Yes — every account sets it up at first sign-in, and it cannot be switched off.
It is requested whenever you sign in with your Sigill password. If you sign in with Google or Microsoft instead, Sigill relies on the verification your own identity provider performs — so whether you are prompted for a second factor then depends on how your organisation has configured Google Workspace or Microsoft 365.
If your organisation signs in through Google Workspace or Microsoft Entra ID, make sure multi-factor authentication is enforced there. That is where the control sits for those accounts.
Sigill uses one-time codes (TOTP) — six digits, changing every thirty seconds. They work with any standard authenticator app, including Google Authenticator, Microsoft Authenticator, 1Password, Bitwarden and Authy.