There is no perfect second factor. SMS reaches everyone, an authenticator app is more resistant and push is more convenient. We compare the three and suggest how to combine them by risk level.

What multi-factor authentication is and why it matters
Multi-factor authentication (MFA) requires, on top of the password, an additional proof of identity: something the user has (a phone, a device) or something they are (a fingerprint). Its effect is enormous: most unauthorised access happens with stolen or reused passwords, and a second factor stops it.
The question for a company is not whether to implement MFA, but with which method and for which operations. Each option carries different advantages and risks, and the best strategy usually combines them.
SMS OTP
A single-use code sent to the user handset. Its decisive advantage is coverage: it works on any phone, with no app, no data plan and no prior setup. It is the lowest-friction method for new users, for account recovery and for broad populations with diverse devices.
Its risks: SIM swapping (the attacker moves the number to another SIM) and phishing (the user reads the code out to an impostor). They are mitigated with copy that warns against sharing the code, attempt and resend limits, short expiry windows, additional risk signals and, for high-value operations, a second method. We cover the implementation in the article on SMS OTP authentication.
Authenticator app (TOTP)
An app (such as the standard authenticators) generates codes that change every 30 seconds from a key shared at enrolment. It depends on neither the network nor the phone number, which makes it immune to SIM swapping and usable offline. It is the preferred method for frequent users and high-risk operations.
Its limitations: it requires a smartphone, installing and configuring the app, and a recovery process if the user loses the device (which usually ends in an SMS OTP or human support). That initial friction reduces adoption among mass audiences.
Push notification
A notification inside the company own app that the user approves with a tap, sometimes with biometrics. It is the most convenient method and it can show context (which operation is being approved, and from where). It requires the user to have the app installed, an active session and a data connection.
Its characteristic risk is approval fatigue: users who approve without reading, or attackers who bombard with requests until one is accepted. It is mitigated with context verification (showing a number the user must select) and request limits.
Passkeys: the passwordless option reaching banking
Passkeys are credentials based on the FIDO2 standard: the device stores a cryptographic key that is unlocked with a fingerprint, face or PIN and only works on the legitimate site or app. That is why they resist phishing: there is no code the user can read out to an impostor.
Banks are starting to adopt them. In September 2026 Visa launched its Visa Payment Passkey at five public-sector banks in India, under the Reserve Bank of India authentication rules in force since April. Those rules are technology-neutral: banks must offer passkeys, but customers can keep using OTP if they prefer.
For a company in Mexico, the lesson is not to replace SMS but to add layers. A passkey requires a compatible device and prior enrollment; SMS remains the channel to onboard the customer, recover the account when they change phones and notify them of every transaction. Mexico’s CNBV has also just confirmed SMS as a channel for delivering authentication codes: we cover it in what changes for embedded banking.
How to combine them by risk
- Sign-up and phone verification: SMS OTP, for coverage and simplicity.
- Routine login from a known device: push if the user has the app; SMS otherwise.
- Sensitive operations (large transfers, changing personal details): authenticator app or push with context; SMS as the fallback with extra limits.
- Account recovery: SMS combined with another verification (email, questions, human support).
- Audiences without a smartphone or data plan: SMS as the only viable method.
The rule is to match the factor to the risk of the operation and to what the user can actually do, and to always keep an alternative method so legitimate customers are never locked out. In every scenario, SMS remains the universal safety net; which is why its delivery should be fast, traceable and secure. The Grupo Tecnophone API offers token authentication, authorised IPs and content encryption for exactly that purpose; read more in Developers.
See also: How to choose an SMS OTP provider in Mexico: 7 points to evaluate
Sources
- “Visa Payment Passkey Goes Live at Five India State Banks: OTP Attack Surface Eliminated”, Tech Times, September 19, 2026. Read article
- “Passkeys”, FIDO Alliance. Read source
Frequently asked questions
Need an enterprise SMS platform?
Grupo Tecnophone provides enterprise SMS messaging in Mexico, an API with sandbox and encryption, per-message delivery reports and a console for campaigns. Talk to an expert or read the developer documentation.


