Blog/Account security

How Long Should a Password Be?

How long a password should be, according to current guidance from NIST and the UK's NCSC, why length matters more than symbols, and how to make long passwords easy to remember.

CyberWatch AI29 September 2026 · 2 min read
A brass combination padlock resting on a laptop keyboard

For years we were told that a good password looks like P@ssw0rd!: a capital letter, a number, a symbol. Security experts now say that advice made passwords harder for people to remember without making them much harder for criminals to crack. What matters most is length, and uniqueness.

The short answer

Aim for at least 15 characters for important accounts. The easiest way to get there is a passphrase: three or four random words, such as copper-lantern-orbit-mango.

The US National Institute of Standards and Technology (NIST), whose guidance is widely followed, emphasises password length over complexity rules, and says systems should allow long passwords and should not force arbitrary composition rules or regular changes without reason. The UK's National Cyber Security Centre recommends combining three random words.

Why length beats symbols

Attackers guess passwords using powerful computers and lists of common passwords and patterns. Each extra character multiplies the number of possible combinations. Adding length grows that number far faster than swapping an "a" for an "@", a substitution that cracking tools already try automatically.

PasswordWhy it is weak or strong
Summer2026!Short, and follows a very common pattern (word, year, symbol). Easy to guess.
Tr0ub4dor&3Looks complex but is short and uses predictable substitutions.
copper-lantern-orbit-mangoLong and made of random words. Much harder to guess, and easier to remember.

These are examples only. Never use a password you have seen published anywhere, including here.

How to make a long password memorable

  • Pick random words, not a phrase from a song or a quote. Random is the key.
  • Picture them together: a copper lantern orbiting a mango. Silly images are easier to recall.
  • Add separators if you like, such as dashes or spaces where allowed.
  • Add a number or symbol only if a site insists.

Length is not the whole story

  1. Unique for every account. A long password reused across sites becomes useless the moment one site is breached. See why password reuse is so dangerous.
  2. Stored safely. A password manager lets you use long, unique passwords without memorising them all. See how to set up a password manager.
  3. Backed by two-step verification. Even a perfect password can be phished. See what two-step verification is.

Which passwords should you remember?

You only need to memorise a few long passphrases: for your email, your password manager, and your device. Let the password manager handle the rest with long random passwords.

Common questions

Should I change my passwords every few months?

Current guidance says no, unless there is a reason, such as a breach or a suspicion someone knows it. Forced regular changes tend to produce weaker, predictable passwords. See password myths.

What if a site limits password length?

Use the longest password allowed, and make sure two-step verification is on.

Got a "password expired" email? Paste it into CyberWatch AI Scan for a free check before you click. Fake password alerts are a common phishing trick.

Passwords are one part of keeping your accounts safe. For the rest, read our complete guide to identity theft and account security.

Frequently asked questions

What is the minimum password length I should use?

For important accounts, aim for at least 15 characters. A passphrase of three or four random words easily reaches that and is easier to remember than a short complex password.

Do I still need symbols and numbers?

Not necessarily. Current guidance focuses on length and uniqueness rather than forced complexity. Add them if a site requires it, but a long passphrase matters more.

Is a long password enough on its own?

No. It must also be unique to that account, and important accounts should have two-step verification. A long password reused on many sites is still dangerous.

Sources

  1. NIST SP 800-63B: Authentication and Lifecycle Management, US National Institute of Standards and Technology
  2. Three random words, UK National Cyber Security Centre
  3. Creating Strong Passwords and Other Ways To Protect Your Accounts, US Federal Trade Commission
Share this article
LinkedIn WhatsApp X
For organizations

Your people get these messages at work too.

CyberWatch AI sends your staff realistic practice attacks, trains the gaps it finds, and shows management exactly where the organization stands.