password-securityINFO

How Often Should You Change Your Password? (2026 Guidance)

The old advice to change your password every 90 days is now discouraged by security experts. When you actually should change a password, why forced rotation backfires, and what to do instead - strong unique passwords, a manager and 2FA.

By Eric Gerard · Editor · PwdFortress4 min readPhoto via Pixabay

If your IT department or an old habit tells you to change every password every 90 days, the modern answer may surprise you: for most accounts, don't. Security guidance has shifted. This guide explains how often you should really change a password, why forced rotation was dropped, and what to do instead.

The short answer

Do not change a strong, unique password on a fixed schedule. Change it only when there is a real reason. That is the current consensus from security bodies including NIST, which dropped routine-rotation advice back in 2017. A strong password you keep, protected by two-factor authentication, beats a stream of weaker ones you are forced to reinvent.

Why "change it every 90 days" backfires

The old rule sounded prudent, but it made things worse in practice. When people are forced to change passwords often, they don't invent strong new ones. They make small, predictable tweaks - Spring2026! becomes Summer2026! - and they reuse patterns across accounts. The result is weaker, more guessable passwords and more reuse, which is exactly what attackers count on.

An hourglass with sand running through it, against a blue background
An hourglass with sand running through it, against a blue background

When you actually should change a password

Rotation should be triggered by events, not the calendar. Change a password right away if:

  • The service announces a data breach or you find your account in one.
  • The password is weak, reused, or shared with anyone.
  • You notice unfamiliar logins or activity on the account.
  • You typed it on a phishing site or an untrusted device.
  • You ever sent it to someone, even yourself, over chat or email.

In any of those cases, change it immediately and turn on two-factor authentication.

Generate a unique password for every account - BitwardenOpen-source, audited password manager that creates and remembers strong, unique passwords so you never reuse or rotate by hand

What to do instead

Routine changing is the wrong habit. These three are the right ones:

  1. Use a unique password for every account. A password manager generates and stores long, random passwords so you never reuse or forget one.
  2. Turn on two-factor authentication. It blocks a stolen password on its own, which matters far more than how often you rotate.
  3. Monitor for breaches. Then you know exactly when a specific password genuinely needs changing - instead of guessing on a schedule.

What makes a password strong enough to keep

The whole "no routine rotation" advice rests on one condition: the password has to be strong and unique to begin with. A weak password that you keep forever is not the goal. What counts as strong?

  • Length over complexity. NIST's own guidance (SP 800-63B) treats length as the main driver of strength and tells services to allow long passwords - at least 64 characters - rather than forcing odd symbol rules. A 16-character random string or a memorable passphrase of five or more random words is far harder to crack than a short password padded with ! and a number.
  • Unique to one account. Reuse is what turns a single breach into many. If a password appears on only one site, a leak there can't unlock anything else you own.
  • Never derived from a pattern. Company2026, your pet's name, or a keyboard walk (qwerty123) are guessable. A generated random password has no pattern to attack.

Get those three right and the password genuinely does not need a calendar reminder. For a full walkthrough, see how to create a strong password.

What if my employer forces a 90-day change?

Many workplaces still enforce periodic rotation, often because an old compliance checklist demands it - even though NIST, Microsoft and the UK's NCSC now advise against routine expiry. You usually can't override company policy, but you can keep it from making your security worse:

  • Use your password manager to generate a brand-new random password each time instead of tweaking the old one. That defeats the predictable Spring → Summer pattern that makes forced rotation dangerous.
  • Never reuse a retired work password on a personal account.
  • If you influence policy, the documented modern position is to drop scheduled expiry and instead rotate on evidence of compromise, paired with multi-factor authentication and breach monitoring.

The point isn't to fight your IT team - it's to make sure that if you must rotate, each new password is still strong and unique rather than a recycled guess. And keep checking whether your passwords have leaked so a real trigger never goes unnoticed.

The bottom line

The honest, current answer to "how often should I change my password" is: not on a schedule - only when something happens. Forced rotation was well-meaning but it pushed people toward weaker, repeated passwords. Swap that habit for strong unique passwords, a manager to hold them, and two-factor authentication. That is what actually keeps accounts safe in 2026.

Frequently asked questions

How often should you change your password?

For most accounts, you should not change a strong, unique password on a fixed schedule. Modern guidance from bodies like NIST says to change a password only when there is a reason - a known breach, a shared or weak password, or signs someone has access. A strong, unique password protected by two-factor authentication does not need routine rotation. Changing it every 30 or 90 days for no reason tends to make security worse, not better.

Why is changing your password regularly no longer recommended?

Because forced rotation backfires in practice. When people are made to change passwords often, they pick weaker ones, follow predictable patterns (Spring2026, then Summer2026), and reuse variations across sites. NIST dropped its routine-rotation advice in 2017 for exactly this reason. A single strong, unique password you keep is safer than a stream of weak ones you are forced to invent every few weeks.

When should you actually change a password?

Change a password immediately if: the service announces a data breach; you discover the password is weak, reused, or shared; you see unfamiliar logins or activity; you entered it on a phishing site or an untrusted device; or you ever sent it to someone. In those cases, change it at once and turn on two-factor authentication. Outside of a real trigger like these, a strong unique password does not need a routine change.

What should I do instead of changing passwords often?

Three things. Use a long, unique password for every account - a password manager generates and remembers them so you never reuse one. Turn on two-factor authentication, which blocks a stolen password on its own. And monitor for breaches, so you know exactly when a specific password actually needs changing. That combination protects you far better than rotating passwords on a calendar.