Password Policy Best Practices for 2025
About 2 min read
A password policy is a set of rules and standards governing the creation and management of passwords within an organization or service. It includes requirements such as minimum length, character-type rules, expiration periods, and history management. The latest guideline from NIST (the U.S. National Institute of Standards and Technology), SP 800-63B, has shifted toward emphasizing password length and randomness over forcing periodic changes.
Why Stricter Rules Do Not Mean Better Security
The difficulty of a password policy lies in the fact that what the rules directly produce is not the passwords themselves but the behavior of the users who follow them. When requirements are imposed, people tend to satisfy them in the easiest way they can still remember: capitalizing only the first letter, adding a symbol at the end, or incrementing a trailing digit at every change. Because these patterns are shared by many users, they are predictable, and attackers build their attacks on precisely such tendencies. A policy that looks strict on paper therefore offers little protection if the passwords actually created under it are weak. The criterion for evaluating a policy should not be how demanding the requirements are, but what kind of passwords users actually create under the rules and whether they can keep following them without strain. The recent shift in guidelines toward fewer memory-dependent requirements reflects this structure.
Modern Password Policies and NIST Guidelines
NIST SP 800-63B (2024 revision) calls for passwords of at least 8 characters (15 or more recommended) and does not recommend forcing periodic changes. As of 2025, many companies are revising their policies to align with this guideline. The traditional "change every 90 days" rule was a cause of weak passwords, where users simply changed the trailing digit. Instead of forcing periodic changes, the design is to require a change when a compromise has been confirmed. In addition, checking passwords against a blocklist of breached passwords is recommended, allowing known dangerous passwords such as "password123" to be blocked in advance.
The Order to Follow When Revising a Policy
When an organization revises its policy, the order matters: hand out the means to generate and store passwords before rewriting the requirements. A policy takes effect not on paper but at the moment users create and type passwords every day. A length requirement rebounds as a burden as long as people rely on memory, producing workarounds such as writing copies on paper or reusing similar strings. Once generation and storage can be delegated to a tool, the requirements can be tightened without adding to what anyone has to memorize, and inquiries to the reset desk do not pile up. When establishing a policy, it is important to consider it together with a company-wide rollout of a password manager. Designing a Corporate Password Policy explains concrete configuration examples by industry.
Effective Password Practices
Randomly generated passwords fully satisfy the requirements of modern password policies. As a countermeasure against credential stuffing, it is essential to use a different password for each service. Combined with a password manager, even long, random passwords are no burden to manage. A common misconception is that "a complex password equals a safe one," but predictable substitutions such as "P@ssw0rd!" are easily cracked by dictionary attacks. What truly matters is sufficient length and randomness.
Was this article helpful?