This lesson covers the complete credential life-cycle of a ZIMRA Self-Service Portal (SSP) user account: how the password is first created, how it is routinely changed, how it is recovered when forgotten, and what happens when repeated failed attempts lock the account. The SSP at https://mytaxselfservice.zimra.co.zw is the public front-end of the Tax and Revenue Management System (TaRMS), and the password is the single key to everything a user can do in it — filing returns, making payments, requesting tax clearance, and corresponding with ZIMRA. The relevant portal pages all live in the Getting Started module: SSP Registration, Login to the Portal, Password Reset, SSP User Profile, Changing the Password, and User Inactivity and Logout.
Three operations that beginners habitually conflate are kept rigorously distinct throughout this lesson. Password creation happens once, at sign-up: after ZIMRA verifies the registration data, it emails a password-creation link to the registered address, and the user sets the first password by following it. Password change is the routine, authenticated operation — the user is logged in, navigates to Getting Started → Changing the Password, and enters the current password plus the new password twice. Password reset is the unauthenticated recovery operation — the user clicks Forgot Password on the login page, supplies a username or registered email, and receives an emailed reset link. A fourth state, the account lock, is triggered by repeated incorrect login attempts and is cured by waiting the prescribed period or contacting ZIMRA support — not by hammering the reset button.
No section of the Income Tax Act [Chapter 23:06] says the word "password". The legal weight of credential management is indirect but real: Section 5 (preservation of secrecy, with offences in Section 5(5)/(5a)) is the statutory reason every person has their own login; Sections 53–61 (representative taxpayers and the public officer) and Section 37A(10)–(11) (the self-assessment return is the assessment) mean that what is done under a login is attributed — to the user, and through the user to the taxpayer. And because every filing and payment deadline (P2 by the 10th, VAT 7 by the 25th, QPDs under Section 72, the four-month ITF 12C under Section 37A) is enforced regardless of whether the taxpayer could log in, a recovery delay is never an excuse — which is why this lesson treats password hygiene as a compliance control, not an IT nicety.
The recovery machinery has one critical dependency: the email address and phone number on the SSP user profile. The reset link goes to the registered email; browser verification codes go to the registered phone or email. A stale email address converts a thirty-second self-service reset into a support ticket with ZIMRA — potentially straddling a filing deadline. Keeping the profile current (Getting Started → SSP User Profile) is therefore the first rule of recovery, and the lesson closes with a deadline-day failure drill: every taxpayer should have at least two SSP users with submission rights, so that one locked account never strands a return.
Because the SSP's own online help was not reachable when this lesson was prepared, screen-level specifics (lock thresholds, link validity windows, password-complexity rules) are stated generally and flagged for verification against the live portal.
