MorphPass.

GUIDE · CHECKED AGAINST NIST AND CISA ON OCTOBER 4, 2026

How to create a strong password

Short version: make it long, make it random, use it for one account only, and store it in a password manager. Below is what the official guidance says, how to apply it when a site has its own rules, and where a password stops being enough.

What official guidance says

Two U.S. government sources are worth reading directly. They are written for different readers, so they say slightly different things.

CISA: long, random, unique

CISA’s current guidance for small and medium businesses lists three properties. It says strong passwords are:

“Long: At least 16 characters long (more is better)
Random: A mix of upper/lowercase letters, numbers and symbols or a passphrase of 5–7 unrelated words
Unique: Used for only one account”

Source: CISA, “Require Strong Passwords”. An older CISA consumer page, now marked as archived content, gives the same three tips and adds that common identifying information, “like birthdays and pet names,” is not safe (archived CISA “Use Strong Passwords” page).

NIST SP 800-63B: what services should accept

NIST Special Publication 800-63B is written for organizations that run sign-in systems, mainly government systems. It sets rules for the service, not for you, but it explains a lot about why sites behave the way they do. In its password section NIST says:

  • “Verifiers and CSPs SHALL require passwords that are used as a single-factor authentication mechanism to be a minimum of 15 characters in length.” Passwords used only as part of multi-factor sign-in may be shorter, but at least eight characters.
  • “Verifiers and CSPs SHOULD permit a maximum password length of at least 64 characters.”
  • “Verifiers and CSPs SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types) for passwords.”
  • “Verifiers and CSPs SHALL NOT require subscribers to change passwords periodically. However, verifiers SHALL force a change if there is evidence that the authenticator has been compromised.”
  • Services should check new passwords against a blocklist of “known commonly used, expected, or compromised passwords.”

Source: NIST SP 800-63B, Password Verifiers. Many real sites still use older rules, such as “one uppercase letter, one number and one symbol.” You have to meet the rules of the site in front of you, even when they differ from NIST.

Step by step

  1. Pick a length first. Use at least 16 characters, as CISA advises, and go longer if the site allows it. MorphPass’s Password preset starts at 20.
  2. Let something random choose the characters. People are bad at being random. A generator or a password manager’s built-in generator does it for you. If you need to type the password from memory, for example the main password for your password manager, use a passphrase of unrelated words picked at random. CISA suggests 5–7 words.
  3. Leave out anything about you. Names, birthdays, pets, teams, and the site’s own name are guessable. NIST’s example blocklist includes “Context-specific words, such as the name of the service, the username, and derivatives thereof.”
  4. Use it for one account only. If one site leaks your password, attackers try the same email and password on other sites. This is called credential stuffing (Verizon’s credential-stuffing research). A unique password means one leak stays one leak.
  5. Save it before you leave the page. Put it straight into a password manager. NIST notes that “Password managers have been shown to increase the likelihood that subscribers will choose stronger passwords, particularly if the password managers include password generators” (NIST SP 800-63B). See Do I need a password manager?
  6. Turn on multi-factor authentication or a passkey. CISA advises pairing strong passwords with MFA because it “adds a critical layer of security even if a password is stolen” (CISA). Where a site offers passkeys, the FIDO Alliance describes them as “phishing-resistant” (FIDO Alliance).
  7. Change it when there is a reason. Change it after a breach notice, a phishing scare or malware on your device, not on a calendar schedule. That matches NIST’s rule above.

Why length matters more than one extra symbol

The arithmetic below is our own, not a source’s. It assumes every character is picked at random from MorphPass’s 86-character set (26 uppercase, 26 lowercase, 10 numbers and 24 symbols). Each added character multiplies the number of possible passwords by 86.

Possible passwords for a random string from 86 characters (our arithmetic)
LengthPossible strings (86length)Equivalent bits (length × log286)
8about 3.0 × 1015about 51
12about 1.6 × 1023about 77
16about 9.0 × 1030about 103
20about 4.9 × 1038about 129

These numbers only apply when the characters really are random. “Summer2026!” has upper case, lower case, numbers and a symbol, and it is still a predictable pattern. Composition rules also shrink the count slightly, because they rule out some strings. We don’t convert these figures into “time to crack.” That depends on how the service stores passwords and how fast an attacker can guess, and neither is visible to you.

When the site has its own rules

Some sites cap the length, ban certain symbols, or demand a fixed mix. Work within the rules but keep the length as high as the site allows:

  • If symbols are restricted, exclude the banned ones rather than dropping all symbols. MorphPass lets you exclude specific characters.
  • If the site demands, say, at least two numbers and two symbols, MorphPass’s exact counts can produce that format. See the worked examples.
  • If the site keeps saying no, read Password requirements keep rejecting my password.

What a strong password does not fix

A perfect password can still be stolen. You can type it into a fake login page, malware can collect it, or the service can be breached. The FBI and CISA describe infostealer malware that collects “financial credentials, cryptocurrency wallets, browser extensions, and multifactor authentication (MFA) details” (FBI/CISA advisory AA25-141B). That is why the steps above also cover MFA, passkeys and unique passwords. Our overview of how passwords get compromised covers each route.