HomeBlogCybersecurity

NIST Password Guidelines: What Small Businesses Change Now

Modern steel padlock among old brass padlocks on an iron railing, illustrating NIST password guidelines for small business security

NIST's current password rules say four things most small business policies still get wrong: make passwords long, stop forcing complexity, stop forcing scheduled changes, and check every new password against a list of known-bad ones. The rules come from NIST SP 800-63B-4, finalized in July 2025. If your policy still demands a capital letter, a symbol, and a reset every 90 days, it's out of date.

Here's what changed, what it means for a 10- to 100-person office, and how to set it up in Microsoft 365.

What do the NIST password guidelines require now?

NIST requires passwords of at least 15 characters when a password is the only login factor, and at least 8 when it's part of multi-factor authentication. It bans composition rules and scheduled resets, requires blocklist checks against common and breached passwords, and requires that password managers and autofill work. That's the whole policy in one paragraph.

The exact language from Section 3.1.1.2 is blunt. Verifiers "SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types)." And they "SHALL NOT require subscribers to change passwords periodically." The one exception: you must force a change when there's evidence a password has been compromised.

The full list for passwords:

  • Length: 15 characters minimum for password-only logins. 8 minimum when the password is one factor of MFA.
  • Maximum: allow at least 64 characters. Spaces and Unicode should work.
  • No composition rules: no "one uppercase, one number, one symbol."
  • No scheduled expiration: change only on evidence of compromise.
  • Blocklist: check every new password against breached, common, and context-specific words like your company name.
  • No hints, no security questions: "What was your first pet's name?" is out.
  • Password managers allowed: autofill must work, and paste should too.
  • Rate limiting: cap failed login attempts.

Why did NIST drop complexity and 90-day resets?

Because they didn't produce stronger passwords. They produced predictable ones. Force a symbol and a number, and people write Summer2026!. Force a change every quarter, and they write Fall2026!. Attackers know the pattern and try it first.

Length beats complexity. A four-word passphrase is easier to remember and harder to guess than an eight-character jumble that ends in an exclamation point.

The bigger problem is reuse. Verizon's 2025 breach research found that compromised credentials were the initial access vector in 22% of breaches, and in the median case only 49% of a user's passwords across different services were distinct. Half your staff's passwords are probably already in use somewhere else. Expiration rules do nothing about that. A blocklist check and a password manager do.

Do these rules apply to a private business?

Not directly. SP 800-63B is written for federal agencies and the companies that run identity systems for them. Nobody fines a 20-person accounting firm for having a 90-day reset.

But it's the benchmark everyone else points to. Auditors, cyber insurance questionnaires, and frameworks like NIST CSF all lean on it. If an underwriter or examiner asks why your policy looks the way it does, "we follow NIST 800-63B" is the answer that ends the conversation.

How do you set this up in Microsoft 365?

Most of it is already the default, with one catch we'll get to. Microsoft's own documentation says that by default, passwords never expire in a Microsoft 365 organization, and it labels "Set passwords to never expire" as the recommended setting. If someone turned expiration on years ago, turn it back off.

The rest takes a few hours, not a project:

  1. Turn off expiration. Microsoft 365 admin center, Settings, Security & privacy, Password expiration policy.
  2. Use the banned password list. Microsoft Entra Password Protection blocks weak and commonly used passwords for cloud users on the free tier. A custom list of up to 1,000 terms, things like your company name, street, and products, needs Entra ID P1, which comes with Business Premium. If you're unsure which license you have, our Entra ID P1 vs P2 breakdown covers it.
  3. Extend it to on-prem Active Directory if you still run a domain controller. Same tool, P1 license.
  4. Know what you can't change. Entra ID's cloud password policy fixes the minimum at 8 characters and still requires three of four character types. Neither setting can be modified. That's fine. A passphrase like "Harbor lamp 7 granite" clears Microsoft's rule and meets NIST's intent. Teach passphrases, and raise the minimum on any on-prem Active Directory with Group Policy or fine-grained password policies.
  5. Kill security questions in self-service password reset. Use the Authenticator app or a phone instead.
  6. Deploy a business password manager. NIST requires that they work. Our password manager FAQ covers picking one and rolling it out.

Does this mean MFA matters less?

No. It matters more. NIST lets a password be as short as 8 characters only because a second factor is doing real work. Drop MFA and you're back to needing 15.

And not all MFA is equal. SMS codes and push approvals get phished every day. Microsoft is already retiring SMS and voice MFA, and passkeys are where this is headed. Our passkeys vs MFA guide explains the difference.

What should your written password policy say?

Keep it to a page. Something like:

  • Passphrases of 15+ characters. No extra symbol rules beyond what Microsoft 365 already enforces.
  • No scheduled changes. Mandatory change on any sign of compromise.
  • Never reuse a work password anywhere else.
  • Store every work password in the company password manager.
  • MFA on every account that supports it, with phishing-resistant methods for admins.

That's it. A policy people can follow beats a strict one they work around.

Frequently asked questions

What is the minimum password length under NIST?

Under SP 800-63B-4, 15 characters when the password is the only factor, and 8 when it's used with multi-factor authentication. NIST also says systems should accept at least 64 characters so people can use long passphrases. Most small businesses should aim for 15 or more regardless.

Does NIST still recommend changing passwords every 90 days?

No. NIST says systems shall not require periodic password changes. You change a password when there's evidence it's been compromised, like a breach alert, a phishing click, or suspicious sign-ins. Scheduled resets push people toward predictable patterns that attackers guess easily.

Are special characters required in passwords anymore?

Not under NIST. The guideline bans composition rules like "one uppercase, one number, one symbol." Microsoft 365 is the exception you live with: its cloud accounts still require three of four character types, and that can't be switched off. A passphrase with a capital and a number satisfies both.

Will dropping password expiration hurt our cyber insurance application?

It shouldn't. Underwriters care about MFA, backups, and endpoint protection, not reset schedules. If a questionnaire asks about rotation, answer that you follow NIST SP 800-63B, force changes on compromise, and screen against breached passwords. That's a stronger answer than "every 90 days."

Is the free Microsoft banned password list enough?

For cloud-only users it covers the basics, since Microsoft's global list blocks common weak passwords at no extra cost. A custom list with your company name and local terms needs Entra ID P1, included in Business Premium. If you sync from on-prem Active Directory, you need P1 for both.

Get your password policy current

Most small offices can bring their password setup in line with NIST in an afternoon. The hard part is knowing which settings are already right and which were changed years ago by someone who's gone. Book a complimentary security assessment and we'll check your Microsoft 365 and Active Directory settings against NIST and tell you exactly what to change. You can also see our full managed IT and cybersecurity services.

NIST CSF 2.0 Implementation

Discuss nist csf 2.0 implementation for your business.

Tell us about your current systems, the result you need and your timeline. We will discuss the work, responsibilities and pricing before you decide on an engagement.

Explore NIST CSF 2.0 Implementation 845-203-3914