-block-paragraph\">Once MFA is active, every login follows this sequence:<\/p>\n\n<ol class=\"wp-block-list\">\n<li>User ID and password<\/li>\n\n\n\n<li>Date of birth, for Level 1 Users<\/li>\n\n\n\n<li>A 6-digit one-time passcode (OTP) sent by text message or email<\/li>\n<\/ol>\n\n<p class=\"wp-block-paragraph\">Two practical details: the OTP is valid for <strong>10 minutes<\/strong> and can take up to <strong>1 minute<\/strong> to arrive. Do not refresh the OTP screen while waiting, as refreshing resets the timer. The \u201crequest a new OTP\u201d button only becomes active after 1 minute.  <\/p>\n\n<h2 id=\"kritik-limitler-hesabinizi-kilitleyen-uc-durum\" class=\"wp-block-heading\">The critical limits: three ways to lock yourself out<\/h2>\n\n<p class=\"wp-block-paragraph\">This is where most problems occur in practice. <\/p>\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><tbody><tr><td>Situation<\/td><td>Limit<\/td><td>Consequence<\/td><\/tr><tr><td>Wrong date of birth<\/td><td>3 attempts<\/td><td>Account locked for 24 hours<\/td><\/tr><tr><td>Wrong OTP entered<\/td><td>3 attempts<\/td><td>A new OTP must be requested<\/td><\/tr><tr><td>\u201cRequest New OTP\u201d<\/td><td>Only twice<\/td><td>Exceeding this triggers a 20-minute lock<\/td><\/tr><\/tbody><\/table><\/figure>\n\n<p class=\"wp-block-paragraph\">A 24-hour lockout is a serious risk in compliance terms. If you need to assign a CoS or file a report close to its deadline, losing a day of access turns straight into a compliance problem. <\/p>\n\n<h2 id=\"ilk-mfa-girisi-level-1-ve-level-2-farki\" class=\"wp-block-heading\">First MFA login: Level 1 and Level 2<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>Level 1 Users.<\/strong> At first login you enter your mobile number with its country code, plus your date of birth. The OTP arrives by text message. <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Level 2 Users and Level 1 Users without a mobile.<\/strong> Select \u201cI don\u2019t have a mobile number\u201d to switch to the email route. The OTP is sent to the registered email address. <\/p>\n\n<p class=\"wp-block-paragraph\">Every user\u2019s registered email must therefore be correct and genuinely accessible to them. A code sent to a shared inbox nobody monitors becomes an access problem. <\/p>\n\n<h2 id=\"kayitli-telefon-numarasi-veya-e-posta-nasil-degistirilir\" class=\"wp-block-heading\">Changing a registered mobile number or email<\/h2>\n\n<p class=\"wp-block-paragraph\">The login screen shows only the last four digits of the number on record. If it is wrong, use \u201cAmend\u201d to update it. When a change is made, an automatic notification is sent to the registered email address. If you receive such a notification without having requested a change, treat it as a possible account compromise and report it to the Business Helpdesk immediately.   <\/p>\n\n<p class=\"wp-block-paragraph\">Level 1 Users who change their phone number or email address must enter their date of birth again at the next login.<\/p>\n\n<h2 id=\"level-2-kullanici-ekleme-donemi-kapaniyor\" class=\"wp-block-heading\">No more new Level 2 Users<\/h2>\n\n<p class=\"wp-block-paragraph\">Under the new functionality, sponsors lose the ability to add new Level 2 Users. Level 1 Users can still be added. <\/p>\n\n<p class=\"wp-block-paragraph\">In practice, if your workflow relies on Level 2 Users you need to restructure it before the switch. When a Level 2 User leaves, you cannot appoint a replacement at that level. <\/p>\n\n<p class=\"wp-block-paragraph\">What to do:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>List your Level 2 Users and identify which of them actually use SMS.<\/li>\n\n\n\n<li>Consider converting the active ones to Level 1 status where appropriate.<\/li>\n\n\n\n<li>Deactivate dormant accounts and accounts belonging to former staff.<\/li>\n\n\n\n<li>Keep at least one active Level 1 User on the licence at all times.<\/li>\n<\/ul>\n\n<h2 id=\"mfa-acilmadan-once-kontrol-listesi\" class=\"wp-block-heading\">Checklist before MFA is enabled<\/h2>\n\n<ol class=\"wp-block-list\">\n<li>Log in to SMS and verify every user\u2019s email address.<\/li>\n\n\n\n<li>Update the mobile number (including country code) and date of birth for Level 1 Users.<\/li>\n\n\n\n<li>Read the Home Office MFA user guide in full and keep it open during the first login.<\/li>\n\n\n\n<li>Close the accounts of former staff and maintain more than one Level 1 User.<\/li>\n\n\n\n<li>Review your Level 2 arrangements.<\/li>\n<\/ol>\n\n<p class=\"wp-block-paragraph\">If these details are incorrect or incomplete, MFA registration cannot be completed and access to SMS may be lost.<\/p>\n\n<h2 id=\"neden-bu-bir-uyum-compliance-meselesi\" class=\"wp-block-heading\">Why this is a compliance issue<\/h2>\n\n<p class=\"wp-block-paragraph\">Your sponsor duties assume uninterrupted SMS access. Most changes relating to a sponsored worker must be reported within 10 working days, and organisational changes within 20 working days. Being locked out because of MFA is not an acceptable reason for missing those deadlines.  <\/p>\n\n<p class=\"wp-block-paragraph\">Equally, being unable to assign a CoS brings recruitment to a stop. Treat MFA preparation as part of your sponsor compliance plan rather than as an IT task. <\/p>\n\n<h2 id=\"guvenlik-hatirlatmasi\" class=\"wp-block-heading\">Security reminder<\/h2>\n\n<p class=\"wp-block-paragraph\">The Home Office will never:<\/p>\n\n<ul class=\"wp-block-list\">\n<li>Ask for your date of birth, SMS user ID or password.<\/li>\n\n\n\n<li>Send you a link or password to log in to SMS.<\/li>\n\n\n\n<li>Send you an email with a link to view messages or take action on SMS.<\/li>\n\n\n\n<li>Send you a one-time passcode you did not request.<\/li>\n<\/ul>\n\n<p class=\"wp-block-paragraph\">If you receive a suspicious email or phone call, or believe your account has been compromised, report it to BusinessHelpdesk@homeoffice.gov.uk. For MFA queries specifically, the Home Office has opened a dedicated mailbox: MFACOC@homeoffice.gov.uk. Include your organisation name and sponsor licence number in the subject line.  <\/p>\n\n<h2 id=\"sik-sorulan-sorular\" class=\"wp-block-heading\">Frequently asked questions<\/h2>\n\n<p class=\"wp-block-paragraph\"><strong>When exactly does MFA become mandatory?<\/strong> The rollout is phased. New groups go live from 3 September 2026, with all sponsors expected to be covered by November 2026. Your own date is in the notification the Home Office sent you.  <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>How long is the OTP valid?<\/strong> 10 minutes. It can take up to a minute to arrive, so wait without refreshing the screen. <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>What if the OTP does not arrive?<\/strong> The \u201crequest a new OTP\u201d button activates after 1 minute. You can use it only twice; exceeding that triggers a 20-minute wait. <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>What happens if I enter the wrong date of birth?<\/strong> After three failed attempts your account is locked for 24 hours. Check that the date of birth held on the system is correct before the switch. <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Do Level 2 Users use MFA?<\/strong> Yes. Level 2 Users receive the OTP by email. However, no new Level 2 Users can be added to a licence.  <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>Does anything else change once MFA is on?<\/strong> No. Only the login step changes. Everything inside the system works as before.  <\/p>\n\n<p class=\"wp-block-paragraph\"><strong>What if I do not have a mobile phone?<\/strong> Select \u201cI don\u2019t have a mobile number\u201d to use the email route. In that case the accuracy of your registered email address becomes critical. <\/p>\n\n<h2 id=\"sonuc\" class=\"wp-block-heading\">Consequence<\/h2>\n\n<p class=\"wp-block-paragraph\">MFA is not an optional security improvement for sponsors. It is a near-term requirement. The to-do list is short: verify user details, restructure your Level 2 arrangements, close dormant accounts and maintain more than one Level 1 User. <\/p>\n\n<p class=\"wp-block-paragraph\">To assess whether your sponsor licence is ready for MFA, review your user structure or audit your SMS compliance processes, get in touch with the Visavis team.<\/p>\n\n<p class=\"wp-block-paragraph\"><em>This article is for general information only and does not constitute legal advice. Home Office announcements and guidance change; rely on the official notification sent to you for the dates and instructions that apply to your licence. <\/em><\/p>\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The Home Office is making multi-factor authentication (MFA) mandatory for all Sponsorship Management System (SMS) users.<\/p>\n","protected":false},"author":2,"featured_media":2640,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"_gspb_post_css":"","footnotes":""},"categories":[47,81],"tags":[],"class_list":["post-2641","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","category-blog-en"],"blocksy_meta":[],"acf":[],"_links":{"self":[{"href":"https:\/\/visavisuk.com\/en\/wp-json\/wp\/v2\/posts\/2641","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/visavisuk.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/visavisuk.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/visavisuk.com\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/visavisuk.com\/en\/wp-json\/wp\/v2\/comments?post=2641"}],"version-history":[{"count":2,"href":"https:\/\/visavisuk.com\/en\/wp-json\/wp\/v2\/posts\/2641\/revisions"}],"predecessor-version":[{"id":2644,"href":"https:\/\/visavisuk.com\/en\/wp-json\/wp\/v2\/posts\/2641\/revisions\/2644"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/visavisuk.com\/en\/wp-json\/wp\/v2\/media\/2640"}],"wp:attachment":[{"href":"https:\/\/visavisuk.com\/en\/wp-json\/wp\/v2\/media?parent=2641"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/visavisuk.com\/en\/wp-json\/wp\/v2\/categories?post=2641"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/visavisuk.com\/en\/wp-json\/wp\/v2\/tags?post=2641"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}