Overview
To comply with the European NIS2 Directive and strengthen IT security, Multi‑Factor Authentication (MFA) is being gradually introduced as mandatory for all reev Platform accounts.
All previous MFA settings (disabled, optional, or enforced) are now frozen. This means that you can no longer adjust the MFA policy.
After the rollout, login to the reev Platform will only be possible with active MFA. MFA applies to all system users of the web interface. The reev App for drivers is not affected.
Setting up MFA
Follow these steps to set up Multi‑Factor Authentication:
Download an authenticator app: Install an authenticator app of your choice on your mobile device.
Scan the QR code: Log in to the reev Platform and scan the displayed QR code with your authenticator app.
Enter the verification code: Enter the 6‑digit verification code from the app.
Name your device (optional): If you use multiple devices, you can name the current one for easier identification.
Save your backup codes: Save the displayed backup codes securely (copy, download, or print). They are used to recover access if you lose your authentication device.
After setup, each login requires the following information:
Email address
Password
6‑digit code from your authenticator app
Backup codes and account recovery
When MFA is activated for the first time, each system user receives a fixed set of single‑use backup codes:
The codes are only displayed once during setup.
They can be copied, downloaded, or printed.
Each code can be used only once.
Tip: Store your backup codes securely and separately from your mobile device. A password manager is a good option.
Reset MFA
If MFA needs to be set up again or login problems occur, administrators can reset a system user’s MFA directly in the reev Platform.
Only a platform administrator can reset another system user's MFA. If you are not the administrator of your organisation's reev account, contact your admin and ask them to follow the steps below.
Follow these steps to reset MFA for a system user:
Go to Administration -> Security Settings.
Find the relevant system user.
Reset the user’s MFA.
The next time the system user logs in, a new QR code for setting up MFA is displayed. The user can then set up MFA again using an authenticator app.
Note: Reset MFA if the system user has changed their mobile phone, can no longer use MFA, or the one-time code is not accepted during login.
⚠️ If your organisation has only one system administrator and that administrator has lost MFA access (e.g. lost phone, no backup codes), it is not possible to perform the reset from within the platform — an admin must be logged in to access Security Settings. In this case, our support team can assist with account recovery. Contact us via chat or the support form and let us know that you are the only administrator in your organisation.
Sample message for users
The following template can be used by administrators to inform all system users about the mandatory MFA rollout:
Subject: Mandatory introduction of Multi‑Factor Authentication (MFA) for your reev login
Dear colleagues,
In accordance with the European NIS2 Directive, Multi‑Factor Authentication (MFA) will be gradually rolled out and become mandatory for all reev accounts. This means that access to the reev Platform will soon require a second security factor.
After our organization’s transition, you will be prompted to set up MFA the next time you log in. Please have an authenticator app ready on your mobile device (e.g. Google Authenticator or Microsoft Authenticator) and follow the onscreen instructions.
Setup steps:
Scan the QR code
Enter the 6‑digit verification code
Save your backup codes
Once MFA is active, you will log in as usual with your password and the current code from your authenticator app.
Best regards,
Your reev Team
Frequently Asked Questions
When will MFA become mandatory?
The rollout started in June 2026. By August 2026, MFA will be active for all reev accounts.
Do I have to use MFA when signing in via Single Sign‑On (SSO)?
If you sign in using a Single Sign‑On (SSO) method and your provider already enforces MFA (e.g. Microsoft Entra ID or Google Workspace), the requirement is automatically met. No additional setup is needed.
During setup, my one-time code is being rejected as invalid – what can I do?
In most cases, this is due to a time discrepancy between your mobile device and our server. The codes are only valid for 30 seconds and are based on the current time. Please check the following:
Enable automatic time setting: Open your smartphone’s Date & Time settings and ensure that ‘Set automatically’ (or ‘Use network time’) is enabled.
Wait for a new code: Wait until a new code appears in your authenticator app and enter it immediately.
Scan the QR code again: Delete the existing entry in your Authenticator app and scan the QR code on the setup page again. If the page has been reloaded in the meantime, the old code is no longer valid.
Select the correct entry: If you have multiple accounts saved in your Authenticator app, make sure you are reading the code from the correct entry.

