The way to do that is to use a client-side certificate in combination with a username/password for authentication.
When I create an account on a website, these are the steps I should have to follow:
1. Choose a username and password
2. Upload a CSR
3. Get the client-side certificate
4. Add it to my local certificate store
When I log in, I should have to follow these steps
1. My client automatically chooses the correct client certificate to send based on the server certificate
2. If I need a passphrase to decrypt my private key, I enter it at a prompt
3. The server verifies the certificate the client sent against whatever CA they use
4. I enter my username/password
5. My credentials are verified and I'm logged in.
I shouldn't have to provide my phone number or email address as a second factor because those factors aren't under my control. The private key associated with the client certificate is under my control.