Search

A a 0 #1 4/4
Uppercase A-Z
Lowercase a-z
Numbers 0-9
Symbols !@#$ 1
Extended (){}|
Compliance
US Government
Industry
European
International
Platform Defaults

Why This Matters

Most accounts get hacked because of weak or reused passwords. A short password can be cracked in seconds by modern hardware, and if you use the same one everywhere, one breach exposes all your accounts. A strong, unique password for each site is the single easiest thing you can do to protect yourself online.

The standards listed below come from government agencies and major organizations that set the rules for how passwords should work. They don't all agree on the details, but the takeaway is simple: longer is better, random is better, and never reuse passwords. Use a password manager so you don't have to remember them all.

Compliance Sources

US Government

StandardWhat it isUpdatedLengthA-Za-z0-9#$!
NIST 800-63B (pdf)Federal digital identity standard202415
CISAUS cybersecurity agency guidelines202416
FBI CJIS v6.0 (pdf)Criminal justice database access202420
DoD STIGMilitary system hardening rules202415
IRS Pub 1075 (pdf)Tax data protection rules202414
FedRAMPCloud security for federal agencies202414
CMMC 2.0 L2 (pdf)Defense contractor cybersecurity202314

Industry

StandardWhat it isUpdatedLengthA-Za-z0-9#$!
PCI DSS 4.0 (pdf)Credit card processing security202412
HIPAAHealthcare data privacy law202412
OWASP ASVS (pdf)Web app security checklist202312
CIS BenchmarkIT security best practices202414
NERC CIP-007 (pdf)Power grid cybersecurity20238
HITRUST CSFHealthcare IT security framework20248
FINRAWall Street broker-dealer rules202412
SWIFT CSCFFinancial messaging network security202412

European

StandardWhat it isUpdatedLengthA-Za-z0-9#$!
CNIL (France) (pdf)French data privacy regulator202312
ANSSI (France) (pdf)French cybersecurity agency202312
BSI (Germany) (pdf)German federal cyber office202412
ENISA (EU)EU cybersecurity agency guidelines202112

International

StandardWhat it isUpdatedLengthA-Za-z0-9#$!
UK NCSC (pdf)UK government cyber baseline202412
Australian ASDAustralia’s signals directorate202415
Canada GCCanadian government IT policy202312
Singapore CSA (pdf)Singapore cyber agency202312
Japan NISC (pdf)Japan’s cybersecurity center202210
New Zealand NZISMNZ government security manual202316
Korea ISMS-PKorean security certification202210

Platform Defaults

StandardWhat it isUpdatedLengthA-Za-z0-9#$!
Microsoft EntraAzure/M365 identity platform202412
Apple IDApple account login20238
AWS IAMAmazon cloud access management202414
Google WorkspaceGoogle business suite202412
SalesforceCRM platform20248
Oracle CloudEnterprise cloud platform202312
GitHubCode hosting platform202415
OktaSingle sign-on provider20238
AdobeCreative & document software202312
SnowflakeCloud data warehouse202414
StripePayment processing API202410
ZoomVideo conferencing platform20248
AtlassianJira/Confluence dev platform20248
GitLabDevOps platform, breach-checking20248
Docker HubContainer registry platform20249
npmJS package registry, HIBP checks20248
DropboxCloud storage, zxcvbn scoring20248
SlackTeam messaging platform20248
X / TwitterSocial media platform202410
PayPalPayment platform, max 20 chars20248
Meta / FacebookSocial media platform20246
SpotifyMusic streaming platform20248
LinkedInProfessional networking platform20246
TwitchLive streaming platform20248