Organisations should shift from enforcing arbitrary character mixes to requiring longer passwords or passphrases, then pair that policy with multi-factor authentication and user education. The goal is to reduce predictable patterns, password reuse, and reset burden without making passwords impossible to remember. A strong policy should balance usability and resistance to brute force attacks, especially in environments where weak passwords drive breach risk.
Why NIST’s shift matters for password policy
NIST’s move away from mandatory character-complexity rules reflects a practical reality: the strongest password policy is not the one that looks hardest to satisfy, but the one that produces secrets people can actually create, remember, and use safely. Complexity requirements often push users toward predictable patterns, write-downs, and reuse across systems.
The better objective is to increase resistance to guessing and reuse without making authentication brittle. That usually means longer passwords or passphrases, screening against known-breached or commonly used values, and reducing friction that drives unsafe workarounds. Good policy design should be measured by real security outcomes, not by whether every password contains a symbol.
For a baseline reference on modern password guidance, organisations can use Password Security and Password Manager Guide, which aligns policy choices with current credential abuse patterns and practical password management.
What to replace complexity rules with
A modern policy should emphasise length, usability, and resistance to common attack paths. Longer passwords or passphrases increase search space far more effectively than arbitrary character mixtures, especially when users choose memorable phrases instead of slight variations on a weak base word. In practice, this makes passwords easier to adopt consistently and harder to guess at scale.
That policy should also block obviously unsafe choices. Screening against breached-password lists, disallowing obvious company names or seasonal patterns, and discouraging reuse across applications all help reduce the value of stolen credentials. The best policies also support password managers, because managers make unique high-entropy passwords realistic rather than aspirational.
- Set minimum length to encourage passphrases rather than short, complex strings.
- Reject known-compromised and commonly guessed passwords.
- Allow all printable characters instead of forcing special-character patterns.
- Support password managers so users can maintain unique credentials per system.
Why usability and MFA matter as much as the password rule
Password policy cannot carry the whole control burden by itself. If the environment is exposed to phishing, credential stuffing, spraying, or reuse from other breaches, multi-factor authentication materially reduces the chance that a stolen password becomes a full account compromise. The policy should therefore be paired with authentication strength that reflects the account’s risk.
For user-facing identity controls, NIST’s digital identity guidance is a useful anchor for deciding how password rules fit into the broader authentication stack. Organisations can use NIST SP 800-63 Digital Identity Guidelines to align password policy with authenticators, assurance expectations, and phishing-resistant options where appropriate.
In parallel, the operational side matters. A policy that forces frequent resets, arbitrary symbols, or inconsistent rules across systems often increases help desk load and encourages user shortcuts. The right measure is whether the policy lowers account takeover risk while keeping legitimate access predictable and supportable.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-63, NIST CSF 2.0, NIST SP 800-53 Rev 5 and CIS Controls v8 set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-63 | AAL — Authenticator Assurance Levels | Modern password policy should fit authenticator strength and assurance decisions. |
| Recommendation — Align password requirements with authenticator assurance and add stronger options where risk is higher. | ||
| NIST CSF 2.0 | PR.AA-05 — Authentication Factors | MFA is a key companion control when password rules are simplified. |
| Recommendation — Implement multi-factor authentication to reduce the impact of stolen or guessed passwords. | ||
| NIST SP 800-53 Rev 5 | IA-5 — Authenticator Management | Password length, reset handling, and lifecycle controls sit under authenticator management. |
| Recommendation — Enforce authenticator rules that support length, uniqueness, and safe credential lifecycle handling. | ||
| CIS Controls v8 | CIS-5 — Account Management | Password policy changes affect account access, reuse, and recovery behaviour. |
| Recommendation — Standardise account access practices and reduce risky password reuse through central policy. | ||
Practitioner Guidance
What to prioritise: Replace composition rules first, then verify that the new policy enforces length, breach screening, and unique-password support before tightening anything else. If users can still choose short or reused passwords, the policy is not yet doing the work you think it is.
What to verify: Check whether password reset rates, lockouts, and help desk tickets change after the policy update. A good rollout usually reduces friction without increasing successful brute force or reuse-driven compromise.
Common mistake: Treating “no complexity rules” as “weakened security.” In practice, removing brittle rules is often the step that makes stronger user behaviour more likely, especially when MFA and password manager support are in place.
Practitioner takeaway: The right password policy is less about forcing visible complexity and more about making weak, reused, and guessable passwords harder to survive in a real attack path.
Related resources from NHI Mgmt Group
- How should organisations update password policies when standards move toward longer passphrases and away from arbitrary expiration?
- What breaks when organisations rely only on password complexity rules?
- What breaks when organisations leave old Group Policy Preferences password policies in place after patching?
- Why do password complexity rules still leave organisations exposed to credential stuffing?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 28, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org