🔁 Password Rotation Calculator

Enter when you last changed a password and your organization's rotation policy to find the exact next-change date.

How the due date is worked out

The date you enter is read as midnight UTC, then the policy is added as a flat number of 86,400,000-millisecond days. Nothing is rounded to calendar months:

next_due  = last_changed + policy_days
remaining = ceil((next_due - now) / 1 day)

2026-01-15 + 90 days = 2026-04-15
2026-03-01 + 90 days = 2026-05-30

90 days is not three months: from 1 March it lands on 30 May, because February is short. Working in fixed UTC days is also why a daylight-saving change never shifts the answer.

Reading the status line

This works out a date; it does not set a reminder, and nothing you type leaves the browser. NIST SP 800-63B has advised against scheduled expiry since 2017, so use this to satisfy a policy you are stuck with rather than to build a new one.

Frequently asked questions

Is a 90-day password change still required?

Not by NIST, which since 2017 has said verifiers should not force arbitrary periodic changes; Microsoft dropped expiry from its Windows security baselines in 2019 for the same reason. Some contracts and PCI DSS still ask for it, so check the rule you are actually held to.

Why is forced password rotation no longer recommended?

Because people meet the deadline with the smallest edit that passes - Summer24! becomes Autumn24! - and a password derived from the old one is guessable from it. Rotation also does nothing about reuse across sites, phishing, or credentials already in a breach dump.

When should I actually change a password?

Immediately if the service reports a breach, if the password turns up in a breach corpus, if you typed it into a phishing page, or if you shared it with someone who no longer needs it. Otherwise leave a long unique password alone and turn on MFA.