One Click Answers

In plain English

How strong does a password really need to be?

· 2 min read

The Simple Answer

Long, random and different for every account. Current United States government guidance puts length first: a password that is the only thing protecting an account should be at least 15 characters.

The guidance comes from NIST, which writes the rules federal agencies follow for logging people in. Its latest version, published in August 2025, changed some things people had been told for years.

What NIST now says

  • A password used on its own should be at least 15 characters long. If a second step, such as a code from your phone, is also required, the minimum is eight.
  • Sites should accept passwords of at least 64 characters.
  • Sites should not force a mixture of uppercase, numbers and symbols.
  • Sites should not make you change a password on a schedule, only if there is evidence it has been exposed.
  • Sites should check new passwords against lists of ones that are common or have leaked.

Why length does the work

A password is only as strong as the number of different passwords an attacker would have to try. That number grows very fast with each extra character. Eight random lowercase letters give 26 to the power of 8, about 209 billion possibilities. Fifteen give about 1.7 sextillion, which is about 8 billion times more. Every extra letter multiplies the total by 26.

How many passwords are possible
PasswordPossibilities
8 random characters from the whole keyboard (94 symbols)about 6.1 quadrillion
12 random lowercase lettersabout 95 quadrillion
15 random lowercase lettersabout 1.7 sextillion

Read the table carefully: twelve plain lowercase letters beat eight characters of every kind by a factor of about sixteen. That is why adding a symbol to a short password helps far less than making it longer.

Random words are a good shortcut

Words are easier to remember than strings of characters, and they work if a machine picks them at random. Five words chosen from a list of 978 give about 890 trillion possibilities, and six give about 860 quadrillion. The catch is the word "random". Words you choose yourself, or a favorite quote, are far easier to guess.

What matters even more

A strong password used on two sites is only as safe as the weaker site. Use a different one for every account and let a password manager remember them, so that you only have to remember one good one. These are counts of possibilities, not promises: nothing here can guarantee that a password stays safe.

Password Generator: Make a random password, or switch to memorable words joined by hyphens. Everything is made in your browser and never sent anywhere.

Password Strength Checker: See an estimate of how strong a password is. It runs in your browser and does not store what you type.

How we know

How the numbers were worked out. The number of possible passwords is the size of the character set raised to the length (for example 26 letters to the power of 8). For random words it is the list size, then one fewer for each word, multiplied together. These are counts of possibilities, not predictions of how long anything takes to crack.

Sources

  • NIST Special Publication 800-63B, Revision 4, "Digital Identity Guidelines: Authentication and Authenticator Management" (August 2025): a password used alone should be at least 15 characters; sites should allow at least 64; should not force mixtures of character types; should not force regular changes; should check passwords against lists of known compromised ones.

Published by OneClickAnswers.

You might also wonder...

Try it yourself

← All articles