In short: offer SMS 2FA, and indeed push users reasonably firmly¹ into adding SMS recovery at the least because for almost all users that’s the right balance of convenience and security, but certainly don’t limit it to SMS, offering better methods like U2F and TOTP.
(Disclosure: I was employed by Fastmail for a few years, but these decisions had been made long before I got there.)
—⁂—
¹ When you set up 2FA, it forces you to add a recovery phone number, except that you can skip that by holding down Ctrl or something, undocumented but support will tell you if you complain about having to do it; or, after creation, you can just remove it again. So yeah, “reasonably firmly”.