Should You Change Your Passphrase Every 90 Days? What NIST Says Now
How often should you change your passphrase? The honest answer is: not on a timer. NIST now tells services to stop forcing rotation, and the research behind that reversal is worth understanding.
My old workplace used to lock everyone out every 90 days until they picked a new password. Every quarter the same ritual: Spring2025! becomes Summer2025!, everyone grumbles, and IT declares the network secure. I believed this was sensible for years. It is not. It never was.
The National Institute of Standards and Technology said so plainly in SP 800-63B: verifiers "SHOULD NOT require memorized secrets to be changed arbitrarily (e.g., periodically)." That line has survived through Revision 4. Microsoft and the UK NCSC dropped forced expiration from their baselines too. This is not a fringe opinion anymore; it is the consensus.
How often should you change your passphrase? Only when something happens.
NIST's position is compromise-driven expiration. You change a passphrase when there is evidence the credential may be compromised, not when a calendar says so. The evidence list is short and concrete:
- The passphrase or account shows up in a known breach database (check Have I Been Pwned).
- The service tells you about suspicious activity or a breach on their end.
- You typed it into a site you now suspect, a phishing page, or shared Wi-Fi login you would not trust again.
- You reused it somewhere, and that somewhere got breached. This one is the silent killer.
Absent any of that, a strong passphrase does not rot. Math does not expire. A six word diceware passphrase is just as uncrackable at month 14 as it was on day one. (If you have not run the numbers, the entropy math is here.)
Why forced rotation made things worse
The research that flipped NIST found that scheduled changes push people toward weaker baseline secrets. When you know you will have to invent a new password in 90 days, you do not invest in a strong one. You pick something disposable and then mutate it predictably: a season, a year, an incremented digit at the end.
Attackers know these habits. A "changed" password that differs from the old one by one character is barely a new password at all. Forced rotation also drives people to write passwords down on sticky notes or reuse one base password across systems with small variations, exactly the behaviors that cause real breaches. The policy designed to limit the damage of a stolen password instead multiplied the number of weak passwords in circulation.
The one exception worth knowing: some regulations still require periodic rotation. PCI-DSS historically did, though version 4.0 relaxed the requirement where MFA is in place. Where a specific regulation conflicts with NIST, the regulation wins. Document your reasoning either way.
What I do instead
I keep one long, random, unique passphrase per important account, generated rather than invented, and I do not touch it unless a trigger fires. Each one gets checked against breach databases at creation. Multi-factor authentication goes on every account that offers it, because a stolen passphrase behind MFA is a failed attack.
That is the whole system. No 90 day timer. No seasonal mutations. The passphrase I memorized for my password manager's master secret (here is the setup I recommend) has been the same for years, and I have no plans to change it, because no trigger has fired.
If a breach notification lands in my inbox tomorrow, I will change exactly the affected credential, immediately, and then go back to leaving everything else alone. That is compromise-driven expiration. It is less work than the old ritual, and it is actually safer.
Frequently asked questions
How often should I change my passphrase?
Not on a schedule. Change it when there is evidence of compromise: it appears in a breach, you reused it somewhere that was breached, you typed it into a suspicious site, or the service reports suspicious activity. NIST SP 800-63B explicitly advises against arbitrary periodic changes.
Why did companies stop requiring 90 day password changes?
Research showed forced rotation made security worse. People picked weaker baseline passwords and applied predictable transformations like Summer2025 to Autumn2025, which attackers anticipate. NIST, Microsoft, and the UK NCSC now all recommend against scheduled rotation.
What should I do instead of rotating my passphrase?
Pick one long, unique, random passphrase per account and keep it. Check it against Have I Been Pwned, enable multi-factor authentication everywhere it is offered, and change the passphrase the moment any compromise evidence appears.
Does a passphrase need changing if the site gets breached?
Yes. A confirmed or suspected breach of the service is the clearest trigger. Change that passphrase immediately, and change it anywhere else you reused it. This is also why every important account deserves its own unique passphrase.
Related reading: How Many Words Does Your Passphrase Need? Entropy Math, Worked Out · How to Remember a Long Passphrase · The Password Manager Emergency Sheet: What to Write Down and Where to Keep It
One practical security guide a week. Get it by email.