Review the security route
Check your password, registered phone number and email before your next login.
Gather what you need
Before you begin, make sure you can access your NS&I number, unique password and registered phone.
Follow this order
- Open NS&I by typing nsandi.com into your browser or opening the official app.
- Sign in with your NS&I number and your unique password.
- Enter a security code only when the genuine NS&I sign-in screen asks for it.
- Check the mobile number and email shown in your account details.
- Update old contact details before changing your network, number or phone.
- Sign out when using a shared computer or someone else’s device.
A strong password should be unique to NS&I, not one reused for your email, supermarket account or bank. Think of reused passwords as using one front-door key for several homes: one lost key can open more than one door.
A six-digit OTP confirms that you can receive a code on the registered route. It does not replace a strong password, and it must never be read aloud, forwarded or typed into a website opened from an unexpected message.
Secure your first login and trusted device
Create a unique sign-in and recognise when a trusted device is only a convenience.
Keep the three secrets separate
| Credential | What it does | What to do |
| Password | Starts your account login | Make it long and unique to NS&I |
| Six-digit OTP | Confirms a current sign-in or action | Use the newest code once, promptly |
| Six-digit PIN | Confirms the step NS&I presents | Keep it private and never disclose it |
Treat device trust with care
A trusted device is usually recognised through browser data, often called cookies. Cookies are small saved settings, like a coat-check ticket showing that this browser completed a prior check.
NS&I sign-in safety flow
1. Official site or app
→
2. Unique password
→
3. Latest six-digit OTP
→
4. Check account access
A trusted browser may skip some repeat checks. Private browsing or deleted cookies can remove that recognition.
Two-factor authentication adds an important second check, but it cannot make every risk disappear. A six-digit OTP can be delayed when there is poor signal, and a trusted device can stop being recognised after browser cookies are deleted, private browsing is used or a browser is updated. Do not weaken NS&I account security by sharing a device, leaving a browser signed in or choosing an easy password simply to avoid extra checks. Instead, keep your registered mobile number up to date, allow essential browser cookies on your own device, use a current browser and access NS&I only by typing nsandi.com yourself.
If a code arrives unexpectedly, treat it as a warning, not as a request to approve anything.
Fix failed codes and protect a lost phone
Match the symptom to one careful action, then secure the account if the phone is lost or replaced.
Solve the symptom you see
| Symptom | Likely cause | Action now |
| OTP has not arrived | Signal, network delay or old number | Wait between 1 and 2 minutes, check signal, then request one new code |
| Code is rejected | A later code was requested | Enter only the newest code received |
| Login keeps looping | Private browsing or blocked cookies | Leave private mode and try a current browser |
| Device is unknown | Browser or cookie change | Complete 2FA, then review account activity |
Act quickly after a phone change
If you have lost your phone, had it stolen or changed your number before updating it, do not keep requesting security codes or rely on a text message from an unknown source. Start from nsandi.com or the official NS&I app, rather than a link in an email or message, and use NS&I’s official contact route if you cannot complete the NS&I sign-in. Ask your mobile provider to secure the SIM if the handset or number may be compromised.
Once access is restored, check the registered mobile number, email address and other account details, change your unique password if there is any doubt about exposure, and never give a security code to someone offering to “recover” the account.
Frequently asked questions
Use these answers to decide your next safe action.
Why is my NS&I code not arriving?
Your code may be delayed by signal or network traffic, or the registered number may be wrong. Wait between 1 and 2 minutes before requesting one fresh code, then use only that latest code.
Can NS&I ask me for my OTP by phone?
No legitimate caller needs your one-time passcode to secure your account. End the call and contact NS&I through the official website if a caller asks for any six-digit code.
Why is NS&I not recognising my device?
Private browsing, deleted cookies, a new browser or stricter privacy settings can remove device recognition. Sign in through the official route and complete the requested check, then review your account if anything looks unfamiliar.
What should I do before changing my phone?
Update and confirm the mobile number in your NS&I account while the old phone still works. This normally takes between 10 and 20 minutes if you can sign in and receive the verification code.
Does 2FA protect my Premium Bonds prizes?
2FA makes unauthorised account access harder because a password alone is not enough. It does not change your Premium Bonds holdings, tax-free prize status or the ERNS prize draw.
Keep your account ready for the next login
Repeat three short checks every few months to keep future access straightforward.
⚠️ Do not delay a password change after a suspected phishing attempt, even if you did not disclose your OTP.
Every few months, carry out a short NS&I account security check. First, confirm that your registered mobile number and email address are current and that you can still access both; this is especially important before travelling, changing network provider or replacing a handset. Second, make sure your NS&I password remains unique and change it promptly if you have entered it on a suspicious page or reused it elsewhere. Third, review your Premium Bonds and account details for unfamiliar changes, and remove access to shared devices by signing out and clearing saved sign-in details where appropriate.
These checks support lost phone protection and make a future two-factor authentication request less likely to become an access problem.
Further reading
If you want to learn more about this topic, these sources may interest you: