Does a master list exist of companies that don't use SMS, or allow the user to exclude it? Otherwise it seems like most 2FA is just opening up a much easier attack vector (social engineering a phone number port) vs guessing a long, random, unique password. A password manager with browser plugin (or iCloud Keychain) mostly solves the phishing issue if you stop a second to think on the rare occasions when you need to manually copy/paste because of a weird subdomain or partner domain.
I've been 'about to' set up 2FA for over a decade now, but it always seems like a bad idea.
Edit: Also, who's to say customer service agents won't/don't fallback to sending an SMS reset code even if the account supposedly requires a dongle or app for 2FA.