CommSec multi-factor authentication, also known as MFA, is an additional security check when logging in to the CommSec website. MFA may ask for approval in the CommSec app after Client ID and password are entered.
This is a one-time set up for a device.




Once setup is complete, the CommSec app is a registered device for MFA.
SMS is only used to help set up the device. After that, website login requests will be required to be approved using the CommSec app.




Unknown login attempts



Multi-factor authentication is additional security when logging in to the CommSec website.
It uses two factors to help confirm the log in:
This helps protect an account from unauthorised access.
No. MFA is for CommSec website login only.
CommSec app log in can be completed using password, PIN or biometrics.
Not every time. After being approved for website login using MFA, an option can be selected to not be asked again to MFA on that browser for 7 days.
If there is no registered CommSec app device, CommSec website log in can continue using Client ID and password.
However, MFA is an additional security measure. You can download and set up MFA with the CommSec app to provide additional protection for website logins.
You can download the CommSec app on the new device and follow the steps to set up MFA again.
Access will be required to the mobile number registered to a CommSec account to receive the 6-digit SMS code. If access is not available to a registered device or mobile number, contact CommSec for further assistance.
First, check that notifications are turned on for the CommSec app in device settings. If a push notification still has not been received, open the CommSec app and check for the login approval request.
Check the internet connection and attempt the CommSec website log in again.
Try the following:
If MFA still isn’t working, you can contact CommSec for help.
If a CommSec app login request is received and is not recognised, select ‘No, it wasn’t me’.
This will decline the login attempt.
A password reset should then be completed and the account checked for any unusual activity. If anything suspicious is noticed or support is required, contact CommSec.
MFA has been introduced as an additional security measure to help protect CommSec accounts.
If the CommSec app has been set up as a registered device, CommSec website logins may require approval through the app.
If there is no registered CommSec app device, website log in can continue using Client ID and password only.
If help is needed with account access or MFA, contact us.
The SMS code is only used when setting up MFA on a device.
After a device has been set up, the CommSec app is used to approve website login requests.
Yes. You can set up more than one compatible mobile device for MFA.
Each device will need to be set up using the CommSec app and a 6-digit SMS code sent to the mobile number registered to your CommSec account.
© Commonwealth Securities Limited ABN 60 067 254 399 AFSL 238814 (CommSec) is a wholly owned but non-guaranteed subsidiary of the Commonwealth Bank of Australia ABN 48 123 123 124 AFSL 234945. CommSec is a Market Participant of ASX Limited and TMX Australia Exchange Pty Limited, a Clearing Participant of ASX Clear Pty Limited and a Settlement Participant of ASX Settlement Pty Limited.
The information on this page has been prepared without taking into account your objectives, financial situation or needs. For this reason, any individual should, before acting on this information, consider the appropriateness of the information, having regards to their objectives, financial situation or needs, and, if necessary, seek appropriate professional advice.
CommSec does not give any representation or warranty as to the accuracy, reliability or completeness of any content on this page, including any third party sourced data, nor does it accept liability for any errors or omissions.