New NIST Password Guidelines: What Houston Businesses Need to Know
NIST’s new guidelines favor longer passwords and blocklists over complexity rules and forced changes, reshaping password security practices
The updated NIST Digital Identity Guidelines overturn decades of password advice. Here is what actually changed - and what your business should do about it.
The National Institute of Standards and Technology has rewritten how passwords should work - and the new advice contradicts most of what corporate IT policies have enforced for the past two decades.
NIST is a non-regulatory federal agency whose cybersecurity guidelines are adopted widely across both the public and private sectors. When NIST changes its Digital Identity Guidelines, password policies at banks, hospitals, and businesses eventually follow. The latest revision is a big one: it moves away from complexity tricks and constant resets, and toward length, screening, and secure storage.
What NIST Actually Changed
The biggest shift is not a single rule - it is the strength of the language.
NIST replaced much of its advisory "should not" wording with mandatory "SHALL NOT," turning long-standing recommendations into requirements for the systems that check your passwords.
In NIST's guidelines, two roles do the work: verifiers, which confirm a login attempt is valid, and credential service providers (CSPs), which issue and manage the credentials. In most organizations, the IT or identity team plays both parts. The new draft directs firm, testable requirements at them - "SHALL" and "SHALL NOT" signal mandatory practice, not friendly guidance. For a business, that means these are the standards an auditor or a cyber-insurance underwriter will increasingly expect you to meet.
The Password Myths NIST Just Retired
Four rules almost everyone still enforces - and what NIST now says instead.
The habits that felt like good security - forced expiration, required symbols, security questions - are exactly the ones NIST now tells you to drop, because they push people toward weaker passwords, not stronger ones.
Forced 90-day resets are out. Making people change passwords on a schedule pushes them toward small, guessable tweaks - "Spring2024!" becomes "Summer2024!" NIST now says do not require periodic changes; force a reset only when there is evidence a password has been compromised.
Composition rules are out. Demanding a mix of uppercase, numbers, and symbols reliably produces the same weak patterns and endless password-reset tickets. NIST says do not impose those rules. A long passphrase is both stronger and easier to remember.
Security questions are out. The name of your first pet or the street you grew up on is often public or easy to guess, so NIST prohibits verifiers from using knowledge-based authentication and password hints. Instead, prospective passwords should be screened against blocklists of known-breached and commonly used passwords.
Still Forcing Quarterly Password Resets?
If your policies still look like 2010, you may be failing the exact standards auditors and insurers now check for. A free assessment shows you where you stand.
Get Your Free Assessment →The New NIST Password Rules, Plainly
What the guidelines actually require, translated out of the standards language.
Stripped of the jargon, NIST's password requirements come down to length, screening, and secure handling - not complexity theater.
- Length over complexity. Require at least 8 characters, recommend 15 or more, and allow passwords of at least 64 characters so people can use real passphrases.
- Accept the full keyboard. Allow all printable ASCII characters, the space character, and Unicode - each Unicode character counts as one toward the length.
- No composition rules. Do not require particular mixes of character types.
- No scheduled expiration. Do not force periodic changes; require a reset only on evidence of compromise.
- No hints or security questions. Do not store hints an unauthenticated visitor could reach, and do not use knowledge-based questions.
- Screen against blocklists. Check every new or changed password against a list of known commonly used, expected, or compromised passwords.
- Store it securely. Salt and hash passwords with a suitable scheme so they resist offline attacks, and verify the entire password without truncating it.
The through-line is simple: make it easy for people to choose a long, unique password, screen out the ones already known to attackers, and protect what you store. That is more secure and less annoying than the old regime of symbols and resets.
The old password rules trained people to be predictable. Forcing a symbol and a reset every quarter did not make anyone safer - it just filled our ticket queue and produced "Password1!" NIST finally caught up with what actually works: length, screening, and good storage.
Policies That Match the Current Standard
CinchOps helps Houston-area businesses bring password and identity policies in line with the latest guidance - and pairs that with everyday managed IT and cybersecurity support.
Explore CinchOps cybersecurity →How CinchOps Helps
CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, and we translate evolving security standards into policies your team can actually live with.
- Policy updates. Aligning your password rules with NIST's current requirements - including dropping outdated resets and composition rules.
- Secure storage. Making sure credentials are salted, hashed, and stored to resist offline attacks.
- Blocklist screening. Setting up checks so new passwords are compared against known-breached lists.
- User education. Helping your people create strong, memorable passphrases that meet the guidelines without sticky notes.
- Identity and access. Layering multi-factor authentication and access controls on top of stronger passwords.
Password rules are one piece of a larger identity strategy. Contact CinchOps to bring your policies up to the current standard - and keep them there.
Frequently Asked Questions
What are the new NIST password guidelines?
NIST's updated Digital Identity Guidelines emphasize password length over complexity. They require a minimum of 8 characters (15+ recommended, up to at least 64 allowed), prohibit forced periodic resets and composition rules, ban security questions and hints, require screening against breached-password blocklists, and require salted-and-hashed secure storage.
Does NIST still recommend changing passwords every 90 days?
No. NIST now says verifiers SHALL NOT require periodic password changes. A forced reset should happen only when there is evidence the password has been compromised. Scheduled expiration tends to produce weaker, more predictable passwords.
Why did NIST drop password complexity requirements?
Requiring specific character types - an uppercase letter, a number, a symbol - reliably produces predictable patterns like "Password1!" and frustrates users without adding real strength. NIST found that length and screening against known-breached passwords protect accounts far better than composition rules.
What does "SHALL" versus "SHOULD" mean in the NIST guidelines?
In NIST's language, "SHALL" and "SHALL NOT" indicate mandatory requirements, while "SHOULD" indicates a strong recommendation. The updated draft converts many former recommendations into requirements, which raises the bar for compliance among the verifiers and credential service providers that manage logins.
How long should a business password be under the new guidelines?
At minimum 8 characters, but NIST recommends 15 or more, and systems should allow at least 64 characters. The practical takeaway is to encourage long passphrases - several words strung together - which are both stronger and easier to remember than short, complex strings.