A modern business password policy is simpler than the old one: require long passphrases (at least 15 characters, or 8 with multifactor authentication), block common and breached passwords, stop forcing scheduled password changes, give everyone a business password manager and require MFA on every account that supports it.

If your password policy still says “eight characters, one capital, one number, one symbol, change it every 90 days,” you’re not alone. A lot of small businesses around Dallas-Fort Worth inherited that rule years ago and never looked back. The trouble is that it produces passwords like Summer2026!, which are easy for attackers to guess and hard for people to remember. The national standard has moved on, and it’s worth catching up.

What are the current password requirements from NIST?

The National Institute of Standards and Technology finalized its updated digital identity guidelines (SP 800-63B-4) in August 2025. It’s written for federal systems, but it’s become the reference point for everyone. The highlights:

  • Length matters most. At least 15 characters when a password is the only factor, and at least 8 when it’s used with MFA. Allow at least 64 characters.
  • No complexity rules. NIST says organizations shall not require mixtures of character types.
  • No forced periodic changes. Change a password only when there’s evidence it was compromised.
  • Block bad passwords. Check new passwords against lists of common and breached passwords.
  • Allow password managers and pasting. NIST says verifiers shall allow password managers and autofill.
  • No security questions. NIST says systems shall not prompt for knowledge-based questions like “What was your first pet’s name?”

How long should a password be?

We recommend at least 15 characters for everyone, even with MFA, and longer for administrators. That sounds painful until you switch to passphrases. Four or five unrelated words, like gravel-pecan-lantern-rodeo, are long, easy to type and far harder to crack than a short jumble of symbols. Don’t use song lyrics, team names or anything tied to your company or family.

Is a passphrase better than a password?

For anything a person has to remember and type, yes. Length beats complexity because every added character multiplies the guesses an attacker needs. A passphrase gets you length without the sticky note on the monitor. For everything else, let the password manager generate long random passwords nobody needs to remember at all.

Why should businesses stop forcing password changes every 90 days?

Forced rotation sounds secure, but it pushes people into predictable patterns: Spring2026! becomes Summer2026!. Attackers know those patterns. Today’s bigger threat is stolen passwords being reused somewhere else. Verizon’s 2025 research on credential stuffing found that automated login attempts using stolen credentials made up a median of 19 percent of all authentication attempts, and that the typical infected user’s passwords were only about half unique. Rotation doesn’t fix reuse. Unique passwords, a password manager and MFA do.

Should a business use a password manager?

Yes. A business password manager is the single change that makes long, unique passwords realistic. Look for one with shared vaults for team credentials, admin controls so the company owns the vault, MFA on the vault itself, reporting on weak or reused passwords and a way to recover access when someone leaves. That last point connects to a bigger risk we cover in what happens if the only person with your admin passwords leaves.

Is LastPass safe after its breach?

LastPass suffered a major breach in 2022 when attackers stole a backup of customer vault data. In December 2025 the UK Information Commissioner’s Office fined LastPass £1.2 million over the incident. The ICO noted that encrypted vault passwords stayed protected because master passwords are never sent to LastPass. That’s the real lesson. A password manager is only as strong as the master password protecting the vault.

If you used LastPass before 2023, change the master password to a long passphrase, turn on MFA and rotate the most sensitive passwords stored in the vault, starting with banking, email and admin accounts. Whatever product you choose, check its security record and make sure it supports business administration rather than a collection of personal accounts.

Should you lie on security questions?

When a site forces you to use security questions, giving the true answer is the weaker choice. Your mother’s maiden name, high school mascot and first car are often findable on social media or public records. A better approach is to treat each answer like a password: use a random phrase that has nothing to do with the question, and store it in your password manager. For your own systems, follow NIST and don’t use security questions for account recovery at all.

How do you secure business accounts beyond passwords?

  1. Turn on MFA everywhere, starting with email, banking, payroll, remote access and admin accounts. Authenticator apps or passkeys are stronger than text messages.
  2. Block common and breached passwords. In Microsoft 365, Entra Password Protection does this and lets you add your own banned words, like your company name.
  3. Give admins separate accounts for admin work, with stronger sign-in requirements.
  4. Remove access promptly when people leave or change roles.
  5. Train people on phishing, because the strongest password doesn’t help if someone types it into a fake login page. Our guide on how to spot a phishing email covers the warning signs.

What should a small business password policy include?

Here’s a plain-language starting point you can adapt:

  • Passwords must be at least 15 characters. Passphrases are encouraged.
  • No complexity rules and no scheduled changes. Passwords are changed when there’s any sign of compromise.
  • Every password must be unique. Work passwords are never reused on personal sites.
  • All work credentials are stored in the company password manager.
  • MFA is required on every system that supports it.
  • Passwords are never shared by email, chat or text.
  • Suspected compromises are reported to IT immediately.

One page, written in normal language and actually enforced by your systems, beats a ten-page policy nobody reads.

Frequently asked questions

What are the strong password requirements in 2026?

Current NIST guidance calls for at least 15 characters when a password is used alone, or 8 with MFA, no forced complexity rules, no scheduled changes and screening against lists of common and breached passwords.

How often should employees change their passwords?

Only when there’s evidence a password has been compromised. NIST no longer recommends scheduled changes because they lead to weaker, predictable passwords.

Are password managers safe for business?

Yes, when the vault is protected by a long master passphrase and MFA. A reputable business password manager is far safer than reused passwords, spreadsheets or sticky notes.

Is it OK to lie on security questions?

Yes. Using made-up answers stored in your password manager is safer than true answers that can be found online. Treat each answer like a password.

What is the best way to secure business accounts?

Combine long, unique passwords stored in a business password manager with multifactor authentication on every account, separate admin accounts and prompt removal of access when people leave.

How The Fulcrum Group helps

We help North Texas organizations replace outdated password rules with something people will actually follow. Through SPOT Managed Security Services, that includes password manager rollout, MFA, Microsoft 365 password protection settings, admin account cleanup and short staff training on passphrases and phishing.

If your password policy hasn’t been touched in years, Schedule a Discovery Call.