Back to the tool

Should You Change Your Passphrase Every 90 Days? What NIST Says Now

How often should you change your passphrase? The honest answer is: not on a timer. NIST now tells services to stop forcing rotation, and the research behind that reversal is worth understanding.

My old workplace used to lock everyone out every 90 days until they picked a new password. Every quarter the same ritual: Spring2025! becomes Summer2025!, everyone grumbles, and IT declares the network secure. I believed this was sensible for years. It is not. It never was.

The National Institute of Standards and Technology said so plainly in SP 800-63B: verifiers "SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)." That line has survived through Revision 4. Microsoft and the UK NCSC dropped forced expiration from their baselines too. This is not a fringe opinion anymore; it is the consensus.

How often should you change your passphrase? Only when something happens.

NIST's position is compromise-driven expiration. You change a passphrase when there is evidence the credential may be compromised, not when a calendar says so. The evidence list is short and concrete:

Absent any of that, a strong passphrase does not rot. Math does not expire. A six word diceware passphrase is just as uncrackable at month 14 as it was on day one. (If you have not run the numbers, the entropy math is here.)

Why forced rotation made things worse

The research that flipped NIST found that scheduled changes push people toward weaker baseline secrets. When you know you will have to invent a new password in 90 days, you do not invest in a strong one. You pick something disposable and then mutate it predictably: a season, a year, an incremented digit at the end.

Attackers know these habits. A "changed" password that differs from the old one by one character is barely a new password at all. Forced rotation also drives people to write passwords down on sticky notes or reuse one base password across systems with small variations, exactly the behaviors that cause real breaches. The policy designed to limit the damage of a stolen password instead multiplied the number of weak passwords in circulation.

The one exception worth knowing: some regulations still require periodic rotation. PCI-DSS historically did, though version 4.0 relaxed the requirement where MFA is in place. Where a specific regulation conflicts with NIST, the regulation wins. Document your reasoning either way.

What I do instead

I keep one long, random, unique passphrase per important account, generated rather than invented, and I do not touch it unless a trigger fires. Each one gets checked against breach databases at creation. Multi-factor authentication goes on every account that offers it, because a stolen passphrase behind MFA is a failed attack.

That is the whole system. No 90 day timer. No seasonal mutations. The passphrase I memorized for my password manager's master secret (here is the setup I recommend) has been the same for years, and I have no plans to change it, because no trigger has fired.

If a breach notification lands in my inbox tomorrow, I will change exactly the affected credential, immediately, and then go back to leaving everything else alone. That is compromise-driven expiration. It is less work than the old ritual, and it is actually safer.

Frequently asked questions

How often should I change my passphrase?

Not on a schedule. Change it when there is evidence of compromise: it appears in a breach, you reused it somewhere that was breached, you typed it into a suspicious site, or the service reports suspicious activity. NIST SP 800-63B explicitly advises against arbitrary periodic changes.

Why did companies stop requiring 90 day password changes?

Research showed forced rotation made security worse. People picked weaker baseline passwords and applied predictable transformations like Summer2025 to Autumn2025, which attackers anticipate. NIST, Microsoft, and the UK NCSC now all recommend against scheduled rotation.

What should I do instead of rotating my passphrase?

Pick one long, unique, random passphrase per account and keep it. Check it against Have I Been Pwned, enable multi-factor authentication everywhere it is offered, and change the passphrase the moment any compromise evidence appears.

Does a passphrase need changing if the site gets breached?

Yes. A confirmed or suspected breach of the service is the clearest trigger. Change that passphrase immediately, and change it anywhere else you reused it. This is also why every important account deserves its own unique passphrase.

Related reading: How Many Words Does Your Passphrase Need? Entropy Math, Worked Out · How to Remember a Long Passphrase · The Password Manager Emergency Sheet: What to Write Down and Where to Keep It

One practical security guide a week. Get it by email.

Try the tool

Long, random, and unique is the whole strategy. Generate a passphrase now on the homepage. It runs entirely in your browser and takes about three seconds.

Get new free tools by email

Want the next guide in your inbox? I publish one practical guide per new tool. Subscribe to the free newsletter on Substack. No spam, unsubscribe anytime.