top of page

NIST Revises Identity Guidelines, Including Password Requirements




ICYMI last week, Finally after we have been hounding them for 15 years, NIST Revised their Identity Guidelines, Including Password Requirements (SP800-63-4) suggesting that credential service providers (CSPs) stop recommending passwords using several character types and stop mandating periodic password changes unless the authenticator has been compromised. Other notable recommendations include passwords between 15 and 64 characters long and CSPs should allow ASCII and Unicode characters to be included in passwords. Accessible here:

 
 
 

Recent Posts

See All
New Microsoft SIRT interesting read

An interesting read from Microsoft about a multi-stage campaign observed between April 14 and 16, 2026, targeting more than 35,000 users across 13,000 organisations in 26 countries. https://www.micros

 
 
 

Comments


© 2026 Dan Weis

danweis.me

bottom of page