
What the document says
NIST Special Publication 800-63B, published in June 2017, sets federal technical requirements for authenticating people to government systems, and its treatment of passwords, which it calls memorized secrets, broke with decades of common practice. According to the document's text, verifiers should not require memorized secrets to be changed arbitrarily, such as periodically, reserving forced changes for evidence that a password has actually been compromised. It similarly advises that verifiers should not impose other composition rules, such as requiring a mix of character types, because such rules had been shown to push people toward predictable patterns rather than genuinely stronger secrets. In place of both practices, the document requires that new passwords be checked against a list of values known to be commonly used, expected or compromised, including passwords drawn from previous breaches, with a match triggering a request for a different secret.
A parallel guidance collection from the UK's National Cyber Security Centre, reflecting the document as currently published, reaches the same conclusions independently, stating that forcing password expiry carries no real benefits and that complexity rules cause users to adopt predictable patterns that attackers already anticipate. It recommends deny lists of common passwords instead.
Confidence and limits
The core guidance is confirmed directly from NIST's own published text, and the UK national guidance corroborates the same recommendations from an independent body, so the substance of the shift is well established. The NIST publication record shows the document was later updated and, as of this document's retrieval, has itself been withdrawn in favour of a newer revision; this article describes the June 2017 guidance and its adoption, not the current state of NIST's authentication standards.
Why it mattered
Periodic forced password changes and complex composition rules had been standard corporate and government policy for years, often written into audit checklists and compliance frameworks well before 2017. Because those rules were embedded in policy documents, vendor defaults and long-running organisational habits, many organisations continued requiring quarterly changes and mandatory special characters long after the federal guidance reversed course, since changing an entrenched, audited policy takes longer than publishing a standard. The gap between publication and practice recurs whenever a standards body reverses long-held conventional wisdom.
Defensive takeaway
Check whether your organisation's password policy still mandates periodic changes or composition rules for their own sake, and if so, replace them with a minimum length requirement and continuous screening against known-breached password lists.
- Does your password policy still force periodic changes for accounts with no evidence of compromise?
- Are new passwords screened against a current list of known-breached or commonly used passwords before being accepted?
- If your policy still requires specific character-type mixes, can you trace that requirement to a current standard rather than an old audit checklist?
The 2017 guidance did not ban passwords or declare them obsolete; it redirected effort toward screening and length and away from rules that mainly changed how predictably people misbehaved, and organisations that have not revisited their own policy since are very likely enforcing a standard NIST itself abandoned years ago.
Check whether your organisation's password policy still mandates periodic changes or composition rules for their own sake, and if so, replace them with a minimum length requirement and continuous screening against known-breached password lists.
The core guidance is quoted directly from NIST's own published text and corroborated independently by UK national guidance; the underlying NIST publication has since been superseded, and this article describes the 2017 guidance and its adoption rather than the current standard.
Sources & reading trail
Direct text of the requirement to drop mandatory periodic password changes and composition rules, and to screen against known-breached password lists.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Confirms the June 2017 publication date and that the document has since been withdrawn and superseded.
government-primary · Source published: 1 June 2017 · Retrieved: 16 September 2026
UK national guidance independently reaching the same conclusions against forced password expiry and complexity rules, as currently published.
government-primary · Source published: Not established · Retrieved: 16 September 2026
Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.