CME Group Rolls Multi-Factor Authentication Delivery Changes Into Production Across Trading and Support Services

CME Group is changing the telephony provider behind SMS and automated-call MFA codes, bringing new message formats and rotating originating phone numbers into production on September 12.

John Miller
Written by John Miller
Published
Share

CME Group is rolling changes to the delivery of multi-factor authentication one-time passcodes into production on Saturday, September 12, replacing the telephony provider used for SMS texts and automated phone calls. The change affects how codes are presented and where the messages appear to come from, but CME has not described it as a new MFA requirement or a change to the underlying access model.

Clients should see six-character authorization or verification codes in CME’s new message examples. SMS messages will state that the code expires in 10 minutes, while automated calls will repeat the verification code three times before disconnecting. The company also says originating phone numbers will rotate dynamically, so users should not rely on a single saved number for future MFA messages.

The rollout matters because CME Group Login is used to reach permissioned applications, APIs and other services, and MFA is required in most cases for entitled applications and APIs. CME says passcodes will continue to be delivered automatically when a login or another action requires MFA. The September 12 change is therefore mainly about the delivery path and presentation of telephony-based codes rather than an expansion of who must use MFA.

New SMS and voice formats arrive with rotating sender numbers

CME’s published examples show the most visible differences in the messages themselves. The new SMS format uses a six-character code and includes an explicit 10-minute expiration notice, replacing the shorter legacy wording. For automated calls, the new script gives a six-character verification code and repeats it three times before the call ends instead of asking the user to press a key to repeat or dismiss the message.

The change in originating numbers may be more operationally noticeable for some users than the wording. CME says the phone numbers used for SMS and voice delivery will rotate, and it specifically advises clients not to save a particular number as the expected source for future codes. That means the recognizable sender number is no longer a stable part of the login experience, even though the passcode still arrives through the same broad channels of text message or automated call.

CME had already made the change available for customer testing in its New Release environment before the production date. The company’s technology roadmap lists September 12 as the production date for the MFA update across a group of trading, post-trade, risk and reference-data services.

The same update spans Globex, EBS, BrokerTec and post-trade services

The roadmap applies the MFA change across CME Globex, EBS Market on CME Globex, BrokerTec Markets on CME Globex, CME STP, CME ClearPort, Risk Management and Monitoring, and CME Reference Data. Separate CME notices for those services repeat the same telephony-provider change, message-format update and rotating-number guidance, indicating that this is a shared authentication delivery change rather than a product-specific modification.

That breadth is important because the affected services sit at different points in a client’s workflow. Globex is CME Group’s electronic trading platform, EBS Market serves foreign-exchange trading, and BrokerTec serves fixed-income markets. CME ClearPort supports submission and clearing workflows for eligible privately negotiated trades, while CME STP automates post-trade processing and confirmation. Risk and reference-data services cover other operational tasks around market access and market information.

The notices do not say that the market protocols used to submit orders or receive market data are being altered by the MFA deployment. Instead, the common element is CME Group Login and the authentication step used to reach entitled applications and services. For firms, that distinction limits the scope of the change: the update is relevant to user access and telephony-based code delivery, not a redesign of the trading engines or market-data feeds themselves.

MFA remains part of CME’s existing access framework

CME Group’s login guidance says a single CME Group Login can be used for premium content, permissioned applications and other services. It also says MFA is required in most instances for access to entitled applications and APIs. CME separately documents Duo Mobile as another authentication method, while the September 12 notices focus specifically on one-time passcodes sent through SMS and automated phone calls.

Users who rely on SMS or voice codes should therefore expect a different-looking message and changing sender numbers without assuming that the authentication request itself is abnormal. At the same time, the rotating-number design makes the content and context of a login request more useful than recognizing a familiar caller or text sender. CME’s notices do not describe any change to the circumstances in which an entitled application asks for MFA.

CME’s user guidance also notes that SMS and phone-call authentication for numbers outside the United States requires activation through its Enterprise Application & System Entitlements team. That existing support model is separate from Saturday’s provider change, but it remains relevant for users who need telephony-based MFA on international numbers. Duo Mobile remains another documented path for users whose access setup supports it.

The company has separate support paths for login and production issues. CME Group Login support is handled through Enterprise Application & System Entitlements, while service notices direct production-environment issues to the Global Command Center. That gives firms a defined escalation route if the new delivery behavior creates an access problem after the production change begins.

As of September 12, the official CME materials reviewed for this story set the change for production that day and describe the expected client-facing behavior. They do not provide a separate post-deployment report declaring the rollout complete or reporting an incident. The supported conclusion is therefore that CME is putting the new MFA telephony delivery setup into production across the listed services, with the practical changes centered on code format, expiry wording and rotating originating numbers.

John Miller

About the author

John Miller

Economics Contributor

John Miller writes about the economic forces behind markets and financial decisions. He covers inflation, interest rates, employment, supply and demand, public policy and the channels through which economic changes affect investors, borrowers and households.

View author profile