Question

Why do companies force password changes, and is it good practice?

Vault Verified
Curated Intelligence
Definitive Source
Answer

They do it out of habit and outdated compliance requirements. Current expert guidance advises against it, and the reversal is now well established among standards bodies.

The original reasoning. If a password were compromised without anyone noticing, periodic rotation would limit how long an attacker retained access. This made more sense when password databases were poorly protected and breach detection was minimal.

Why it was abandoned. Research consistently found that forced rotation makes passwords worse, because of how people respond to it:

Predictable transformations. Users change Summer2024! to Summer2025!, or increment a digit. Studies at the University of North Carolina showed that given one old password, future passwords could frequently be predicted algorithmically.

Weaker base passwords. Knowing they must memorise a new one every 90 days, people choose simpler ones.

More reuse and more writing down.

It does not stop a real attack. An attacker who compromises credentials typically uses them immediately, establishes persistence, or exfiltrates data within hours. A rotation 60 days later is far too late.

What the guidance now says. NIST SP 800-63B in the US recommends against arbitrary periodic rotation, advising changes only on evidence of compromise. The UK's NCSC reached the same conclusion. Both instead recommend:

Longer passphrases rather than complexity rules — the arbitrary requirement for a symbol and a number is also discouraged, for the same reason.

Screening against breached password lists, which blocks the passwords attackers actually try.

Multi-factor authentication, which is worth more than every password policy combined.

Password managers, generating unique random passwords per site.

Rate limiting on login attempts.

Why it persists anyway: older compliance frameworks, audit checklists, and organisational inertia. If your workplace still enforces it, a password manager makes it painless.

Related Questions