Password Policy Generator
Generate a clear, modern company password policy based on NIST SP 800-63B — length, MFA, breached-password screening, lockouts and password managers.
How to use
- 1Enter your organization name and choose your requirements.
- 2Copy the policy into your handbook or IT policies and adjust as needed.
How it's calculated
Defaults follow NIST SP 800-63B: length over complexity, no forced periodic changes, screening against breached passwords, and multi-factor authentication.
Frequently asked questions
Should passwords expire every 90 days?
NIST advises against forced periodic changes — they lead to weaker, predictable passwords. Change them only when there's evidence of compromise.
Are complexity rules (symbols, numbers) required?
NIST recommends against composition rules. Longer passphrases are both stronger and easier to remember.
What minimum length should we use?
At least 8 characters with MFA, and 15 for single-factor passwords under the 2024 revision; many organizations choose 12–14 for everyone.