I have had a bit of pushback from some of my free users, that feel it is unfair that 2FA is only available to paid users.
The reason for this is that at present we use an SMS-based 2FA system, so it costs us every time we send a message. No much, but it all adds up.
So that's the only reason.
I could introduce an email based OTP option, but that's not true 2FA, and they'd probably complain about that too. I don't have development capacity at the moment to integrate and test an authentication app option, although possibly in the future.
The costs if I did enable 2FA for all accounts (taking into account the fact that most probably wouldn't use it) aren't that high, so I'm minded to just do it.