10DLC Will Do What Passkeys Couldn't
The security community has been saying for years that SMS 2FA is weak. SIM swapping, SS7 interception, social engineering. All real, all well documented.
That isn’t what’s going to kill it. In the US you now can’t send an authentication text without clearing a registration process that small teams & independent developers mostly can’t clear.
A week to send a six digit code

I spent over a week trying to register an OTP-only application with two providers. The app does one thing. It sends six digit codes. It got rejected repeatedly, and the reasons moved between rejections: not enough detail, questions about projected volume, requests for documentation that wasn’t mentioned in the application.
Under A2P 10DLC you register a brand, then register a campaign, describe the use case & wait on approval from the provider and then from the carriers. It’s sold as spam reduction, and what it delivers is fees, delays & a review process nobody can explain to you.
There’s no fast path for the most boring use case on the internet, which is send a code, verify the code, done.
The fees
Brand registration fees, campaign registration fees, per-message surcharges. None of it is much money at enterprise volume, which is presumably who the schedule was written around. Working out what a single OTP actually costs you means reading several documentation pages or talking to a salesperson, and the numbers move.
SMS has gone from a utility to a gated service.
What folks do instead
Authenticator apps, push approvals, passkeys, WebAuthn, FIDO2. All better than SMS, all more resistant to phishing, and the industry was heading that way regardless.
I’ve a feeling the move is going to be faster & messier than anyone planned, because it isn’t the better technology doing the pushing. Developers who can’t reliably send a text will switch to something. Most will pick something stronger. Some will bolt on a weaker fallback or drop the second factor entirely, because the easy path doesn’t run through a phone number any more.
10DLC was introduced to deal with A2P spam. The spam hasn’t gone anywhere. What’s gone is the ability to send a login code without a month of paperwork.