MFA (Multi-Factor Authentication)
Definition
• Knowledge factor ("what I know") : password, PIN code, answer to a secret question, passphrase.
• Possession factor ("what I have") : phone that receives an OTP via SMS or via a TOTP application (Google Authenticator, Authy, 1Password), YubiKey or other FIDO2 key, certificate on smart card.
• Inherence factor ("what I am") : fingerprint, facial recognition, voice, iris. Implemented via native APIs of modern operating systems (Face ID, Touch ID, Windows Hello, Android BiometricPrompt).
MFA vs 2FA : 2FA is a strict subset of MFA — exactly two factors. MFA can combine two, three or more factors. Mass-market practice often confuses the two terms; in B2B and legal cybersecurity, MFA is the generic term.
MFA and electronic signature : advanced electronic signature (AES) requires strong authentication of the signer, which translates in practice to MFA (typically e-mail + OTP SMS). Qualified signature (QES) requires reinforced MFA — identity verification with identity document + possession factor (smart card or QSCD). The eIDAS regulation does not explicitly name MFA but requires it through strong authentication requirements.
Certyneo implementation : MFA mandatory for all administrator access (TOTP via Google Authenticator or e-mail OTP at choice). For signers, the e-mail + SMS OTP combination is applied by default on AES-level envelopes. See also OTP and strong authentication.
Frequently asked questions
What are examples of MFA?
The most common examples of multi-factor authentication: an OTP code received by SMS or email, a TOTP app (Google Authenticator, Microsoft Authenticator), a physical security key (YubiKey, FIDO2/WebAuthn), biometrics (fingerprint, face recognition), a professional smart card, or a push notification approved on mobile. MFA combines at least two factors from different families: something you know, something you have, or something you are.
What is the difference between MFA and 2FA?
2FA (two-factor authentication) is a special case of MFA that combines exactly two factors — typically password + OTP code. MFA refers to any combination of at least two factors and can stack more (password + OTP + biometrics). All 2FA is therefore MFA, but MFA can go further.
Is MFA mandatory for an advanced electronic signature?
The eIDAS regulation does not mandate MFA as such, but the advanced signature requires the signature to be uniquely linked to the signer and created under their sole control (art. 26). In practice this translates into strong authentication: Certyneo verifies the signer's access to their mailbox and then sends an OTP code by SMS — two distinct factors — before sealing the signature and its audit trail.
Related guides
Related terms
Ready to put these concepts into practice?
Certyneo allows you to create eIDAS-compliant signature envelopes in just a few clicks, with no installation required.
