How Often Should You Change Passwords? The 2026 NIST Answer

How Often Should You Change Passwords? The 2026 NIST Answer, key points at a glance
How Often Should You Change Passwords? The 2026 NIST Answer, key points at a glance
By Marcus Webb, Financial Security Specialist · 17 August 2026 · 7 min read

If you still rotate every password on a 90-day schedule, you are following advice that NIST officially abandoned, and that security research shows can make your accounts less safe. The 2026 answer: change a password immediately after a breach, when you reused it elsewhere, or when someone else knows it; otherwise a long, random, unique password can stay unchanged for years.

What is password rotation? Password rotation is the practice of periodically replacing a password with a new one, historically every 30-90 days. NIST Special Publication 800-63B, the U.S. digital identity guideline that most security policies copy, removed mandatory periodic rotation in 2017 and has kept it out since, because forced rotation measurably degrades password quality.

This guide explains why the 90-day rule died, when you genuinely must change a password, how to check whether yours have leaked, and what modern guidance actually says.

Bottom line: There is no "right" interval on a calendar. Rotate on events, not dates: breach, reuse discovery, suspected compromise, or a service's explicit request. A 16+ character random password that has never leaked does not need changing on a schedule, changing it for no reason only gives you a new password to forget, reuse, or weaken.

Why NIST Abandoned Forced Password Changes

For decades the default corporate policy was "change your password every 90 days." NIST's own research and that of security firms showed the policy backfires:

NIST SP 800-63B now says: verify new passwords against known-breached lists, stop hinting questions, and require a change only when compromise is suspected. The 90-day mandate is gone, and security policies that still enforce it are working from a pre-2017 playbook.

When You Actually Must Change a Password (2026)

Replace these four categories of passwords today:

SituationAction
A service you use announces a breachChange immediately, and on any account where you reused that password
You reused the same password on multiple sitesChange every instance to a unique random password
Someone else knows it (shared, written down, shown on screen)Rotate immediately
Your password is short, weak, or pattern-basedUpgrade to 16+ random characters

How to Check Whether Your Password Has Leaked

You don't need a calendar, you need visibility:

What to Do When a Password Is Exposed

  1. Change the affected password immediately, before you do anything else.
  2. Change the same password on every other account where you reused it.
  3. Enable multi-factor authentication on the account and any financial services connected to it.
  4. Review recent logins and transactions for anything you didn't do.
  5. Generate the replacement with a client-side random password generator, 16+ characters, symbols included, and store it in a password manager.

The Modern Best Practice (2026)

Frequently Asked Questions

How often should I change my passwords?

Only when there is a reason: after a breach or leak that involves the account, when you discover you reused the password elsewhere, when someone else knows it, or when the service tells you to. For a strong, unique, randomly generated password that has never leaked, there is no schedule, NIST and modern guidance say leave it alone.

Did NIST really stop recommending password changes?

Yes. NIST SP 800-63B removed mandatory periodic password changes (the old 90-day rule) because forced rotation pushed people toward predictable, reused passwords. NIST now recommends changing a password only when there is evidence of compromise.

How do I know if my password leaked?

Check Have I Been Pwned for your email addresses, and use a password manager that screens new passwords against known-breached lists. If a service you use announces a breach, change that account's password immediately, and any account where you reused it.

Does changing passwords often make accounts more secure?

For most people, no. Forced frequent changes encourage weaker, reused, easier-to-remember passwords, and research shows many users respond to rotation mandates by just appending a number. A long random password changed only on real compromise events is stronger in practice.

What passwords should I change right now?

Any password you've reused across multiple sites, any password shorter than 12 characters, any password that appears in a breach you were part of, and any password you've shared or written down in plain view. Replace them with 16+ character random passwords from a client-side generator.

This article is for general educational purposes. NIST guidance reflects Special Publication 800-63B as of 2026. This is not financial or legal advice. Some links are affiliate links, if you buy through them we may earn a commission at no extra cost to you. See our affiliate disclosure.

How Long Should a Strong Password Actually Be?

NIST's current guidance shifts the focus from complexity rules to password length. A longer password is significantly harder to crack than a short one stuffed with symbols, because the number of possible combinations grows exponentially with each added character. A twelve-character password made of random words is generally stronger than an eight-character password mixing uppercase letters, numbers, and punctuation.

As a practical baseline, aim for at least fifteen characters for accounts that matter, email, banking, and any account tied to your identity. For accounts where a breach could cause serious harm, longer is better. The exact number matters less than making sure the password is both long and unique to that account.

The Biggest Password Mistake Most People Still Make

Reusing passwords across multiple sites remains the single most common and damaging habit. When one site suffers a breach, attackers immediately test those stolen credentials against other popular services. This technique, called credential stuffing, is automated, fast, and highly effective precisely because so many people reuse passwords.

Common variations on reuse are just as risky. Adding a number at the end, capitalizing the first letter, or appending the site name to a base password does not meaningfully protect you. Automated tools are programmed to try these patterns first.

Using a Password Manager Without Introducing New Risk

A password manager solves the reuse problem by generating and storing a unique, random password for every account. You only need to remember one strong master password. This is the most practical way to follow NIST's guidance at scale, it is not realistic to memorize dozens of long, unique passwords without help.

When setting up a password manager, a few steps are worth taking carefully:

Two-Factor Authentication and Why It Changes the Equation

Even a strong, unique password can be stolen through phishing, malware, or a site breach. Two-factor authentication (2FA) adds a second layer that an attacker typically cannot bypass just by knowing your password. When 2FA is active on an account, a stolen password alone is not enough to break in.

This is one reason NIST no longer insists on frequent password rotation for accounts with 2FA enabled, the risk profile is fundamentally different. Rotating a password every ninety days provides little protection if an attacker already has real-time access to your session; conversely, 2FA blocks most opportunistic attacks even when a password has been exposed.

Authenticator apps generate time-based codes and are generally more secure than receiving codes by SMS, which can be intercepted. Hardware security keys offer an even stronger option for high-value accounts.

How to Verify Your Security Setup Is Actually Working

It is worth periodically confirming that your defenses are in place rather than assuming everything is fine. A simple review routine might include:

None of this needs to be done weekly. A brief review every few months, combined with prompt action whenever you receive a breach notification, covers the vast majority of realistic threats for most people.

Keep the advice above in practice with NordPass, a password manager built for simple, secure storage.