🔁 Password Rotation Calculator
Enter when you last changed a password and your organization's rotation policy to find the exact next-change date.
How the due date is worked out
The date you enter is read as midnight UTC, then the policy is added as a flat number of 86,400,000-millisecond days. Nothing is rounded to calendar months:
next_due = last_changed + policy_days
remaining = ceil((next_due - now) / 1 day)
2026-01-15 + 90 days = 2026-04-15
2026-03-01 + 90 days = 2026-05-30
90 days is not three months: from 1 March it lands on 30 May, because February is short. Working in fixed UTC days is also why a daylight-saving change never shifts the answer.
Reading the status line
- The badge is green above 7 days remaining, amber inside the last week, and red once the count goes negative, where it reports the days overdue.
- The countdown rolls over at midnight UTC, not local midnight, so west of Greenwich it can shed a day during your evening.
- Last Changed starts on today's date, so it shows a full policy period until you overwrite it with the real one.
Frequently asked questions
Is a 90-day password change still required?
Not by NIST, which since 2017 has said verifiers should not force arbitrary periodic changes; Microsoft dropped expiry from its Windows security baselines in 2019 for the same reason. Some contracts and PCI DSS still ask for it, so check the rule you are actually held to.
Why is forced password rotation no longer recommended?
Because people meet the deadline with the smallest edit that passes - Summer24! becomes Autumn24! - and a password derived from the old one is guessable from it. Rotation also does nothing about reuse across sites, phishing, or credentials already in a breach dump.
When should I actually change a password?
Immediately if the service reports a breach, if the password turns up in a breach corpus, if you typed it into a phishing page, or if you shared it with someone who no longer needs it. Otherwise leave a long unique password alone and turn on MFA.