NIST Password Policy Generator
Stop forcing your employees to change their passwords every 90 days. Generate a modern, secure policy based on the latest National Institute of Standards and Technology (NIST) guidelines.
Policy Settings
NIST Configuration
NIST recommends at least 8, but 12-15 is preferred for passphrases.
Generated Policy Preview
# [Company Name] - NIST-Compliant Password Policy
**Effective Date:** 8/10/2026
## 1. Purpose
The purpose of this policy is to establish a secure, modern, and user-friendly standard for creating and managing passwords at [Company Name], in accordance with the latest guidelines from the National Institute of Standards and Technology (NIST SP 800-63B).
## 2. Password Requirements (The "Passphrase" Rule)
We emphasize length over complexity. Employees must use "passphrases" (multiple words strung together) rather than short, complex passwords that are hard to remember.
* **Minimum Length:** Passwords must be at least 12 characters long.
* **Maximum Length:** Passwords can be up to 64 characters long to support passphrases.
* **Complexity:** We DO NOT force arbitrary complexity rules (e.g., you do not *have* to include a special character or a number, though you may if you wish).
## 3. Password Expiration (No 90-Day Rotations)
* **No Forced Expiration:** In alignment with NIST guidelines, [Company Name] no longer requires employees to arbitrarily change their passwords every 30, 60, or 90 days.
* **Exception:** Passwords will only be forcibly reset if there is evidence or suspicion of a compromise (e.g., if a data breach occurs or a laptop is stolen).
## 4. Multi-Factor Authentication (MFA)
* **Strictly Required:** Multi-Factor Authentication (MFA) is mandatory for all accounts accessing company data. An authenticator app or hardware security key is highly preferred over SMS-based codes.
## 5. Banned Passwords
* **Dictionary Checks:** The IT department will actively screen new passwords against a "breached password dictionary." If you attempt to use a password that has been previously compromised on the internet (e.g., "password123"), the system will reject it.
## 6. Password Managers
* **Approved Use:** We recognize that humans cannot memorize dozens of unique 12-character passphrases. Employees are highly encouraged to use the company-approved Password Manager to generate and store their credentials.
* **Never** store passwords in unencrypted Word documents, Excel spreadsheets, or on sticky notes attached to monitors.
## 7. Reporting Compromise
If you believe your password has been phished, guessed, or stolen, you must reset it immediately and contact **IT Support**.
Why upgrade your password policy?
For decades, IT departments forced employees to create complex passwords (like P@ssw0rd1!) and change them every 90 days. The National Institute of Standards and Technology (NIST) recently updated their official guidelines (SP 800-63B) because these old rules actually make security worse.
The Old Way (Bad)
- • Require a mix of upper, lower, numbers, and symbols.
- • Force users to change passwords every 90 days.
- • Result: Employees write passwords on sticky notes, or just change
Spring2023!toSummer2023!.
The NIST Way (Good)
- • Require long "passphrases" (12+ characters).
- • Never force password expirations unless there is a known breach.
- • Screen new passwords against known breached lists.