logo

NIST Drops Password Complexity, Mandatory Reset Rules

ID: a204a714-1ae2-549d-b624-67b5a273f5b9

STIX ID: report--a204a714-1ae2-549d-b624-67b5a273f5b9

Feed Name: Dark Reading

Date Published: 2024-09-25

Date Updated: 2026-04-21

Author: Edge Editors

...
...

Per the NIST SP 800-63-4 draft, credential service providers and verifiers shall not require specific character-type composition or periodic password changes; instead they should require a minimum of 8 characters (15 recommended), allow passwords up to at least 64 characters including ASCII/Unicode, stop using knowledge-based authentication, and only force password changes when there is evidence of compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.