How to Create a Strong Password

Modern password guidance puts much more weight on length and uniqueness than on forcing a particular mix of uppercase letters, numbers and symbols. The goal is a password that is hard to guess, different for every account, and easy to manage safely.

A good baseline: long and unique

You do not need to force complexity yourself

NIST's current guidance tells services not to impose composition rules such as “must contain one uppercase letter, one digit and one symbol.” Those rules often lead people to make predictable changes rather than genuinely stronger passwords. If a website requires a symbol or number, of course you must meet its rule; just do not mistake the rule itself for security.

A password manager-generated password may contain letters, digits and symbols because it is random. That is excellent. The important point is that randomness, length and uniqueness matter more than manually following a recipe.

The easiest strong strategy: use a password manager

If you need to remember a password yourself

Use a long passphrase made from unrelated words rather than a short word with obvious substitutions. Avoid names, birthdays, pets, teams, addresses, or phrases that someone could learn from your social media. Do not use the same “base password” with a different site name attached to the end; once an attacker sees one version, the pattern is easy to predict.

Do not change passwords on a fixed schedule

Routine password changes every 30, 60 or 90 days are no longer considered good general practice. Change a password when you have evidence or a credible reason to think it was exposed, when a service reports a breach affecting it, or when you accidentally reused or shared it. Otherwise, keep the strong unique password and avoid creating a weaker replacement just because the calendar says so.

Add protection beyond the password

What to do after a breach

  1. Change the affected password immediately.
  2. If you reused it anywhere else, change every reused copy.
  3. Sign out other sessions if the service offers that option.
  4. Enable MFA or a passkey.
  5. Watch the account for unfamiliar activity and review recovery settings.

Quick password checklist

Last reviewed: · Updated to reflect NIST SP 800-63B-4 password guidance