Short answer
Not yet. Civic.ly does not currently ask for a second factor (like a one-time code) every time you log in — you sign in with your email and password. Multi-factor authentication is something we plan to add, but it isn't live today.
The one time you do enter a code is when you first set up your account — that's a one-off step to verify your email address. After that, it isn't asked for again, so it isn't acting as MFA on your day-to-day logins.
Detail
If your IT team or a Cyber Essentials / Cyber Essentials Plus assessor asks "is MFA enforced on Civic.ly?", the accurate answer is no, not at present — it's on our roadmap. It's a common question from councils going through that certification, so do ask us if you need it confirmed in writing for your assessment.
A quick way to tell the difference:
- Account setup (one-off): the first time you access your account you enter a verification code we email you, then set your password. This confirms your email — it happens once.
- Everyday login: email + password only. No extra code is requested.
- MFA (not yet available): a second factor requested at each login (for example a code from an authenticator app). This is what we plan to add in future.
If MFA matters for your council, let us know and register your interest at ideas.civic.ly — that helps us prioritise it.
Watch-outs
- The setup code isn't MFA. Because you enter a code when you first get in, it's easy to assume MFA is already on. It isn't — that code is a one-time email verification at sign-up.
- Resetting your password isn't a second factor either. You can reset your own password from the login screen, but that's account recovery, not MFA. See How do I reset a Civic.ly password?.