How to create a strong password (according to NIST)

For years we were told to mix capitals, numbers and symbols and to change passwords every three months. NIST, which writes the reference guidance, now advises almost the opposite. What it actually says, and what to do about it.

Reviewed on 3 October 2026 · 4 min read

What makes a password strong: length, not symbols

NIST (the US National Institute of Standards and Technology) publishes the reference guidance on digital identity, SP 800-63B. Its revision 4 explains that length is the primary factor in password strength: passwords that are too short fall to brute-force and dictionary attacks. Composition rules (demanding capitals, digits and symbols) bring much less than was assumed, because people respond to them in very predictable ways: someone who would have chosen "password" picks "Password1" when forced to add a capital and a number, or "Password1!" when a symbol is also required.

That changes the classic advice. A long phrase that is easy to type is stronger than a short word full of symbols nobody can remember.

What NIST requires from services (and what it means for you)

The guidance is written for the people who build login systems, but its rules say a lot about good practice. The main ones, quoted from revision 4:

  • A minimum length of 15 characters when the password is the only authentication factor. If it is only used together with another factor (two-step verification), the minimum drops to 8 characters.
  • Allowing passwords of at least 64 characters and accepting all printable ASCII characters, including the space, as well as Unicode.
  • No composition rules such as "one capital, one number and one symbol".
  • No forced periodic changes. A change should only be forced when there is evidence the password has been compromised.
  • Rejecting passwords on a blocklist: common ones, ones from previous breaches, dictionary words and context-specific words such as the service or user name.
  • Allowing password managers and paste: the guidance says managers increase the likelihood that people choose stronger passwords, especially when they include a generator.
  • No security questions such as "what was the name of your first pet?" and no stored hints.

In short: if a site forces a change every 90 days or caps passwords at 12 characters, it is following advice NIST no longer gives. You can do what does work: long, unique passwords kept in a manager.

How to create a good password, step by step

  1. Make it long. Aim for 16 characters or more, and 20 or more for important accounts (email, bank, the password manager itself).
  2. Make it unique. A different password for every account. If one leaks, the others stay safe. Reusing passwords is the most common reason accounts get compromised.
  3. Make it random. People are bad at inventing randomness: we reach for dates, names and patterns. Let a generator do it. The UtilsDock password generator uses your browser's secure random number generator (the same kind used in cryptography) and works on your device: the password is never sent to or stored on a server.
  4. Keep it in a manager. A password manager remembers and fills passwords for you, so you only need to memorise the master one.
  5. Turn on two-step verification wherever it is offered. With it, even a stolen password is not enough to get in.

Random characters or a passphrase

There are two good options, and you can combine them:

  • Random characters (for example 18–24 characters mixing types): the strongest for a given length. Ideal for accounts your manager fills in and you never type by hand.
  • A passphrase (four or more random words): easier to remember and type. Good for your manager's master password or your computer login. The key is that the words are chosen at random (with dice or a generator), not a famous phrase, a song lyric or anything related to you.

NIST itself notes that using passphrases with several words is often an effective way to create longer passwords.

How much strength is enough

Strength is measured in bits of entropy: each bit doubles the number of guesses an attacker needs. A random 16-character password mixing lowercase, uppercase, digits and symbols is around 105 bits, far beyond brute force with current technology. Above about 80 bits is considered very strong. But entropy only counts if the password is truly random: "Mypet2026!" looks complex and is not, because attackers try that kind of pattern first.

Mistakes that weaken your passwords

  • Changing "Summer2025!" to "Summer2026!". Attackers try predictable variations of old passwords.
  • Using personal details (dates, names, plates) that can be found on social media.
  • Reusing your email password elsewhere: whoever controls your email can reset almost every other account.
  • Keeping them in an unprotected note or sending them in chat.
  • Changing them out of routine and always picking something similar. One good password you never change beats a worse one every three months.

When you should change one

Change a password when a service reports a breach, when you suspect someone has access, if you used it on a computer that is not yours, or if you shared it and no longer want that person to have it. In those cases, generate a new, different one and check any other accounts where you used the old one.

To see how services should store your password (a slow, salted hash), read the guide to hashes and checksums.

Sources and further reading

Figures checked on 3 October 2026.

Do it now, free, in your browser. Your files are not uploaded.

Generate strong random passwords in your browser. Nothing is sent or stored.

Frequently asked questions

How many characters should a strong password have?
NIST requires services to demand at least 15 characters when the password is the only factor, and 8 when it is used with another factor. As a practical rule, use 16 or more, and 20 or more for important accounts.
Do I need symbols, capitals and numbers?
They are not required to be strong. NIST advises against imposing composition rules, because length matters more and people respond to them predictably. Adding them does no harm, but they do not replace length or randomness.
Should I change my passwords regularly?
NIST says services should not require periodic changes, only when there is evidence the password has been compromised. Change yours after a breach or if you suspect someone knows it.
Is a password manager safe?
Yes, and NIST recommends them: managers make stronger, unique passwords more likely. Choose a trusted one, protect it with a long master password and turn on two-step verification.
What is a passphrase?
A password made of several words: long and easy to remember. To be strong, the words must be chosen at random and not form a well-known phrase or relate to you.
Is it safe to generate passwords on a website?
It depends where they are generated. The UtilsDock generator creates the password in your browser with the browser's own secure random generator and neither sends nor stores it. Even so, copy it straight into your password manager.