Insight

Password policies that match current guidance: length, breached-password checks and no forced expiry

Many login pages still enforce rules that security guidance abandoned years ago: mandatory symbols, forced password changes every few months and blocked paste. Current guidance from NIST in the United States and the National Cyber Security Centre in the UK favours length, screening against breached passwords, password managers and multi-factor authentication.

Published by Somnium Digital

A wireframe of the Insight page: headline, supporting sections and a single call to action. Insight Modern password policies Get in touch 01 Why old password rule… 02 What current guidance… 03 Applying it to custom…

Why old password rules persist

Rules requiring an uppercase letter, a number and a special character, combined with changes every 90 days, became standard in corporate IT and were copied into countless websites and customer portals. They felt secure because they made passwords look complicated.

In practice, users responded predictably. They chose passwords like a word followed by a number and an exclamation mark, incremented the number at each forced change, wrote passwords down and reused them across services. Attackers know these patterns, and complexity rules did little against the most common attacks: reuse of passwords leaked from other sites and phishing.

What current guidance says

NIST Special Publication 800-63B, the US digital identity guideline for authentication, has for years advised against arbitrary composition rules and periodic password changes, and recommended checking new passwords against lists of commonly used, expected or compromised values. Its latest revision, finalised in 2025, strengthened these positions and set longer minimum lengths for passwords used as the only authentication factor.

The UK National Cyber Security Centre gives similar advice. It recommends against forced regular password expiry, supports password managers, encourages long passwords such as three random words for people who must remember them, and emphasises multi-factor authentication for important accounts.

Length over complexity
Allow long passwords and passphrases, with generous maximum lengths, rather than requiring specific character types.
No forced periodic changes
Require a change when there is evidence of compromise, not on a fixed schedule.
Breached password screening
Reject passwords that appear in known breach corpora or lists of common passwords.
Allow paste and password managers
Do not block pasting into password fields or autofill.
No password hints or knowledge questions
Avoid security questions whose answers can be researched or guessed.
Rate limiting
Limit failed login attempts to slow down guessing attacks.

Applying it to customer portals

For customer-facing logins, friction has a direct cost: abandoned registrations, forgotten passwords and support tickets. Modern guidance reduces friction and improves security at the same time.

Let customers use long passphrases and password managers, show clear feedback when a password is too short or found in a breach list, and explain why rather than showing a list of character rules. Offer a show-password option so people can check what they typed on mobile devices.

Screening against breached passwords can be implemented without sending the password to a third party, for example by using services that accept only a partial hash prefix and return matching suffixes for local comparison. Store passwords only with a modern, slow password hashing algorithm designed for that purpose.

Beyond passwords

Passwords remain vulnerable to phishing and reuse, however well they are chosen. Multi-factor authentication significantly reduces account takeover, and phishing-resistant methods such as passkeys and security keys offer the strongest protection.

For employee systems, single sign-on with multi-factor authentication through a central identity provider reduces the number of passwords people manage and gives administrators control over access. For customer portals, passkeys can replace passwords for users who adopt them while password login remains as a fallback.

Account recovery deserves the same attention as login. A strong password policy is undermined if a password reset relies on easily guessed security questions or an email link sent to an account an attacker already controls.

Handling compliance requirements

Some organisations keep old rules because an audit checklist, contract or industry standard appears to require them. Many standards have updated their expectations, but interpretations differ, and some frameworks still refer to older controls.

Where a requirement genuinely applies, document it and, if possible, meet its intent through stronger modern controls such as multi-factor authentication and breached password screening. Explaining the current guidance to auditors often resolves the question, because the underlying goal is reducing account compromise, not enforcing symbols.

Questions

Should passwords expire every 90 days?

Current NIST and NCSC guidance advises against forced periodic changes; passwords should be changed when there is evidence of compromise.

Are complexity rules still recommended?

No. Guidance favours length and screening against common and breached passwords over mandatory character types.

Should we block pasting passwords?

No. Blocking paste hinders password managers, which help users create strong, unique passwords.

What are three random words?

A UK NCSC suggestion for creating memorable long passwords by combining three unrelated words.

How can breached passwords be checked safely?

Using approaches that compare partial hashes locally, so the full password is not sent to a third party.

Is a strong password policy enough?

No. Multi-factor authentication and phishing-resistant methods such as passkeys provide much stronger protection.

Are security questions acceptable for recovery?

They are weak, because answers can often be researched or guessed. Stronger recovery methods should be used.

Where this sits in what we do

This article covers one decision inside a wider engagement. The solution page sets out how that engagement runs, what it includes and what it costs to find out.

Login rules frustrating customers without adding security?

We modernise authentication in portals and business systems with breached-password screening, multi-factor options, passkeys and safer recovery.

Get in touch

Tell us what you are trying to change

Describe the problem rather than the service — the two frequently differ, and working out which is which is the useful part of a first conversation. We reply within one working day, and if it is outside what we do well you will hear that in the reply rather than after a call.

We use what you send to reply to you. Nothing else, and no list.

WhatsApp