📋 Password Policy Generator

Choose your rules to build a written password policy you can paste into an employee handbook or security doc.

How the document is assembled

Each ticked box adds one numbered clause, and the numbering closes up when you untick something. The order is fixed:

1. minimum length
2. character requirements  (merged into one clause)
3. reuse of the last 5
4. blocklist of breached passwords
5. rotation, or the no-expiry wording
6. MFA

Untick every character box and clause 2 disappears rather than printing an empty requirement. Set rotation to None and clause 5 flips: passwords do not expire, but must be changed the moment compromise is suspected.

Which defaults follow current guidance

This writes wording, not configuration - it enforces nothing in Active Directory or your app, and it is not a compliance sign-off. Some frameworks still mandate expiry: PCI DSS wants either a 90-day change or continuous analysis of account posture, which is what the rotation dropdown is for.

Frequently asked questions

What minimum password length should a company policy set?

12 characters, or 15 if the policy covers administrators or customer data. Set a generous maximum too - rejecting long passwords is a sign the system is not hashing them properly.

Why is forcing a password change every 90 days no longer recommended?

Because it makes passwords worse. NIST SP 800-63B has said since 2017 that verifiers should not require arbitrary periodic changes, only a change on evidence of compromise. People meet a deadline with a minimal edit, so the new password is guessable from the old.

Should the policy demand an uppercase letter, a number and a symbol?

Only if a system you cannot change already does. NIST advises against composition rules for the same reason as rotation: they steer everyone to the same shapes, a capital first and a 1! on the end. Length and a blocklist buy far more.