2024 NIST Password Guidelines: Enhancing Security Practices
ID: c4d35444-b4c0-5e91-aec8-726e33c47463
STIX ID: report--c4d35444-b4c0-5e91-aec8-726e33c47463
Feed Name: Security Boulevard
Date Published: 2024-09-23
Date Updated: 2026-04-22
Author: Robyn Ferreira, Compliance Success Manager, Scytale
This blog post outlines anticipated 2025 updates to NIST password guidelines, shifting emphasis from complexity to longer passphrases (12-16 characters), eliminating mandatory periodic password changes except after evidence of compromise, expanding support to all ASCII and Unicode characters, prohibiting password hints, encouraging password managers, and aligning with user behavior and the NIST Cybersecurity Framework 2.0; it highlights expected benefits such as stronger security with better usability, fewer resets, improved compliance, and reduced risk from weak or reused passwords.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
