One-time passwords sent by SMS or email are the weakest link in most client login journeys. They can be intercepted, relayed in real time, or defeated by a convincing phishing page. The circular sets a fixed date to retire them.
The deadline, and what it covers
- Replace one-time passwords and device binding with phishing-resistant methods.
- Deadline: as soon as practicable, and no later than 8 July 2027.
- Strengthen account monitoring and surveillance for suspicious activity.
- A separate SFC circular of 2 June 2026 covers AI-enabled cyberattack resilience.
What this means for you
The date is fixed, so the work is a project with a hard end, not a policy statement. Start with the client journey you cannot change quickly — legacy platforms, shared logins, and any flow where a third party controls the login screen.
What to do first
Map every route a client uses to log in and trade, including mobile apps and any white-label front end. Then confirm which of them can adopt passkeys or hardware-backed authentication before the deadline.