Organisations should treat SMS-based MFA as a lower assurance option, not a final destination. It can still help reduce risk compared with passwords alone, but SIM swap attacks, interception, and phishing make it unsuitable for high-risk access. For stronger protection, prioritise phishing-resistant methods such as FIDO2 hardware keys or biometric authentication for critical users and sensitive systems.
Why SMS MFA is a stepping stone, not the end state
SMS can still raise the bar above passwords alone, but it remains vulnerable to adversary-in-the-middle phishing, SIM swap fraud, and code interception. That makes it a weaker fit for privileged users, remote admin paths, and any workflow where a stolen second factor could immediately expose sensitive systems or data. Stronger methods reduce both takeover risk and reliance on recoverable phone numbers.
For organisations that are still using SMS, the practical question is not whether it has value at all, but where its residual risk is acceptable. For low-sensitivity use cases it may be a transitional control, but for high-value access it should be treated as an interim measure while phishing-resistant methods are deployed.
What makes phishing-resistant authentication different
Phishing-resistant methods bind the authentication event to the intended site or device so the user is not simply typing or relaying a reusable code. FIDO2 security keys and passkeys are the clearest examples because they are designed to resist credential replay and code theft. In practice, that changes the attacker problem from “steal a code” to “compromise the actual authenticator or the enrolled device.”
Biometric authentication can also be part of a stronger sign-in experience, but it is best understood as a local unlock factor rather than a stand-alone guarantee of phishing resistance. What matters operationally is the full method chain, including device binding, recovery paths, and whether the method still works when the user is pushed through a fake login page.
How to choose the right method for each access tier
The cleanest decision rule is to align the method with the value of the access. SMS may be acceptable for temporary or lower-risk populations where a rapid rollout matters more than maximum assurance. Phishing-resistant methods should be the default for administrators, executives, finance teams, and any account that can change security settings, access sensitive records, or approve transactions.
Rollout should also account for recovery. If the fallback path to reset a passkey or hardware key relies on weak help desk processes or SMS again, the overall assurance drops back to the weakest step. Organisations get better results when they pair strong primary authentication with tight enrollment, recovery, and exception handling.
Risk and Threat Considerations
SMS MFA fails when the defender assumes a one-time code is equivalent to possession of a secure second factor. Attackers can phish the code in real time, redirect a phone number through SIM swap, or intercept messages through device compromise and carrier abuse. The result is that the second factor still protects against some bulk attacks, but it does not reliably stop targeted account takeover.
Failure mechanism: The attacker captures or reroutes the SMS challenge, then reuses the code or session before it expires. If the account also has weak recovery, the attacker may convert a single intercepted sign-in into persistent access.
Impact: High-value accounts can be taken over even when MFA is “enabled,” which creates a false sense of security and leaves privileged access, sensitive data, and downstream systems exposed.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 addresses the attack surface, NIST SP 800-63, NIST SP 800-53 Rev 5 and OWASP ASVS set the technical controls, and ISO/IEC 27001:2022 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | Digital Identity Guidelines | Phishing-resistant authenticators and assurance levels directly govern MFA choice. |
| Recommendation — Use phishing-resistant authenticators for high-risk access and map sign-in strength to assurance level. | ||
| NIST SP 800-53 Rev 5 | IA-2 — Identification and Authentication (Organizational Users) | Employee and admin sign-in assurance is central to choosing stronger MFA. |
| IA-5 — Authenticator Management | SMS codes, hardware keys, and passkeys all depend on authenticator lifecycle and recovery. | |
| Recommendation — Require stronger authentication for organizational users with elevated access. Manage enrollment, rotation, revocation, and recovery for all authenticators. | ||
| ISO/IEC 27001:2022 | A.5.17 — Authentication information | The topic concerns protecting and using authentication material and recovery paths. |
| Recommendation — Protect authentication information and limit weak fallback recovery paths. | ||
| OWASP ASVS | V6 — Authentication | The question compares authentication methods and their assurance properties. |
| Recommendation — Set higher authentication requirements for sensitive users and privileged actions. | ||
| OWASP Non-Human Identity Top 10 | NHI-04 — Insecure Authentication | Weak second factors and phishing-eligible sign-in flows are authentication weaknesses. |
| Recommendation — Prefer phishing-resistant authenticators over SMS for critical access. | ||
Practitioner Guidance
What to prioritise: Use phishing-resistant authentication first for privileged, remote, and high-impact access, then phase SMS out where the blast radius justifies the migration cost. A good transition plan starts with the highest-risk accounts, not the easiest ones.
What to verify: Check that the chosen method is truly bound to the user’s intended device or authenticator, and that recovery does not silently downgrade assurance. If a help desk reset or fallback SMS path can re-enable access on its own, the control is weaker than the login method suggests.
Common mistake: Treating “MFA enabled” as a complete answer. Assurance depends on the specific factor, the recovery route, and the phishing resistance of the end-to-end flow, not just the presence of a second prompt.
Practitioner takeaway: SMS is better than passwords alone, but it is a compromise control, not a durable security destination; reserve it for lower-risk cases and move critical access to phishing-resistant methods as soon as practical.
Related resources from NHI Mgmt Group
- What is the difference between push-based MFA and phishing-resistant authentication?
- What is the difference between phishing-resistant MFA and traditional password-based authentication in government identity programs?
- What is the difference between certificate-based authentication and FIDO passkeys for phishing-resistant MFA?
- What is the difference between phishing resistant authentication and OTP-based MFA in an adversary-in-the-middle attack?