Strong passwords in 2026: what still matters
Length beats complexity: NIST and BSI advice on passphrases, unique passwords, password managers and why you no longer need to change passwords on a schedule.
Login securityPublished
A strong password in 2026 is long, unique to a single account and stored in a password manager. Complexity rules and forced monthly changes have been dropped by the standards bodies because they led people to predictable patterns. What matters now is length, uniqueness, and a second factor behind the password.
What the standards say
The US standard NIST SP 800-63B-4, finalised in 2025, tells services to:
- require at least 15 characters when a password is the only factor, and at least 8 when it is one of several factors,
- accept long passwords of at least 64 characters, including spaces and Unicode,
- not impose composition rules such as “one capital, one digit, one symbol”,
- not force regular password changes,
- check new passwords against lists of known breached and common passwords,
- allow pasting, so that password managers work.
The German BSI gives consumers a similar picture on its page on creating secure passwords. Its guidance is more detailed about length versus character types: a long password of around 25 characters can get by with fewer character types, shorter ones need more variety, and one protected by multi-factor authentication can be shorter. It also suggests choosing five or six random words separated by spaces. Treat BSI’s figures as a minimum and aim higher where you can.
Old habits and what to do instead
| Old habit | Why it fails | Better |
|---|---|---|
| “P@ssw0rd2026!” style substitutions | Cracking tools know these patterns | A random passphrase or generated password |
| One strong password everywhere | One leak opens every account | A unique password per account |
| Change every 90 days | Leads to predictable increments like “Spring1”, “Summer1” | Change only after a leak or suspicion |
| Security questions with true answers | Answers can be researched | Treat answers as extra passwords, store them in your manager |
| Writing passwords on sticky notes | Visible to anyone nearby | Use a manager, or keep a locked paper backup at home |
Three ways to build a strong password
- Generated by a password manager. 20 or more random characters, never typed by hand. Best for nearly all accounts.
- Random-word passphrase. Five or six words picked by dice or a generator, not by you, for example for your device login or the master password of your manager. Easy to type, long enough to resist guessing.
- A passkey instead of a password. Where a site supports it, a passkey cannot be phished or reused, so the password question disappears for that account.
A phrase from a song or a quote is not random and is guessable by dictionary attacks. Let a tool pick the words.
Step by step: tidy up your passwords
- Install a password manager and protect it with a long passphrase that you use nowhere else. Our comparison of the best password managers helps you pick one.
- Start with the accounts that unlock others: email, Apple or Google account, banking, then shops and social media.
- Replace weak and reused passwords with generated ones as you log in. You do not need to do all of them in a day.
- Turn on two-factor authentication or passkeys for the same accounts.
- Check for leaks. If a password appeared in a breach, change it now. See what to do after a data breach.
- Let go of the schedule. No calendar reminders to change a good password.
Passwords you still must memorise
Only a few: your device login, your password manager’s master password and your email account. Pick a separate passphrase for each, and write down the master phrase on paper for a secure home location in case you forget it.
Is a long password enough?
On its own, no. A strong password does not protect against phishing, malware or a breach at the service. That is why modern advice pairs it with a second factor or replaces it with a passkey.
Common questions about password rules
Why do some sites still demand symbols and a monthly change? Many systems were built before the guidance changed. If a site insists, follow its rules, but make the password long and unique anyway. A policy on a login page does not change what is actually safe.
Is a longer password always better? Up to a point. Length helps against guessing, but beyond a certain size the weak points are elsewhere: phishing, malware and reuse. A 20-character random password stored in a manager is already far beyond what attackers can guess.
What about “leetspeak” and clever substitutions? Cracking tools try these first. Replacing an “a” with “@” adds almost no strength.
Are passphrases safe if they are famous quotes? No. Anything from a song, book or film is in dictionaries. Use random words.
What a good policy for a household looks like
- Every account has its own generated password.
- The few remembered passphrases are long, random and never reused.
- Important accounts have 2FA or a passkey.
- Passwords change only after a leak, a phishing click or when a device is lost.
- Recovery options are current, so you can get back in without guessing.
A note on password hints and reuse across work and home
Never use a work password at home or the reverse. A breach at a small shop should never open your employer’s systems, and a leak of your work email should not open your private accounts. Keeping them apart is free and takes only a manager.
Bottom line
Stop inventing complicated passwords. Let a manager generate them, make the few you remember long and random, add a second factor, and change a password only when there is a reason.
Frequently asked questions
How long should a password be?
As long as the service allows and you can manage. NIST SP 800-63B-4 sets 15 characters as the minimum for passwords used alone, and 8 when combined with another factor. A random passphrase of five or six words is a good practical target for passwords you must memorise.
Do I need special characters and numbers?
Not for security's sake. NIST tells services not to require mixtures of character types. BSI still describes combinations of length and character types, so if a site demands symbols, add them, but length does more work.
Should I change my passwords regularly?
No, not on a schedule. NIST says services should not force periodic changes, and the BSI no longer recommends it either. Change a password when there is a reason: a leak, a phishing click or a shared device.
Is it safe to use the same password with small variations?
No. Attackers try variations of leaked passwords automatically. Every account needs its own unrelated password, which a password manager generates for you.
More in Login security
Account recovery: how to plan it before you need it
Locked out of Google, Apple or your email? Set up recovery options, backup codes and a trusted contact now, and test them, so a lost phone is an annoyance.
Account security for the whole family: a practical guide
Keep a household safe online: a shared password manager, 2FA for everyone, child accounts, help for parents and a simple plan if someone loses access.
Backup codes: what they are and where to keep them
Backup codes get you into an account when your phone or authenticator is gone. Learn how to generate them, where to store them safely and when to replace them.
Fingerprint and face login: how safe is biometrics?
Fingerprint and face unlock are convenient and, used on your own device, quite safe. Learn how they work, where they fall short and how to set them up sensibly.
Hardware security keys explained: how they work
A hardware security key is a small device that proves it is you. Learn how FIDO2 keys work, what to look for, how to set one up and why you need a spare.
How authenticator codes (TOTP) work and how to use them
TOTP codes are the six-digit numbers in authenticator apps. See how they are generated, why they work offline, their limits and how to back them up safely.