Compliance

Password Policy Compliance Checker

Check a password policy against NIST SP 800-63B, PCI DSS 4.0 and CIS Benchmarks, including the rules that changed and the composition and rotation requirements that current guidance now advises against.

Last reviewed by the Radiatus Cloud team

Findings appear here.

Going for ISO 27001, SOC 2, HIPAA or GDPR?

Radiatus runs end-to-end compliance & GRC programs.

Get a free readiness review

The guidance reversed and most policies did not

NIST SP 800-63B abandoned mandatory periodic rotation and composition rules years ago, on the evidence that both make passwords weaker rather than stronger. Forced rotation produces predictable increments, and composition rules push users toward the same handful of substitutions. The current guidance is the opposite of what most corporate policies still say: long minimums, no forced expiry without evidence of compromise, no character-class requirements, and a check against known-breached passwords.

Standards now disagree with each other

PCI DSS 4.0 moved toward NIST but not all the way, requiring a 12-character minimum and retaining 90-day rotation unless dynamic risk analysis is performed instead. An organisation subject to both has to satisfy the stricter of two rules that point in different directions, which is why a policy usually needs to be written against a specific standard rather than against good practice in the abstract. This tool reports each standard separately rather than blending them into a single verdict.

Blocklists do more than any length rule

Checking a proposed password against a list of known-breached and obviously weak values removes far more real risk than adding a character class. Credential stuffing works because people reuse passwords that already appear in public breach corpora; length and complexity rules do nothing against that, and a blocklist does. It is the single most effective requirement in the current guidance and the one most often left unimplemented.

Related tools

Frequently Asked Questions

Should passwords expire every 90 days?

NIST SP 800-63B advises against periodic rotation without evidence of compromise, because it produces predictable increments. PCI DSS 4.0 still requires 90 days unless you perform dynamic risk analysis of account posture instead.

Why does NIST advise against complexity rules?

Because composition requirements push users toward the same predictable substitutions while making passwords harder to remember. The evidence is that they reduce rather than increase real resistance to guessing.

What minimum length should I set?

NIST sets 8 as the floor for user-chosen secrets and recommends allowing at least 64. PCI DSS 4.0 requires 12. CIS Benchmarks commonly specify 14 for privileged accounts.

What is a password blocklist?

A list of known-breached, dictionary and context-specific values that are rejected at the point the user sets a password. It removes more real risk than any composition rule, because credential stuffing relies on reuse of passwords already in public breach corpora.

Why report each standard separately?

Because they disagree. PCI DSS 4.0 and NIST point in different directions on rotation, and blending them into one verdict would hide the conflict you actually have to resolve.

Privacy & Security

Everything runs in your browser; nothing is uploaded.

Data: None
Client-side-Side
Active
v1.0

How to Use

Enter your current policy settings and review the findings.

Disclaimer: This tool is provided "as is" without warranty of any kind. Results are for educational and utility purposes.