Template

Password Policy

Modern, usable password and authentication rules that people can actually follow.

Intended audience
All staff; enforced by whoever administers accounts
Difficulty
Beginner
Estimated time
20 minutes
Access
Free
NIST SP 800-63
NIST SP 800-171
All industries

Version v1.0.0 · Last reviewed 2026-08-01 · Document owner: ComplianceAnvil Content Team

What you will be able to do

  • Set a minimum password length rather than relying on complexity rules alone.
  • Decide when password rotation should occur based on suspected compromise, not a fixed calendar.
  • Apply stricter rules to administrative accounts, including separation from daily-use accounts.
  • Document how shared accounts are handled when they cannot be avoided.

1. Requirements

  • Minimum length of at least 12 characters; length beats complexity.
  • No reuse of work passwords on any other service.
  • A company password manager is used to store and generate credentials.
  • MFA is required wherever it is available.

2. Rotation

Passwords are changed on suspicion of compromise rather than on a forced schedule, unless a contract or regulator requires otherwise.

3. Administrative accounts

  • Separate from daily-use accounts.
  • MFA always required.
  • Reviewed at least quarterly.

4. Shared accounts

Prohibited by default; where unavoidable, document owner, purpose, and rotation.

Key takeaways

  • Length matters more than complexity: the template sets a 12-character minimum instead of arbitrary symbol requirements.
  • Modern guidance favors event-driven password changes, such as suspected compromise, over forced periodic rotation.
  • A company password manager should be the standard way credentials are generated and stored, not an optional convenience.
  • Administrative accounts need to be separate from everyday accounts and reviewed at least quarterly because they carry more risk.
  • Shared accounts should be avoided by default, and where unavoidable, documented with an owner, purpose, and rotation plan.

Sources

Written from these public, authoritative publications. ComplianceAnvil paraphrases and summarizes them; it does not reproduce copyrighted control text.

How this was written and reviewed

Published
Author
ComplianceAnvil Editorial Team
Technical reviewer
ComplianceAnvil Technical Review Board
Jurisdiction
United States (federal)
First published
2026-08-01
Last reviewed
2026-08-01
Next review due
2027-08-01

Version v1.0.0 · Document owner: ComplianceAnvil Content Team

Important

This template is provided for readiness and educational purposes. Organizations should review and adapt it for their environment.

Matched on shared frameworks, topics, and program packs.

Quick reference

Password Best Practices — One Page

Post it by the desk: the current, sane guidance on passwords and multi-factor authentication.

Beginner
4 min
Free
NIST SP 800-63

Published · v1.0.0 · 2026-08-01

Exercise

Build a Sample SSP Section

Draft one System Security Plan section end to end, using the narrative pattern assessors expect.

Advanced
25 min
Free
NIST SP 800-171
CMMC

Published · v1.0.0 · 2026-08-01

Exercise

Build Your First Asset Inventory

Practice building an inventory from a realistic ten-person business, then apply the same pattern to your own.

Beginner
20 min
Free
CIS Controls
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Exercise

Classify Sample Data

Sort realistic records into classification levels and defend the handling rules that follow.

Intermediate
15 min
Free
NIST SP 800-171
ISO 27001

Published · v1.0.0 · 2026-08-01

Checklist

CMMC Readiness Checklist

Work through the preparation steps most small contractors miss before a CMMC assessment: scope, system boundary, documentation, and evidence.

Intermediate
45 min
Free
CMMC
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Guide

Common Compliance Mistakes

The recurring, expensive errors we see small businesses make — and the cheap correction for each.

Beginner
9 min
Free
NIST CSF
NIST SP 800-171

Published · v1.0.0 · 2026-08-01

Put this into practice

Resources tell you what good looks like. A Program Pack does the work with you — generated documentation, tracked controls, training, and evidence in one workspace.