CinchOps managed IT services and cybersecurity Houston Texas
  • Services
    • Managed IT Services
    • Cybersecurity
    • Business Continuity & Disaster Recovery (BCDR)
    • Virtual CTO & CIO Services
    • Cloud Services
    • Software Defined Wide Area Networks (SD-WAN)
    • Voice Over IP (VoIP)
    • Business Process Automation
  • Industries
    • By Company Size
      • Small & Midsize Businesses
      • Enterprise IT Services & Support in Houston, TX
    • Construction
    • CPA Firms
    • Energy Services & Utilities
    • Engineering
    • Law Firms
    • Manufacturing
    • Oil & Gas Services
    • Wealth Management
  • Local to You
    • Brookshire
    • Cypress
    • Fulshear
    • Houston
    • Katy
    • Missouri City
    • Richmond
    • Rosenberg
    • Sealy
    • Sugar Land
    • The Woodlands
    • Tomball
  • Reviews
  • Resources
    • IT Scorecards
    • IT Outage Calculator
    • Blog
    • News & Updates
    • Videos
    • FAQs
    • CinchOps CyberJeopardy
  • Research
    • Houston Area Security Index
    • Houston Area Patch Index
    • Houston MSP Review Index
    • Houston Growth Index
    • Houston Vulnerability Index
    • Cybersecurity by the Numbers
  • About Us
    • Our Story
    • Your Story
    • My Story
  • Contact
I Need IT Support Now
Digital padlock with keyhole and password field on blue circuit board background.
Shane
Shane October 1st, 2024

New NIST Password Guidelines: What Houston Businesses Need to Know

NIST’s new guidelines favor longer passwords and blocklists over complexity rules and forced changes, reshaping password security practices

Password Security
Most Password Rules You Were Taught Are Now Officially Wrong. NIST Says Length Beats Complexity - and Forced Resets Have to Go.

The updated NIST Digital Identity Guidelines overturn decades of password advice. Here is what actually changed - and what your business should do about it.

TL;DR
NIST's updated password guidance drops the old rules almost everyone still follows. Out: mandatory symbols and numbers, 90-day forced resets, and security questions. In: longer passwords (a minimum of 8 characters, but 15+ recommended, up to at least 64), blocklist checks against known-breached passwords, and salted-and-hashed storage. NIST also stiffened its language from "should not" to "SHALL NOT," turning these from suggestions into compliance requirements for the systems that verify your logins.
📋 What Changed 🔀 Myths NIST Retired 🔑 The New Rules 🚀 How CinchOps Helps

The National Institute of Standards and Technology has rewritten how passwords should work - and the new advice contradicts most of what corporate IT policies have enforced for the past two decades.

NIST is a non-regulatory federal agency whose cybersecurity guidelines are adopted widely across both the public and private sectors. When NIST changes its Digital Identity Guidelines, password policies at banks, hospitals, and businesses eventually follow. The latest revision is a big one: it moves away from complexity tricks and constant resets, and toward length, screening, and secure storage.

The short version: stop forcing symbol-and-number passwords that expire every quarter. Start allowing long passphrases, screen them against known-breached lists, and store them properly. That is the direction NIST now requires.

What NIST Actually Changed

The biggest shift is not a single rule - it is the strength of the language.

NIST replaced much of its advisory "should not" wording with mandatory "SHALL NOT," turning long-standing recommendations into requirements for the systems that check your passwords.

In NIST's guidelines, two roles do the work: verifiers, which confirm a login attempt is valid, and credential service providers (CSPs), which issue and manage the credentials. In most organizations, the IT or identity team plays both parts. The new draft directs firm, testable requirements at them - "SHALL" and "SHALL NOT" signal mandatory practice, not friendly guidance. For a business, that means these are the standards an auditor or a cyber-insurance underwriter will increasingly expect you to meet.

The Password Myths NIST Just Retired

Four rules almost everyone still enforces - and what NIST now says instead.

The habits that felt like good security - forced expiration, required symbols, security questions - are exactly the ones NIST now tells you to drop, because they push people toward weaker passwords, not stronger ones.

OLD RULES VS. WHAT NIST NOW SAYS THE OLD RULE WHAT NIST NOW SAYS Change your password every 90 days Constant resets = predictable patterns ✓ No forced expiration Only reset on evidence of compromise Require upper, lower, number & symbol Leads to "Password1!" everywhere ✓ No composition rules Length does the work instead 8 characters is plenty Short passwords crack fast ✓ Aim for 15+, allow up to 64 Passphrases beat complexity Security questions add safety Answers are easy to find or guess ✓ No knowledge-based questions Screen against breached-password lists
The four password habits NIST's updated guidelines retire - and what replaces each one.

Forced 90-day resets are out. Making people change passwords on a schedule pushes them toward small, guessable tweaks - "Spring2024!" becomes "Summer2024!" NIST now says do not require periodic changes; force a reset only when there is evidence a password has been compromised.

Composition rules are out. Demanding a mix of uppercase, numbers, and symbols reliably produces the same weak patterns and endless password-reset tickets. NIST says do not impose those rules. A long passphrase is both stronger and easier to remember.

Security questions are out. The name of your first pet or the street you grew up on is often public or easy to guess, so NIST prohibits verifiers from using knowledge-based authentication and password hints. Instead, prospective passwords should be screened against blocklists of known-breached and commonly used passwords.

Still Forcing Quarterly Password Resets?

If your policies still look like 2010, you may be failing the exact standards auditors and insurers now check for. A free assessment shows you where you stand.

Get Your Free Assessment →

The New NIST Password Rules, Plainly

What the guidelines actually require, translated out of the standards language.

Stripped of the jargon, NIST's password requirements come down to length, screening, and secure handling - not complexity theater.

  • Length over complexity. Require at least 8 characters, recommend 15 or more, and allow passwords of at least 64 characters so people can use real passphrases.
  • Accept the full keyboard. Allow all printable ASCII characters, the space character, and Unicode - each Unicode character counts as one toward the length.
  • No composition rules. Do not require particular mixes of character types.
  • No scheduled expiration. Do not force periodic changes; require a reset only on evidence of compromise.
  • No hints or security questions. Do not store hints an unauthenticated visitor could reach, and do not use knowledge-based questions.
  • Screen against blocklists. Check every new or changed password against a list of known commonly used, expected, or compromised passwords.
  • Store it securely. Salt and hash passwords with a suitable scheme so they resist offline attacks, and verify the entire password without truncating it.

The through-line is simple: make it easy for people to choose a long, unique password, screen out the ones already known to attackers, and protect what you store. That is more secure and less annoying than the old regime of symbols and resets.

100% Free

Free Security Assessment

Not sure whether your password and identity policies meet the current standard? Get a FREE assessment of where your Houston business stands - and what to fix first.

Get Your Free Assessment

The old password rules trained people to be predictable. Forcing a symbol and a reset every quarter did not make anyone safer - it just filled our ticket queue and produced "Password1!" NIST finally caught up with what actually works: length, screening, and good storage.
Shane Stevens, CEO, CinchOps - LinkedIn

Policies That Match the Current Standard

CinchOps helps Houston-area businesses bring password and identity policies in line with the latest guidance - and pairs that with everyday managed IT and cybersecurity support.

Explore CinchOps cybersecurity →

How CinchOps Helps

CinchOps is a Katy, Texas managed IT services provider serving businesses across the Houston metro, and we translate evolving security standards into policies your team can actually live with.

  • Policy updates. Aligning your password rules with NIST's current requirements - including dropping outdated resets and composition rules.
  • Secure storage. Making sure credentials are salted, hashed, and stored to resist offline attacks.
  • Blocklist screening. Setting up checks so new passwords are compared against known-breached lists.
  • User education. Helping your people create strong, memorable passphrases that meet the guidelines without sticky notes.
  • Identity and access. Layering multi-factor authentication and access controls on top of stronger passwords.

Password rules are one piece of a larger identity strategy. Contact CinchOps to bring your policies up to the current standard - and keep them there.

https://cinchops.com/wp-content/uploads/2024/08/CinchOps-Cybersecurity-For-SMBs.mp4
CinchOps cybersecurity for small and mid-sized businesses.

Frequently Asked Questions

What are the new NIST password guidelines?

NIST's updated Digital Identity Guidelines emphasize password length over complexity. They require a minimum of 8 characters (15+ recommended, up to at least 64 allowed), prohibit forced periodic resets and composition rules, ban security questions and hints, require screening against breached-password blocklists, and require salted-and-hashed secure storage.

Does NIST still recommend changing passwords every 90 days?

No. NIST now says verifiers SHALL NOT require periodic password changes. A forced reset should happen only when there is evidence the password has been compromised. Scheduled expiration tends to produce weaker, more predictable passwords.

Why did NIST drop password complexity requirements?

Requiring specific character types - an uppercase letter, a number, a symbol - reliably produces predictable patterns like "Password1!" and frustrates users without adding real strength. NIST found that length and screening against known-breached passwords protect accounts far better than composition rules.

What does "SHALL" versus "SHOULD" mean in the NIST guidelines?

In NIST's language, "SHALL" and "SHALL NOT" indicate mandatory requirements, while "SHOULD" indicates a strong recommendation. The updated draft converts many former recommendations into requirements, which raises the bar for compliance among the verifiers and credential service providers that manage logins.

How long should a business password be under the new guidelines?

At minimum 8 characters, but NIST recommends 15 or more, and systems should allow at least 64 characters. The practical takeaway is to encourage long passphrases - several words strung together - which are both stronger and easier to remember than short, complex strings.

Discover More

Password Leak Study: 94% of Passwords Are Reused
What Is Identity and Access Management?
CinchOps Cybersecurity Services

Sources

  • NIST SP 800-63B, Digital Identity Guidelines - Authentication and Authenticator Management
  • NIST, Identity and Access Management resources
Shane Stevens, founder and CEO of CinchOps
About the Author

Shane Stevens

Shane Stevens is the founder and CEO of CinchOps, a managed IT and cybersecurity provider for small and mid-sized businesses across the Greater Houston area, including Katy. He brings more than 35 years of IT experience, including director, VP, and CTO roles at Tidal Software, Cisco, ABB, Delinea, Digital.ai, and NinjaOne, to keeping local businesses secure, efficient, and productive.

Read Shane’s story·Connect on LinkedIn

BLOG

Latest News & Articles

March 18th, 2026
Proactive IT Houston
Proactive Managed IT Support: What Houston SMBs Actually Need

Stop Paying for Faster Firefighting and Start Preventing Fires – A Practical Guide to Proactive IT Support for Houston Businesses

April 22nd, 2026
Managed IT Houston
Before You Add Another AI Tool, Read This: CinchOps on Cash Flow, Outcomes, and What Actually Works

The AI Conversation Houston Businesses Actually Need to Have – Your P&L And Cash Flow Doesn’t Care How Many Agents You Deployed

January 26th, 2026
MSP Near Me
Proactive vs. Reactive IT Support: How to Tell the Difference Before You Hire an MSP

Is Your MSP Really Proactive? What Houston Small Businesses Should Ask Before Hiring Managed IT Support – If You’re Always Calling IT, Your IT Isn’t Working

March 16th, 2026
Law Firm Cybersecurity
Law Firm Cybersecurity: 76% of Greater Houston Firms Do Not Pass Basic Security Standards

Six Security Categories, Over 1,300 Firms: A Data-Driven Assessment – Understanding the Blind Spot Between Passive and Active Security Scores

July 17th, 2025
Managed Service Provider Houston Cyberscurity
United Natural Foods Cyberattack: $400 Million Supply Chain Disruption

United Natural Foods Reports Cyberattack Impact on Operations and Financial Results – Supply Chain Resilience: Learning from United Natural Foods’ Cyber Incident

Take Your IT to the Next Level!

Book A Consultation for a Free Managed IT Quote

BOOK A FREE CONSULTATION
281-269-6506
CinchOps managed IT services and cybersecurity Houston Texas
  • Home
  • Our Story
  • Reviews
  • FAQs
  • Contact
  • Sitemap
Contact info
  • 281-269-6506
  • info@cinchops.com
  • 2717 Commercial Center Blvd.
    Suite E200
    Katy, Texas, 77494

Services
  • Managed IT Services
  • Cybersecurity
  • Virtual CTO & CIO
  • Business Continuity & Disaster Recovery for Houston Businesses
  • Cloud Services
  • Business Process Automation for Houston Businesses
Service Areas
  • Brookshire
  • Cypress
  • Fulshear
  • Houston
  • Katy
  • Missouri City
  • Richmond
  • Rosenberg
  • Sealy
  • Sugar Land
  • The Woodlands
  • Tomball
©2026 CinchOps, LLC. All Rights Reserved.  | Privacy Policy