Never use 2FA alone. You always need a 3rd factor in case you lose one of the others which is more likely than losing a single password. I don't know why websites don't enforce this.
In case of TOTP one way of doing that is to scan the QR code on two devices. Many services only allow 1 MFA hardware/virtual device (I'm looking at you, AWS...)