Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

Password1! can pass a website’s character-composition test and still be predictable. NIST’s current password guidance rejects character-class rules—such as requiring uppercase letters, numbers, or symbols—and instead requires covered services to screen new passwords against a blocklist of commonly used, expected, or compromised values. That is why a password’s ability to satisfy a rule is not proof that it is hard to guess.

Why does Password1! pass the password rules?

A site that requires an uppercase letter, a number, and a symbol may accept Password1! because it contains all three. But those additions follow a familiar pattern: capitalize the first letter, add a number, then append a symbol. NIST uses this exact example in SP 800-63B-4, Appendix A, “Strength of Passwords”, explaining that composition rules can lead users to make predictable changes to otherwise simple passwords.

Passing a composition check only means the password meets that site’s formatting policy. It does not show that the password is uncommon, unique to that account, or resistant to guessing. NIST’s approach focuses on length and screening the complete proposed password against a blocklist rather than rewarding a particular mix of character types.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Does NIST require special characters in passwords?

No. Under the current NIST guidance, covered verifiers and Credential Service Providers (CSPs) must not require a password to include a particular combination of character types, such as uppercase letters, digits, or symbols. A website may still have its own rules, but those rules should not be mistaken for NIST’s current recommendation.

#1 Best Overall
OnlyKey FIDO2 / U2F Security Key and Hardware Password Manager | Universal Two Factor Authentication | Portable Professional Grade Encryption | PGP/SSH/Yubikey OTP | Windows/Linux/Mac OS/Android
  • ✅ PROTECT ONLINE ACCOUNTS – A password manager, two-factor security key, and secure communication token in one, OnlyKey can keep your accounts safe even if your computer or a website is compromised. OnlyKey is open source, verified, and trustworthy.
  • ✅ UNIVERSALLY SUPPORTED – Works with all websites including Twitter, Facebook, GitHub, and Google. Onlykey supports multiple methods of two-factor authentication including FIDO2 / U2F, Yubico OTP, TOTP, Challenge-response.
  • ✅ PORTABLE PROTECTION – Extremely durable, waterproof, and tamper resistant design allows you to take your OnlyKey with you everywhere.
  • ✅ PIN PROTECTED – The PIN used to unlock OnlyKey is entered directly on it. This means that if this device is stolen, data remains secure, after 10 failed attempts to unlock all data is securely erased.
  • ✅ EASY LOG IN –No need to remember multiple passwords because by plugging OnlyKey to your computer, it automatically inputs your username and password. It works with Windows, Mac OS, Linux, or Chromebook, just press a button to login securely!

NIST’s implementation FAQ explains the concern: users often respond to a special-character requirement by appending a symbol such as “!” to a familiar password. A character-mix rule can therefore create a predictable variation rather than a meaningfully stronger secret.

What does NIST actually recommend for passwords?

NIST SP 800-63B-4, published in July 2025, sets requirements for password length and screening. The minimum depends on whether the password is used alone or only within a multifactor authentication process.

Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Use NIST guidance
Password used as a single authentication factor Must be at least 15 characters long.
Password used only as part of a multifactor authentication (MFA) process May be shorter, but must be at least eight characters long.
Maximum length accepted Verifiers should permit a maximum length of at least 64 characters.

These are NIST requirements and a recommendation for covered verifiers, not a claim that every website already follows them. They also do not mean that a long password is automatically safe: the verifier must still screen the whole proposed password against a blocklist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Screen the whole password against a blocklist

When a user sets or changes a password, the verifier must compare the complete proposed password against a blocklist of commonly used, expected, or compromised values. If the proposed password is on that list, it must be rejected. NIST’s implementation FAQ describes this as a way to prevent the use of common values that are especially vulnerable.

Rank #3
Thetis Pro For Business - FIDO2 Security Key L1 MFA & NFC Passkey Access For School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesforce,Dual USB A +USB C
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-C, USB-A, & NFC): Designed for PCs, Macs, iPhones, and Android. For mobile use, simply unfold the key, align it with your phone’s NFC antenna, and hold for a few seconds to authenticate.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

This is whole-password screening; it does not mean NIST requires rejecting every dictionary word or every password that contains a familiar substring. The point is to block the proposed secret when the complete value is known to be commonly chosen, expected, or compromised.

Do not force calendar-based password changes

NIST says verifiers should not require users to change passwords periodically. A verifier must require a change when there is evidence that an authenticator has been compromised. That distinguishes a response to a real security signal from an expiration schedule that makes users change passwords simply because time has passed.

Rank #4
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.

How NIST’s approach differs from a typical composition rule

Question Character-composition policy NIST guidance
What is checked? Whether the password includes required character types, such as capitals, numbers, and symbols. Length, plus whether the complete proposed password appears on a blocklist.
Does authentication context affect the minimum? Not necessarily; the site defines its own policy. Yes. The minimum is 15 characters for single-factor use and at least eight when the password is used only with MFA.
When should the password change? A site may set a calendar-based expiration policy. No routine periodic change; require a change when there is evidence of compromise.
What entry features are supported? A site’s policy and form determine what users can enter. NIST recommends support for long passwords, password-manager autofill, and copy and paste.

What password-entry features should a service support?

Length requirements only help if users can create and enter passwords that meet them. NIST’s Customer Experience Considerations recommend allowing long passwords and supporting password-manager autofill and copy and paste. Those features make it easier to use long, distinct passwords without relying on memorable character substitutions.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Are passwords phishing-resistant?

No. NIST states that passwords are not phishing-resistant. Stronger length rules and blocklist screening address password strength and common choices; they do not prevent a user from being tricked into entering a password on a fraudulent site. MFA can add another layer, but do not treat composition rules—or password length—as protection against phishing.

Best Value
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.