Passwords protect email, financial accounts, social media, shopping accounts, cloud storage, and many other services. Unfortunately, outdated password advice can make account security more difficult than it needs to be.
Many people were once told to change every password every 30, 60, or 90 days. Current guidance takes a different approach: create strong, unique passwords and change them when there is a reason—not simply because the calendar says so.
How Often Should a Password Be Changed?
A strong, unique password does not normally need to be changed on a fixed schedule.
The current NIST Digital Identity Guidelines advise organizations not to require arbitrary periodic password changes unless there is evidence that a password has been compromised or the user requests a change.
Frequent forced changes can encourage people to create predictable passwords such as:
Summer2026!Summer2026!!Fall2026!PasswordJuly1!
An attacker who discovers one version may be able to guess the next one.
Instead of automatically replacing passwords every few months, conduct a password-security review several times a year. Look for reused, weak, old, or exposed credentials, but only change the passwords that need attention.
Change a Password Immediately When:
- A company reports a data breach involving passwords.
- A password manager or browser reports that the password was exposed.
- An unfamiliar device or location appears in the account’s login history.
- Someone successfully—or unsuccessfully—attempts to access the account.
- The password was entered into a suspicious website or phishing page.
- A computer or phone may contain malware or a keylogger.
- The password was accidentally shared, emailed, posted, or displayed publicly.
- The same password was used on another account that was compromised.
- Someone who knew a shared password should no longer have access.
If a reused password is exposed, replace it on every account where it was used. Begin with email, financial accounts, cloud storage, and the password manager itself.
The Federal Trade Commission also recommends changing a password immediately when a company reports that it was stolen in a breach.
What Makes a Password Strong?
The most important qualities are length, randomness, and uniqueness.
Every account should have a different password. Reusing one strong password across several websites is dangerous because attackers can take credentials stolen from one website and try them elsewhere. This is called credential stuffing.
When a password must be memorized, aim for at least 15 characters. Longer is generally better. A passphrase made from several unrelated words can be easier to remember than a shorter collection of symbols.
For example, the structure could resemble:
Lantern-River-Coffee-Planet-Window
Do not use that example as an actual password. Any password published online should be considered unsafe.
Avoid:
- Names of family members or pets
- Birthdays, addresses, and phone numbers
- Keyboard patterns such as
qwerty - Number sequences such as
123456 - Famous quotations and song lyrics
- Common words followed by a year or exclamation point
- Slight variations of passwords used on other accounts
NIST recommends using a password manager and making memorized passwords at least 15 characters long.
Let a Password Generator Do the Work
People are not very good at creating truly random passwords. A password generator can create a long, unpredictable password such as a random combination of letters, numbers, and symbols.
For passwords stored in a manager, consider generating at least 16 to 20 characters—or the longest password the website accepts. Because the manager remembers it, the password does not need to be easy to type or memorize.
Never paste a real password into an unfamiliar online “password strength checker.” A malicious or poorly protected checker could collect it.
Tools for Creating and Storing Passwords
A password manager is an encrypted vault that generates, stores, and fills passwords. It allows every account to have a unique password without requiring the user to memorize them all.
Common options include:
- Apple Passwords for people who primarily use Apple devices
- Google Password Manager for Chrome, Android, and Google accounts
- Microsoft Edge Password Manager
- Firefox Password Manager
- Dedicated password managers such as Bitwarden
These are examples, not endorsements. Compare reputable reviews, supported devices, security features, update history, recovery options, and cost before choosing a manager.
A browser’s built-in manager may be the easiest starting point. A dedicated manager may be preferable when passwords must work across several browsers, operating systems, or family members.
Protect the Password Manager
A password manager concentrates many credentials in one place, so the vault itself needs strong protection.
- Create a long, unique master passphrase.
- Never reuse the master passphrase anywhere else.
- Enable multifactor authentication on the vault.
- Keep the manager and all connected devices updated.
- Configure the vault to lock automatically.
- Store recovery information in a secure offline location.
- Learn the recovery process before an emergency occurs.
- Never approve an unexpected login notification.
Do not store the vault’s master password inside the vault as the only copy. If it must be written down, keep it in a locked and private physical location—not on a note attached to the computer.
For family or business passwords, use the manager’s secure sharing feature instead of sending credentials by text message or email.
Turn On Multifactor Authentication
Even an excellent password can be stolen through phishing, malware, or a data breach. Multifactor authentication, also called MFA or two-factor authentication, requires another form of verification.
An authenticator app, hardware security key, or passkey is generally preferable to a code delivered by email or text when stronger options are available.
According to CISA, strong passwords, a password manager, and MFA are among the most important steps people can take to protect their accounts.
Email deserves special attention because password-reset messages for other accounts are often delivered there. Protect the primary email account with a unique password and MFA.
Consider Using Passkeys
Some services now support passkeys. A passkey uses cryptographic credentials stored on a trusted device instead of a traditional password. Passkeys can be easier to use and are more resistant to phishing.
When a reputable service offers a passkey, consider enabling it. Keep recovery information current and protect every device that can access the passkey.
A Simple Password-Security Routine
Once every three or four months:
- Open the password manager’s security or password-health report.
- Look for reused, weak, and exposed passwords.
- Replace the most important risky passwords first.
- Review recent activity on email and financial accounts.
- Remove old accounts and unfamiliar signed-in devices.
- Confirm that MFA and recovery information still work.
- Install updates for the password manager, browser, and operating system.
- Check that recovery codes remain available in a secure location.
This is a security review—not a requirement to replace every healthy password.
Final Thoughts
Passwords should be changed because something has increased the risk, not merely because a certain number of days have passed.
The strongest practical approach is to use a password manager, generate a different long password for every account, protect the vault with MFA, and respond immediately to breach warnings or suspicious activity.
A person who uses 100 unique generated passwords is generally safer than someone who regularly rotates one memorable password across 100 accounts.
