The three factors
MFA combines factors from different categories: something you know (a password or PIN), something you have (a phone, an authenticator app or a security key) and something you are (a fingerprint or face). Two factors from the same category, such as two passwords, do not count as MFA. Two factor authentication (2FA) is MFA with exactly two factors.
Not all MFA is equally strong
Codes sent by SMS are better than nothing but can be intercepted. Authenticator apps are stronger. Security keys and passkeys based on FIDO2 are the strongest, because they resist phishing: they only work on the genuine website.
Why it matters
Stolen and reused passwords are among the most common ways into a company. MFA means a password alone is not enough to log in, which blocks most of these attacks.
Where it shows up in compliance
MFA is expected under ISO 27001 (Annex A 8.5), required by the ENS for many access types, listed in NIS2 risk management measures and routinely checked in SOC 2 audits and cyber insurance questionnaires.




