Wednesday, December 18, 2024

Mandatory Multi-Factor Authentication (MFA) on E-Invoice and E-Way Bill Portals: Key Updates

The GST Network (GSTN) has announced important updates regarding Multi-Factor Authentication (MFA) on the E-Invoice and E-Way Bill portals, effective from 1st January 2025. These updates aim to improve security across these platforms, in line with government guidelines. Here's a breakdown of the key changes and their timeline.

What is Multi-Factor Authentication (MFA)?

MFA adds an extra layer of security by requiring users to provide two or more verification factors to access their account. This could include:

  • Username and password (first factor)
  • OTP (One-Time Password) sent to the registered mobile number or email (second factor)

This helps ensure that only authorized users can access critical information on the portals.

MFA Rollout Timeline for E-Invoice and E-Way Bill Portals

Effective Date    AATO Threshold        MFA Requirement
1st January 2025        AATO exceeding Rs 20 Crores        Mandatory
1st February 2025        AATO exceeding Rs 5 Crores        Mandatory
1st April 2025        All other taxpayers & users        Mandatory

Important Notes for Taxpayers:

  • For Taxpayers with AATO exceeding Rs 20 Crores:
    MFA will be mandatory from 1st January 2025. These users must activate MFA before this date to ensure seamless access to the portals.

  • For Taxpayers with AATO exceeding Rs 5 Crores:
    Starting 1st February 2025, MFA will be mandatory. If your turnover is in this category, make sure you activate MFA by this date.

  • For All Other Taxpayers & Users:
    From 1st April 2025, MFA will become mandatory for everyone using the portals, regardless of their turnover. Therefore, it is crucial to start the activation process ahead of this deadline.

Steps to Enable MFA:

  1. Login to the Portal: Visit the E-Way Bill or E-Invoice portal and log in using your GSTIN and password.
  2. Update Your Mobile Number: Ensure that your GSTIN is linked to a valid mobile number for OTP delivery.
  3. Enable MFA: Follow the step-by-step guide on the portal to set up MFA. This typically includes verifying your mobile number and email address.
  4. Test the Process: Once MFA is activated, log in again to test that the system is working as expected.

Conclusion:

Starting from 1st January 2025, MFA will be rolled out in phases for taxpayers with varying turnover thresholds, ultimately becoming mandatory for all users by 1st April 2025. It is essential for businesses and taxpayers to activate MFA promptly to avoid any disruptions in using the E-Way Bill and E-Invoice portals. Detailed instructions are available on the respective portals for easy activation.