Skip to content
Tech News
← Back to articles

GitHub's 2FA is to become mandatory on September 2, 2026

read original more articles
Why This Matters

GitHub's move to make two-factor authentication (2FA) mandatory by September 2026 marks a significant step toward enhancing security in the software development ecosystem. This policy aims to protect user accounts and the broader software supply chain from malicious attacks, benefiting both developers and consumers by promoting a more secure digital environment.

Key Takeaways

Hey birdie-github!

We're reaching out to let you know that as announced last year, we will officially ([begin][1]) requiring two-factor authentication (2FA) for certain contributors on GitHub.com. You are receiving this notification because your account meets the criteria for the current enrollment group, and you have 2FA enabled already.

You don't need to do anything in response to this email. After September 2nd, 2026 at 00:00 (UTC), you will no longer be able to disable 2FA. If you disable 2FA before then, your access to GitHub.com will be restricted on this date until you re-enable 2FA. This email, and a dismissible banner on GitHub.com, will be the only notifications about this change.

For more information about this program, please take a look at ([our documentation][2]).

Making the software supply chain more secure is a team effort, and we couldn't do it without you. Your enrollment in 2FA is an impactful step in keeping the world's software secure.

To see this and other security events for your account, visit your account ([security audit log][3]).

If you run into problems, please contact support by visiting the GitHub ([support page][4]).

Thanks, The GitHub Team

[1]: https://github.blog/2023-03-09-raising-the-bar-for-software-security-github-2fa-begins-march-13 [2]: https://docs.github.com/authentication/securing-your-account-with-two-factor-authentication-2fa [3]: https://github.com/settings/security-log [4]: https://github.com/contact