Skip to content
VaultPass

Passwords

How often should you change your password? The answer changed

The VaultPass desk4 min read
The face of an antique clock

The ninety-day password change was, for two decades, the most widespread security policy in the corporate world. It was also one of the most damaging, and the people who invented it have spent years asking everyone to drop it.

For twenty years, password expiry was the symbol of an organisation taking security seriously. Every ninety days, millions of people got the notice that it was time to change.

In 2017 the American National Institute of Standards and Technology — the same body that had popularised the practice — published a revision of its guidance saying the opposite: do not force periodic password changes unless there is evidence of compromise. The British National Cyber Security Centre reached the same conclusion.

It was not a change of fashion. It was the result of watching what people actually did.

Why the rule failed

Expiry had an apparently solid logic: if someone steals your password without your noticing, periodic changes limit how long it stays useful.

The problem is what it does to people.

It produces worse passwords. Nobody invents a strong, fresh key every quarter. What they do is increment: Summer2024!, Summer2024!!, Summer2025!. The studies that measured this found that, knowing one of a user’s old passwords, the new one could be guessed within a few attempts in a very high share of cases. In other words: forced change made keys more predictable, not less.

It pushes people to write them down badly. If you have to relearn a key every three months, it ends up on a sticky note under the keyboard or in a file called passwords.txt.

It arrives too late. This is the decisive argument. When credentials are stolen, nobody waits eighty days to use them. They use them within hours. By the time the scheduled change comes round, the damage is done and the attacker has been inside for a while — often with an open session or a forwarding rule in place that changing the password does not touch.

It is exhausting. And security fatigue is real: someone who receives too many alerts stops paying attention exactly when the one that mattered arrives.

The current recommendation is to change a password when there is a reason. These are the reasons:

  • It appears in a breach. You can check with the breach checker.
  • You suspect someone knows it. An ex-partner, a colleague, someone who looked over your shoulder.
  • You typed it on a shared or borrowed computer, in a hotel, an internet café, or a work laptop if the account is personal.
  • You fell for phishing, even if you realised two seconds later.
  • It is reused. If you use it on more than one site, that alone is reason enough.
  • It is weak. Short, containing a dictionary word, or following an obvious pattern.
  • A service has had a breach, even if they say passwords were encrypted.

Outside those cases, a long, random, unique password can live for years untouched. It does not decay over time.

The comparison that settles it

Picture two people.

Ana changes her password every ninety days, as her employer requires. Her current key is Autumn2025!. She uses it, with variations, at work and on her personal email.

Ben has a different password on every service, all generated at random by his manager, and has not changed any of them in three years. He has two-factor authentication on his email and his bank.

Ben is enormously better protected, and he has not changed a password in three years. Change frequency was never the variable that mattered: uniqueness, length and the second factor were.

What is worth doing periodically

Changing passwords by the calendar does not help. Reviewing the state of your accounts does. Once a year, in half an hour:

  1. Open your password manager’s security report and look at reused and breached keys. Fix those.
  2. Check where two-factor authentication is enabled and add it where it is missing, starting with email.
  3. Verify your recovery codes: that they exist, that they are off your phone, and that you know where they are.
  4. Look at open sessions and authorised apps on your email and social accounts. Close anything you do not recognise.
  5. Delete accounts you no longer use. A forgotten account on a service that goes under is a breach waiting to happen.

That protects far more than twelve password changes a year.

If your employer still requires it

Many corporate policies still demand quarterly changes, sometimes because a certification asks for it. Arguing rarely pays, so the sensible strategy is to comply well:

  • Do not increment the previous one. Generate a fresh random key.
  • Store it in the manager and do not try to memorise it.
  • If the system will not let you paste from the manager — it happens — use a phrase of random words, which types cleanly.

And if you have a say in that policy, the argument that tends to work is that the reference guidance no longer recommends it. The conversation stops being an opinion and becomes an overdue update.

In short

  • Calendar-based password changes have been discouraged since 2017 by the very bodies that popularised them.
  • You change when there is a reason: breach, suspicion, reuse or weakness.
  • What actually protects you is uniqueness, length and two-factor authentication.
  • An annual account review pays off more than twelve routine changes.

Frequently asked

The questions that keep coming up

Do you have to change your password every three months?

No. Neither the American standards institute NIST nor the British National Cyber Security Centre recommends it any more. Calendar-driven changes push people towards predictable, weaker passwords.

When should you change a password, then?

When there is a reason: a known breach, a suspicion that someone knows it, having typed it on a shared or borrowed device, or having fallen for a phishing attempt.

My employer forces a change every 90 days. What do I do?

Comply, because it is the policy in force, and do it properly: generate a new random password with a manager rather than adding a number to the end of the old one.

What about the password manager's master key?

Only if you suspect it has been compromised or it is weak. If it is a long random phrase that exists only in your head, changing it on a schedule adds nothing and raises the risk of forgetting it.

Keep reading