RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Defense

Defense / From the archive · June 2017 record · prepared 16 September 2026

Federal guidance dropped forced password changes and complexity rules

NIST's 2017 authentication guideline asked for breach screening instead of periodic changes, and practice lagged for years.

Visual for this record: Federal guidance dropped forced password changes and complexity rules
Visual published by pages.nist.gov, shown for identification of the record. Credit: pages.nist.gov · source page ↗ Rights: owner-review-pending.

What the document says

NIST Special Publication 800-63B, published in June 2017, sets federal technical requirements for authenticating people to government systems, and its treatment of passwords, which it calls memorized secrets, broke with decades of common practice. According to the document's text, verifiers should not require memorized secrets to be changed arbitrarily, such as periodically, reserving forced changes for evidence that a password has actually been compromised. It similarly advises that verifiers should not impose other composition rules, such as requiring a mix of character types, because such rules had been shown to push people toward predictable patterns rather than genuinely stronger secrets. In place of both practices, the document requires that new passwords be checked against a list of values known to be commonly used, expected or compromised, including passwords drawn from previous breaches, with a match triggering a request for a different secret.

A parallel guidance collection from the UK's National Cyber Security Centre, reflecting the document as currently published, reaches the same conclusions independently, stating that forcing password expiry carries no real benefits and that complexity rules cause users to adopt predictable patterns that attackers already anticipate. It recommends deny lists of common passwords instead.

Confidence and limits

The core guidance is confirmed directly from NIST's own published text, and the UK national guidance corroborates the same recommendations from an independent body, so the substance of the shift is well established. The NIST publication record shows the document was later updated and, as of this document's retrieval, has itself been withdrawn in favour of a newer revision; this article describes the June 2017 guidance and its adoption, not the current state of NIST's authentication standards.

Why it mattered

Periodic forced password changes and complex composition rules had been standard corporate and government policy for years, often written into audit checklists and compliance frameworks well before 2017. Because those rules were embedded in policy documents, vendor defaults and long-running organisational habits, many organisations continued requiring quarterly changes and mandatory special characters long after the federal guidance reversed course, since changing an entrenched, audited policy takes longer than publishing a standard. The gap between publication and practice recurs whenever a standards body reverses long-held conventional wisdom.

Defensive takeaway

Check whether your organisation's password policy still mandates periodic changes or composition rules for their own sake, and if so, replace them with a minimum length requirement and continuous screening against known-breached password lists.

  • Does your password policy still force periodic changes for accounts with no evidence of compromise?
  • Are new passwords screened against a current list of known-breached or commonly used passwords before being accepted?
  • If your policy still requires specific character-type mixes, can you trace that requirement to a current standard rather than an old audit checklist?

The 2017 guidance did not ban passwords or declare them obsolete; it redirected effort toward screening and length and away from rules that mainly changed how predictably people misbehaved, and organisations that have not revisited their own policy since are very likely enforcing a standard NIST itself abandoned years ago.

Defensive takeaway

Check whether your organisation's password policy still mandates periodic changes or composition rules for their own sake, and if so, replace them with a minimum length requirement and continuous screening against known-breached password lists.

The core guidance is quoted directly from NIST's own published text and corroborated independently by UK national guidance; the underlying NIST publication has since been superseded, and this article describes the 2017 guidance and its adoption rather than the current standard.

Sources & reading trail

SP 800-63B: Digital Identity Guidelines – Authentication and Lifecycle Management ↗

Direct text of the requirement to drop mandatory periodic password changes and composition rules, and to screen against known-breached password lists.

government-primary · Source published: Not established · Retrieved: 16 September 2026

SP 800-63B (Withdrawn), Digital Identity Guidelines: Authentication and Lifecycle Management ↗

Confirms the June 2017 publication date and that the document has since been withdrawn and superseded.

government-primary · Source published: 1 June 2017 · Retrieved: 16 September 2026

Password administration for system owners: updating your approach ↗

UK national guidance independently reaching the same conclusions against forced password expiry and complexity rules, as currently published.

government-primary · Source published: Not established · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.