ACE Portal SMS authentication gives customs brokers, importers of record, and account administrators another way to receive login security tokens. Available as an optional method beginning September 12, 2026, SMS can improve access resilience, but firms should govern enrollment carefully and retain email authentication as a reliable fallback.
What the ACE Portal SMS Option Changes
An Additional Authentication Channel, Not a New Filing Requirement
The new capability allows an ACE Portal user to register a mobile telephone number and receive future authentication tokens by text message. The user must first complete a successful login using email authentication before registering the number. During subsequent login attempts, the user can generally select either email or SMS as the token delivery method.
This change is optional. Email authentication remains available, and organizations are not required to enroll every ACE Portal user in SMS authentication. Message and data rates may apply, depending on the mobile plan associated with the registered number.
For high-volume customs brokerage operations and import compliance teams, the practical benefit is channel redundancy. An unavailable corporate email system, delayed email security filtering, or limited remote access can interrupt time-sensitive Portal activity. SMS provides an alternative that may help authorized personnel regain access without waiting for email delivery issues to be resolved.
The change is limited to ACE Portal login authentication. It does not modify Automated Broker Interface filing procedures, entry processing, ACE report permissions, user entitlements, account structures, or CAPE and ACH enrollment workflows. Existing authorization boundaries remain in place after a user authenticates.
Organizations should therefore treat SMS enrollment as an access-management decision rather than a customs filing change. Brokerage IT teams, importer security personnel, and ACE account owners remain responsible for deciding which users may register numbers, what type of device is acceptable, and how registered numbers will be removed when personnel or responsibilities change.
How SMS Registration and Login Work
The Initial Enrollment Sequence
Enrollment begins with the established email authentication process. The user signs in to the ACE Portal, receives and enters the email-delivered security token, and then registers a mobile telephone number for SMS delivery. Completing email authentication first helps establish control of the existing login channel before a new delivery method is added.
The operational sequence is generally straightforward:
- Complete a normal ACE Portal login using email authentication.
- Register an eligible mobile number for SMS security tokens.
- Confirm that the number is entered accurately and can receive messages.
- During a later login, select email or SMS as the token delivery channel.
- Use Manage Preferences to edit or remove the registered number and related notifications.
Firms should test both delivery methods after enrollment rather than assuming the new channel works under every condition. SMS delivery can be affected by mobile carrier filtering, device settings, international roaming, geographic coverage, number type, or temporary telecommunications outages. Email should remain documented and usable as the primary fallback.
Training Users for Both Login Paths
Training should cover more than the registration click path. Users need to understand which number they are permitted to register, how to choose between token channels, where preferences are maintained, and whom to contact when neither method produces a usable token.
Night-shift teams, remote staff, and personnel responsible for urgent release or reporting work should practice both authentication paths. Current registration screenshots and navigation guidance are available through the CBP ACE Training webpage, while unresolved login issues can generally be directed to ACE.Support@cbp.dhs.gov.
Governance Controls for Brokers and Importers
Personal Devices Versus Monitored Operations Phones
A central policy decision is whether users may register personal mobile numbers or must use company-managed devices. Personal phones can provide direct, rapid access, but they introduce privacy, reimbursement, device-loss, and offboarding considerations. Company-managed phones offer stronger organizational oversight, although shared devices can create accountability problems if several employees can view the same authentication token.
A monitored operations phone may appear convenient for round-the-clock teams, but firms should avoid turning a shared token channel into an informal substitute for individual ACE credentials. ACE Portal accounts should remain individually assigned, and authentication practices should support traceability. Passwords and user accounts should never be shared merely because a team shares responsibility for a customs function.
Access Inventory and Offboarding Requirements
Every SMS registration should be recorded in the organization’s access inventory. At a minimum, the record should identify the ACE user, registered number, device ownership type, enrollment date, business owner, and most recent review date. Sensitive details should be protected in accordance with the company’s security and privacy policies.
Offboarding procedures should explicitly require the removal or update of the registered number through Manage Preferences. This control is important when an employee leaves, changes roles, replaces a device, transfers a telephone number, or no longer requires ACE Portal access. Disabling corporate email alone may not fully address a previously registered SMS channel.
Periodic access reviews should verify that:
- Each active user still requires ACE Portal access.
- The registered telephone number remains accurate and authorized.
- Email authentication continues to function as a fallback.
- Shared or operational devices have defined custodians.
- Lost, replaced, or reassigned devices are handled promptly.
- Internal support teams know the escalation path for login failures.
SMS increases convenience and resilience, but it should operate within the same identity governance framework applied to credentials, permissions, and privileged trade systems.
Frequently Asked Questions
Is ACE Portal SMS Authentication Mandatory?
No. SMS authentication is an optional token delivery method. Users can generally continue receiving login tokens by email, and organizations can decide whether SMS enrollment is appropriate for their security policies and operating model.
Does SMS Authentication Change ACE Filing or Reporting Permissions?
No. The option affects how a user receives a login token. It does not change ABI transmissions, entry filing requirements, ACE report access, account permissions, or other entitlements assigned to the user.
Can a User Keep Email Authentication After Registering a Phone?
Yes. Email remains available as an alternative authentication channel. Maintaining a tested email path is advisable because SMS delivery may be disrupted by carrier, device, coverage, or geographic limitations.
Where Can a Registered Phone Number Be Changed or Removed?
Users can generally edit or remove their telephone number and associated notifications through Manage Preferences in the ACE Portal. Firms should incorporate this step into device-replacement and offboarding procedures.
Should a Brokerage Use a Shared Operations Phone?
A shared operations phone may support shift coverage, but it can weaken accountability if controls are unclear. Firms should define device custody, prohibit credential sharing, document authorized users, and determine whether individually managed company devices provide better traceability.
Who Should Handle ACE Portal Login Problems?
Internal IT or security teams should first confirm email availability, SMS delivery, device settings, and the user’s registered preferences. Issues that cannot be resolved internally can generally be escalated to ACE.Support@cbp.dhs.gov.
How Stable Software Can Help
Strengthen Trade Operations Beyond the Login Screen
ACE Portal SMS authentication improves token delivery flexibility, but resilient customs operations require broader control over data, workflows, user responsibilities, and exception handling. Stable Software helps importers and customs brokers automate trade processes, reduce manual work, and create more consistent operational oversight across high-volume environments.
By connecting access procedures with documented workflows, structured data, and reliable process controls, firms can reduce disruption when personnel, devices, or authentication channels change. Trade leaders can also strengthen accountability without slowing the teams responsible for time-sensitive customs activity. Learn how Stable Software can support a more automated, controlled, and scalable customs operation.
Resources
| Type | Resource |
|---|---|
| Primary CSMS | CSMS #69896141 — SMS Option Now Available for ACE Portal Login Authentication |




