How Strong Should Your Password Be in 2026?

Password advice has shifted significantly in recent years. The old rules — 8 characters, one number, one symbol, change it every 90 days — are largely outdated. Here's what actually matters now, based on current NIST guidance.

Length beats complexity

According to NIST's updated password guidelines, length is the single biggest factor in password strength — more important than mixing in symbols or capital letters. The current recommendation is a minimum of 8 characters, with 15 or more recommended, up to 64 characters allowed. A long, simple passphrase is generally harder to crack than a short password packed with special characters.

Complexity rules are on their way out

Forced requirements for specific character types (at least one symbol, one number, one uppercase letter) are no longer considered best practice. They tend to push people toward predictable patterns — like swapping "a" for "@" — that don't actually add much real security, while making passwords harder to remember.

Stop changing passwords on a schedule

Mandatory password resets every 60 or 90 days are also outdated advice. Current guidance recommends changing a password only when there's actual evidence it may have been compromised — not on a fixed calendar. Scheduled resets tend to result in weaker, more predictable passwords as people run out of new ideas.

Use a password manager, and consider MFA

The practical way to follow this advice — a long, unique password for every single account — is a password manager. It removes the need to remember dozens of passwords and makes reuse unnecessary. On top of that, multi-factor authentication (MFA) adds a second layer of protection, ideally using a phishing-resistant method like a hardware key or passkey rather than SMS codes.

Generate a strong password

Use the Password Generator to create a random password up to 128 characters long, with full control over which character sets to include. For most accounts, a length of 15+ characters with all character sets enabled is a solid, low-effort default that follows current best practice.

FAQ

Do I still need numbers and symbols in my password?

Current NIST guidance no longer requires mandatory complexity rules like forced special characters. Length matters more than character variety — a long passphrase without symbols is generally stronger than a short password stuffed with them.

Should I still change my passwords every 90 days?

No. NIST's updated guidance recommends against forced periodic password resets on a fixed schedule, since it tends to push people toward weaker, more predictable passwords. Change a password when there's actual evidence of a breach, not on a calendar.

Is a password manager actually necessary?

For most people, yes. It's the only realistic way to use a long, unique password for every account without reusing or forgetting them. Reused passwords are one of the most common ways accounts get compromised when an unrelated site suffers a data breach.