SMS OTPs are vulnerable to SIM-swap fraud, SS7 interception, and social engineering, so they do not provide strong assurance when used alone. They also create weak device binding because the factor is tied to a phone number rather than a trusted device or user context. Regulated sectors increasingly require phishing-resistant, auditable authentication instead.
Why This Matters for Security Teams
SMS-based one-time passwords look simple, but they do not meet the assurance bar required in regulated environments because the control is tied to a phone number, not a verified device or a phishing-resistant authenticator. That makes them vulnerable to SIM-swap fraud, SS7 interception, and social engineering. Current guidance increasingly points toward stronger authentication under frameworks such as NIST Cybersecurity Framework 2.0, where identity assurance, resilience, and monitoring are treated as operational controls rather than convenience features.
For security teams, the issue is not only theft of the code. It is the way SMS OTPs weaken auditability, create inconsistent device binding, and leave organisations unable to prove that the second factor belonged to a trusted authenticator at the time of access. NHIMG research on Ultimate Guide to NHIs — Regulatory and Audit Perspectives shows how regulated environments increasingly expect demonstrable control over identity events, not just successful logins. In practice, many security teams encounter SMS OTP weakness only after account takeover or a failed audit review has already exposed the gap.
How It Works in Practice
Moving away from SMS OTPs usually means replacing them with phishing-resistant authenticators and stronger identity binding. In most regulated environments, the preferred direction is a combination of hardware-backed authenticators, device trust, and risk-based policy evaluation at login. This aligns with modern identity guidance and with the practical lifecycle concerns described in Ultimate Guide to NHIs — Lifecycle Processes for Managing NHIs, where lifecycle control and revocation are treated as first-class requirements.
In practice, teams should evaluate authentication against the following requirements:
- Phishing resistance, so the factor cannot be replayed through a fake login page.
- Device binding, so access is tied to a trusted endpoint rather than a phone number alone.
- Strong recovery paths, so reset and fallback flows do not become the new weakest link.
- Central logging, so authentication events can be reviewed for audit and incident response.
- Policy enforcement, so higher-risk access can require step-up controls or block access outright.
Standards bodies now treat identity assurance as part of a broader security architecture, not a standalone login feature. For implementation planning, teams should map their target state to the NIST Cybersecurity Framework 2.0 and then phase out SMS where compensating controls cannot make the risk acceptable. This guidance breaks down in highly constrained user populations, such as shared-device field operations or low-connectivity environments, because recovery and fallback workflows can reintroduce the same weak assurances the migration is meant to remove.
Common Variations and Edge Cases
Tighter authentication often increases onboarding and support overhead, so organisations have to balance user friction against regulatory assurance. That tradeoff matters most during migration, when legacy applications, emergency access, and third-party workflows still depend on SMS as a fallback. Best practice is evolving, but current guidance suggests that SMS should be treated as transitional at most, not as the primary second factor in regulated access paths.
There are a few edge cases worth calling out. SMS can still appear in low-risk notification workflows, but that is different from using it to satisfy authentication requirements. Some organisations also keep SMS as a break-glass recovery option while they deploy stronger methods, but that approach needs strict monitoring, short recovery windows, and clear approval rules. NHIMG’s research on Top 10 NHI Issues reinforces the broader pattern: weak identity controls tend to persist where governance is fragmented and exceptions become permanent. In regulated settings, the real risk is not only the factor itself, but the false sense of compliance it creates when auditors see “2FA” without understanding the underlying assurance level.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Non-Human Identity Top 10 address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-63, NIST Zero Trust (SP 800-207) and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AA-1 | Identity proofing and authentication assurance are central to replacing SMS OTPs. |
| NIST SP 800-63 | AAL2 | SMS OTPs generally fail phishing-resistant expectations for higher assurance access. |
| NIST Zero Trust (SP 800-207) | Policy decision point | Access should be evaluated by context and trust, not by a weak one-time code alone. |
| OWASP Non-Human Identity Top 10 | NHI-01 | Weak authentication and poor lifecycle control are core identity risks in regulated systems. |
| NIST AI RMF | GOVERN | Authentication change needs governance, accountability, and risk decisions across the lifecycle. |
Map each application to an assurance level and retire SMS where AAL2+ phishing resistance is required.
Related resources from NHI Mgmt Group
- When do NHI access reviews create more value than a one-time cleanup?
- How do organisations reduce the dwell time of exposed credentials at scale?
- Should organisations still use one-time passwords for MFA?
- How should organisations move away from password-based authentication without hurting user productivity?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on August 24, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org