Search tools

Search for a command to run...

Password Policy Generator

Generate a clear, modern company password policy based on NIST SP 800-63B — length, MFA, breached-password screening, lockouts and password managers.

How to use

  1. 1Enter your organization name and choose your requirements.
  2. 2Copy the policy into your handbook or IT policies and adjust as needed.

How it's calculated

Defaults follow NIST SP 800-63B: length over complexity, no forced periodic changes, screening against breached passwords, and multi-factor authentication.

Frequently asked questions

Should passwords expire every 90 days?

NIST advises against forced periodic changes — they lead to weaker, predictable passwords. Change them only when there's evidence of compromise.

Are complexity rules (symbols, numbers) required?

NIST recommends against composition rules. Longer passphrases are both stronger and easier to remember.

What minimum length should we use?

At least 8 characters with MFA, and 15 for single-factor passwords under the 2024 revision; many organizations choose 12–14 for everyone.