Your Password Policy Is Due for a 2025 Refresh: What NIST Now Recommends
NIST’s 2025 update to SP 800-63B replaces fiddly complexity rules with what actually works: long passphrases, breached-password screening, and phishing-resistant MFA. This guide explains the changes in plain English and shows how to build a password policy that improves real-world security while reducing user friction.