openideurope.eu

Strong passwords in 2026: what still matters

Length beats complexity: NIST and BSI advice on passphrases, unique passwords, password managers and why you no longer need to change passwords on a schedule.

Login securityPublished

A strong password in 2026 is long, unique to a single account and stored in a password manager. Complexity rules and forced monthly changes have been dropped by the standards bodies because they led people to predictable patterns. What matters now is length, uniqueness, and a second factor behind the password.

What the standards say

The US standard NIST SP 800-63B-4, finalised in 2025, tells services to:

  • require at least 15 characters when a password is the only factor, and at least 8 when it is one of several factors,
  • accept long passwords of at least 64 characters, including spaces and Unicode,
  • not impose composition rules such as “one capital, one digit, one symbol”,
  • not force regular password changes,
  • check new passwords against lists of known breached and common passwords,
  • allow pasting, so that password managers work.

The German BSI gives consumers a similar picture on its page on creating secure passwords. Its guidance is more detailed about length versus character types: a long password of around 25 characters can get by with fewer character types, shorter ones need more variety, and one protected by multi-factor authentication can be shorter. It also suggests choosing five or six random words separated by spaces. Treat BSI’s figures as a minimum and aim higher where you can.

Old habits and what to do instead

Old habit Why it fails Better
“P@ssw0rd2026!” style substitutions Cracking tools know these patterns A random passphrase or generated password
One strong password everywhere One leak opens every account A unique password per account
Change every 90 days Leads to predictable increments like “Spring1”, “Summer1” Change only after a leak or suspicion
Security questions with true answers Answers can be researched Treat answers as extra passwords, store them in your manager
Writing passwords on sticky notes Visible to anyone nearby Use a manager, or keep a locked paper backup at home

Three ways to build a strong password

  1. Generated by a password manager. 20 or more random characters, never typed by hand. Best for nearly all accounts.
  2. Random-word passphrase. Five or six words picked by dice or a generator, not by you, for example for your device login or the master password of your manager. Easy to type, long enough to resist guessing.
  3. A passkey instead of a password. Where a site supports it, a passkey cannot be phished or reused, so the password question disappears for that account.

A phrase from a song or a quote is not random and is guessable by dictionary attacks. Let a tool pick the words.

Step by step: tidy up your passwords

  1. Install a password manager and protect it with a long passphrase that you use nowhere else. Our comparison of the best password managers helps you pick one.
  2. Start with the accounts that unlock others: email, Apple or Google account, banking, then shops and social media.
  3. Replace weak and reused passwords with generated ones as you log in. You do not need to do all of them in a day.
  4. Turn on two-factor authentication or passkeys for the same accounts.
  5. Check for leaks. If a password appeared in a breach, change it now. See what to do after a data breach.
  6. Let go of the schedule. No calendar reminders to change a good password.

Passwords you still must memorise

Only a few: your device login, your password manager’s master password and your email account. Pick a separate passphrase for each, and write down the master phrase on paper for a secure home location in case you forget it.

Is a long password enough?

On its own, no. A strong password does not protect against phishing, malware or a breach at the service. That is why modern advice pairs it with a second factor or replaces it with a passkey.

Common questions about password rules

Why do some sites still demand symbols and a monthly change? Many systems were built before the guidance changed. If a site insists, follow its rules, but make the password long and unique anyway. A policy on a login page does not change what is actually safe.

Is a longer password always better? Up to a point. Length helps against guessing, but beyond a certain size the weak points are elsewhere: phishing, malware and reuse. A 20-character random password stored in a manager is already far beyond what attackers can guess.

What about “leetspeak” and clever substitutions? Cracking tools try these first. Replacing an “a” with “@” adds almost no strength.

Are passphrases safe if they are famous quotes? No. Anything from a song, book or film is in dictionaries. Use random words.

What a good policy for a household looks like

  • Every account has its own generated password.
  • The few remembered passphrases are long, random and never reused.
  • Important accounts have 2FA or a passkey.
  • Passwords change only after a leak, a phishing click or when a device is lost.
  • Recovery options are current, so you can get back in without guessing.

A note on password hints and reuse across work and home

Never use a work password at home or the reverse. A breach at a small shop should never open your employer’s systems, and a leak of your work email should not open your private accounts. Keeping them apart is free and takes only a manager.

Bottom line

Stop inventing complicated passwords. Let a manager generate them, make the few you remember long and random, add a second factor, and change a password only when there is a reason.

Frequently asked questions

How long should a password be?

As long as the service allows and you can manage. NIST SP 800-63B-4 sets 15 characters as the minimum for passwords used alone, and 8 when combined with another factor. A random passphrase of five or six words is a good practical target for passwords you must memorise.

Do I need special characters and numbers?

Not for security's sake. NIST tells services not to require mixtures of character types. BSI still describes combinations of length and character types, so if a site demands symbols, add them, but length does more work.

Should I change my passwords regularly?

No, not on a schedule. NIST says services should not force periodic changes, and the BSI no longer recommends it either. Change a password when there is a reason: a leak, a phishing click or a shared device.

Is it safe to use the same password with small variations?

No. Attackers try variations of leaked passwords automatically. Every account needs its own unrelated password, which a password manager generates for you.

More in Login security