□

Home » cybersecurity » 15 Character Minimum, 8 With MFA: Standards Aligned Password Rules for IT Teams

15 Character Minimum, 8 With MFA: Standards Aligned Password Rules for IT Teams

The current best practice is length over complexity: a minimum of 15 characters for single-factor passwords or 8 when paired with multifactor authentication, enforced alongside MFA, a password manager, and no forced rotation unless a breach occurs, according to NIST’s implementation guidance. CISA and NCSC echo this shift away from arbitrary complexity rules toward longer passphrases, phishing-resistant authentication, and server-side protections like blocklists and rate-limiting. The rest of this guide translates those standards into steps you can apply today.


TL;DR:

  • Password length is more critical than complexity, with 15 characters recommended for single-factor and at least 8 with MFA enabled.
  • Implement passphrases using random words instead of complex rules, and favor MFA methods that resist phishing, like hardware keys.
  • Regular forced password changes are unnecessary unless a breach occurs, and security questions should be retired due to their guessability.
  • Store passwords using salted, hash algorithms such as Argon2id, and ensure password storage systems are designed to resist offline attacks.
  • Always use a unique and strong master password for your password manager, and enable MFA on the vault itself for maximum protection.

Logmeonce
logmeonce.com
Strengthen Password Security
Explore LogMeOnce solutions for password management, passwordless MFA, cloud encryption, and dark web monitoring.

Explore security resources

1. Build Your Password Policy on These Seven Rules

A good policy follows a strict order of priority. Each rule below reduces risk more than the one after it, so start at the top if you are rewriting a policy from scratch.

  1. Set a minimum length for passwords that is higher for single-factor logins and lower when MFA is active. NIST SP 800-63-4 sets these as the floor and recommends allowing a generous maximum length so passphrases and manager-generated secrets can be accommodated.
  2. Favor passphrases over composition rules. Requiring a mix of symbols, numbers, and capital letters pushes people toward predictable patterns. The NCSC’s three random words approach uses plain length and randomness instead, and it is easier to remember than a string like “P@ssw0rd1”.
  3. Require MFA everywhere it is technically possible. CISA ranks authentication methods from strongest (physical FIDO security keys and passkeys) to weakest (SMS codes), and recommends choosing phishing-resistant options whenever the system supports them.
  4. Mandate or strongly encourage a password manager, and make sure your own systems allow pasting and autofill rather than blocking it, a requirement NIST now writes directly into its guidance.
  5. Screen every new password against a blocklist of known-compromised credentials and add rate-limiting on login attempts so attackers cannot brute-force their way past a short lockout window.
  6. Drop periodic forced rotation. NIST SP 800-63B-4 explicitly states that passwords should only be changed when there is evidence of compromise, not on a fixed calendar, because forced rotation tends to produce weaker, more predictable passwords over time.
  7. Retire security questions and password hints. Both are guessable from public information or social media, and neither adds real protection once MFA and a manager are in place. Accept full Unicode input and normalize it consistently so accented characters and emoji do not break authentication.
  • Minimum length wins over complexity rules every time.
  • MFA should be the default state, not an opt-in feature.
  • Never require users to change a healthy password on a fixed schedule.

Pro Tip: If you can only fix one thing this quarter, turn on MFA for every privileged account first. It blocks far more account takeovers than any password rule change.

2. How to Roll Out These Rules Across an Organization

Translating policy into practice takes a sequence, not a single memo. Here is a practical order for IT and security teams.

  • Write the policy language first: 15-character minimum (8 with MFA), a required blocklist check, no scheduled rotation, and explicit permission for paste and autofill in every login form.
  • Start MFA deployment with admin and privileged accounts, then expand outward; use phishing-resistant methods like FIDO2 passkeys where your identity provider supports them.
  • Roll out single sign-on where feasible so each person juggles fewer passwords overall, which CISA’s identity guidance points to as a way to reduce password sprawl across cloud and on-prem systems.
  • Choose a password manager architecture (cloud-synced vault versus local storage), decide how vault recovery works, and require MFA on the vault itself, not just on individual accounts. Our team password manager guide covers the features worth checking before you commit to one.
  • Configure rate-limiting and account lockout thresholds, then set monitoring alerts that trigger an incident response when repeated failed logins or credential-stuffing patterns show up.
  • Phase enforcement in waves, track adoption through login telemetry, and run short, targeted training for teams still on legacy systems that cannot yet support longer passwords or modern MFA.

Pro Tip: Give legacy systems a documented exception window instead of blocking the whole rollout. A partial rollout with a deadline beats a stalled one with none.

3. Why Secure Storage Matters as Much as the Password Itself

A strong password rule is only as good as the system storing it. OWASP’s Password Storage Cheat Sheet lays out what a verifier should do on the back end, and it matters just as much as any front-end rule.

  • Salt and hash every password with a memory-hard algorithm, with Argon2id as the current recommended choice, since it raises the cost of offline cracking far beyond older schemes like unsalted SHA-1 or MD5.
  • Store the hashing scheme name and cost factor alongside each hash so you can migrate to a stronger algorithm later without forcing every user to reset their password at once.
  • Accept a maximum length of at least 64 characters and normalize Unicode input (NFC normalization) before hashing, so accented letters and multi-script passphrases behave consistently every time.
  • Check new and changed passwords against a large compromised-password list and reject matches with a clear explanation, paired with server-side rate-limiting that throttles repeated guesses.
  • Consider an additional server-held keyed hashing layer or hardware security module for high-value systems, and never store password hints or knowledge-based recovery answers in plain text or otherwise.

4. Simple Password Tactics for Everyday Users

Not everyone manages a corporate policy, but the same standards translate into a few habits worth keeping.

  • Try a three-random-word passphrase like “lamp-garden-whistle” for accounts without a manager attached, following the logic NCSC outlines in its guidance; it is longer and harder to guess than most composition-rule passwords, though a manager-generated random string is stronger still.
  • When you do have a password manager, let it generate and store fully random secrets instead of ones you invent yourself, and lean on paste and autofill rather than retyping.
  • If you must write a password down, keep it somewhere securely protected rather than easily accessible., and never store it as an unencrypted digital note.
  • Check whether any of your accounts show up in a breach through dark web monitoring or similar alerts, and treat a match as your signal to change that one password.
  • Avoid predictable substitutions like swapping “a” for “@,” avoid reusing passwords across sites, and skip SMS-only MFA when an authenticator app or passkey is available.
  • Give your password manager’s own master password extra length and uniqueness, and turn on MFA for the vault itself, since it protects everything stored inside.

Pro Tip: A a unique, sufficiently long passphrase you only use once is worth more than a clever 10-character password you reuse everywhere.

Our guide to creating strong passwords walks through more examples if you want extra practice building your own.

5. Handling Account Recovery and Password Resets Safely

Recovery flows are often the weakest link in an otherwise solid password policy, since an attacker who cannot guess a password will frequently target the reset process instead. A secure reset should verify identity through a channel separate from the one being reset, such as a verified email plus a time-limited link, rather than relying on security questions that can be answered from public social media profiles.

Reset links should expire quickly, ideally within an hour, and should invalidate all other active sessions once used, so a stolen link cannot be reused later. Any account recovery flow worth keeping also notifies the account owner by a second channel the moment a reset is requested, giving someone a chance to catch an attack in progress.

Secure password recovery sequence diagram

For MFA-protected accounts, recovery should never allow a fallback that skips MFA entirely. A common failure case is a support desk that resets MFA on request with only a name and email as proof, which effectively erases the protection MFA was supposed to provide. Build recovery around the same verification strength as the original login, not a weaker shortcut, and log every password reset event so unusual patterns, like one account being reset repeatedly in a short window, get flagged automatically.

6. Communicating Password Policy Changes to Your Users

A technically sound policy fails if nobody understands why it changed. When you move from composition rules to length-based passphrases, explain the reasoning in plain terms: longer passwords are harder to crack, and dropping forced rotation removes an annoyance that used to produce weaker passwords anyway.

Give people a short, concrete example rather than an abstract rule. Showing someone a three-word passphrase next to an old eight-character complex password, and explaining which one actually takes longer to crack, does more than a paragraph of policy language.

Timing matters too. Announce MFA or password manager rollouts in advance, with a clear date and a short how-to guide, rather than surprising people with a login prompt they do not understand. Our password manager tips guide is the kind of resource worth linking directly in that rollout message. Follow up with a quick reminder during the transition window, and keep a simple support channel open for anyone who gets locked out while adjusting to the new rules.

6. Communicating Password Policy Changes to Your Users — overview diagram

7. Why Standards Shifted Away From Complexity Rules

For years, password policy chased complexity because it felt rigorous, even though it pushed people toward predictable patterns like swapping a letter for a symbol. NIST and NCSC moved toward length because it is both easier for people to manage and harder for machines to crack.

What strikes me most is how much of this shift is really about matching rules to real behavior instead of ideal behavior. Blocklists, rate-limiting, and MFA do the heavy lifting; the password itself only has to be long enough to resist offline guessing, and a manager handles the rest. That is a more honest way to design security than hoping everyone perfectly follows a rule they do not understand.

— Mike

A Practical Way to Put These Rules Into Practice

Following every rule in this guide by hand, remembering unique passphrases, checking breach status, enabling MFA on every account, gets tedious fast. Our password manager generates and stores long random passwords, supports passwordless MFA for phishing-resistant login, and includes dark web monitoring so you find out about a compromised credential before it gets used against you. We also offer encrypted cloud storage for the files you keep alongside your passwords.

Logmeonce

Plans start with a free Premium tier, and paid options available at various monthly prices including Professional and Family plans, detailed on our pricing and comparison page. Compare plans there to find the fit for your household, team, or organization.

FAQ

What are the five golden rules of password security?

The core rules are: use a long passphrase (15+ characters for single-factor, 8+ with MFA), enable multifactor authentication, use a password manager, skip forced rotation unless you suspect a breach, and never reuse a password across accounts. These come directly from current NIST guidance and related standards from CISA and NCSC.

What is the 8-4 rule for passwords?

There is no official “8-4 rule” in NIST, CISA, or NCSC guidance. The closest standard distinction is NIST’s requirement of an 8-character minimum for passwords used alongside MFA versus a 15-character minimum for passwords used alone, detailed in the NIST implementation FAQ.

What are the best practices for creating strong passwords?

Favor length over complexity, aiming for 15 characters or more, or use a memorable three-random-word passphrase as NCSC recommends. Pair that password with MFA, store it in a password manager, and avoid predictable substitutions, personal information, or reuse across sites.

What are the NIST password guidelines for 2026?

NIST’s current guidelines call for a 15-character minimum for single-factor passwords, an 8-character minimum when MFA is active, a maximum length of at least 64 characters, mandatory support for password managers and paste functionality, and no required periodic rotation absent evidence of compromise, as laid out in NIST SP 800-63B-4.

Do password managers make it safe to use the same master password everywhere?

No, your master password should be unique and never reused on any other site, since it protects every credential stored in your vault. Make it long, enable MFA on the vault itself, and treat it as the single most important password you own.

Sources

Search

Category

Protect your passwords, for FREE

How convenient can passwords be? Download LogMeOnce Password Manager for FREE now and be more secure than ever.