Why are SMS OTPs costly for enterprises?

Vincent Delitz

Vincent

Created: January 8, 2025

Updated: April 19, 2025

introducing passkeys large scale overview

Read the full article

Learn how to implement passkeys as phishing-resistant MFA for large-scale consumer deployments and boost security as well as user convenience.

Read the full article

Already read by 5,000+ enterprise security leaders.


Why Are SMS OTPs Costly for Enterprises?#

SMS one-time passwords / passcodes (OTPs) have been a popular method for multi-factor authentication (MFA), but they impose significant costs on enterprises. Here's why:

why are sms otps costly for enterprises

1. Per-Message Fees#

  • Every SMS OTP sent incurs a fee, which can accumulate rapidly for organizations with millions of users.
  • For businesses with international customer bases, cross-border SMS delivery is even more expensive due to higher carrier charges.

2. High Volume of SMS OTPs#

Large-scale consumer deployments require frequent SMS OTPs for account logins, sign-ups, and recovery, increasing the volume - and the cost.

3. Fraudulent SMS Requests (AIT)#

Attackers exploit vulnerabilities like artificially inflated traffic (AIT), generating fake OTP requests to drive up SMS costs maliciously.

Enterprise Icon

Get free passkey whitepaper for enterprises.

Get for free

4. Operational Costs#

  • SMS OTP delivery failures lead to support tickets, requiring customer service intervention to resolve issues.
  • Addressing these failures adds to operational overhead and frustrates users.

5. User Preference Challenges#

Many users prefer SMS OTPs for convenience, making it difficult for organizations to transition to cheaper alternatives like authenticator apps without compromising UX.

How Passkeys Help Reduce Costs#

Passkeys eliminate the need for SMS OTPs entirely by relying on secure, phishing-resistant authentication mechanisms. By reducing dependency on SMS, enterprises can save up to 90% in OTP-related expenses while enhancing user experience.

introducing passkeys large scale overview

Read the full article

Learn how to implement passkeys as phishing-resistant MFA for large-scale consumer deployments and boost security as well as user convenience.

Read the full article

Already read by 5,000+ enterprise security leaders.

Add passkeys to your app in <1 hour with our UI components, SDKs & guides.

Start for free

Enjoyed this read?

🤝 Join our Passkeys Community

Share passkeys implementation tips and get support to free the world from passwords.

🚀 Subscribe to Substack

Get the latest news, strategies, and insights about passkeys sent straight to your inbox.

Share this article


LinkedInTwitterFacebook