If your IT department or an old habit tells you to change every password every 90 days, the modern answer may surprise you: for most accounts, don't. Security guidance has shifted. This guide explains how often you should really change a password, why forced rotation was dropped, and what to do instead.
The short answer
Do not change a strong, unique password on a fixed schedule. Change it only when there is a real reason. That is the current consensus from security bodies including NIST, which dropped routine-rotation advice back in 2017. A strong password you keep, protected by two-factor authentication, beats a stream of weaker ones you are forced to reinvent.
Why "change it every 90 days" backfires
The old rule sounded prudent, but it made things worse in practice. When people are forced to change passwords often, they don't invent strong new ones. They make small, predictable tweaks - Spring2026! becomes Summer2026! - and they reuse patterns across accounts. The result is weaker, more guessable passwords and more reuse, which is exactly what attackers count on.

When you actually should change a password
Rotation should be triggered by events, not the calendar. Change a password right away if:
- The service announces a data breach or you find your account in one.
- The password is weak, reused, or shared with anyone.
- You notice unfamiliar logins or activity on the account.
- You typed it on a phishing site or an untrusted device.
- You ever sent it to someone, even yourself, over chat or email.
In any of those cases, change it immediately and turn on two-factor authentication.
Generate a unique password for every account - BitwardenOpen-source, audited password manager that creates and remembers strong, unique passwords so you never reuse or rotate by hand→What to do instead
Routine changing is the wrong habit. These three are the right ones:
- Use a unique password for every account. A password manager generates and stores long, random passwords so you never reuse or forget one.
- Turn on two-factor authentication. It blocks a stolen password on its own, which matters far more than how often you rotate.
- Monitor for breaches. Then you know exactly when a specific password genuinely needs changing - instead of guessing on a schedule.
What makes a password strong enough to keep
The whole "no routine rotation" advice rests on one condition: the password has to be strong and unique to begin with. A weak password that you keep forever is not the goal. What counts as strong?
- Length over complexity. NIST's own guidance (SP 800-63B) treats length as the main driver of strength and tells services to allow long passwords - at least 64 characters - rather than forcing odd symbol rules. A 16-character random string or a memorable passphrase of five or more random words is far harder to crack than a short password padded with
!and a number. - Unique to one account. Reuse is what turns a single breach into many. If a password appears on only one site, a leak there can't unlock anything else you own.
- Never derived from a pattern.
Company2026, your pet's name, or a keyboard walk (qwerty123) are guessable. A generated random password has no pattern to attack.
Get those three right and the password genuinely does not need a calendar reminder. For a full walkthrough, see how to create a strong password.
What if my employer forces a 90-day change?
Many workplaces still enforce periodic rotation, often because an old compliance checklist demands it - even though NIST, Microsoft and the UK's NCSC now advise against routine expiry. You usually can't override company policy, but you can keep it from making your security worse:
- Use your password manager to generate a brand-new random password each time instead of tweaking the old one. That defeats the predictable
Spring → Summerpattern that makes forced rotation dangerous. - Never reuse a retired work password on a personal account.
- If you influence policy, the documented modern position is to drop scheduled expiry and instead rotate on evidence of compromise, paired with multi-factor authentication and breach monitoring.
The point isn't to fight your IT team - it's to make sure that if you must rotate, each new password is still strong and unique rather than a recycled guess. And keep checking whether your passwords have leaked so a real trigger never goes unnoticed.
The bottom line
The honest, current answer to "how often should I change my password" is: not on a schedule - only when something happens. Forced rotation was well-meaning but it pushed people toward weaker, repeated passwords. Swap that habit for strong unique passwords, a manager to hold them, and two-factor authentication. That is what actually keeps accounts safe in 2026.
★ Audit Cure53 2024 · ✓ Plan gratuit · Cross-platform
Lock down your accounts → NordPassStrong unique passwords · breach scanner · free tier→Frequently asked questions
How often should you change your password?
For most accounts, you should not change a strong, unique password on a fixed schedule. Modern guidance from bodies like NIST says to change a password only when there is a reason - a known breach, a shared or weak password, or signs someone has access. A strong, unique password protected by two-factor authentication does not need routine rotation. Changing it every 30 or 90 days for no reason tends to make security worse, not better.
Why is changing your password regularly no longer recommended?
Because forced rotation backfires in practice. When people are made to change passwords often, they pick weaker ones, follow predictable patterns (Spring2026, then Summer2026), and reuse variations across sites. NIST dropped its routine-rotation advice in 2017 for exactly this reason. A single strong, unique password you keep is safer than a stream of weak ones you are forced to invent every few weeks.
When should you actually change a password?
Change a password immediately if: the service announces a data breach; you discover the password is weak, reused, or shared; you see unfamiliar logins or activity; you entered it on a phishing site or an untrusted device; or you ever sent it to someone. In those cases, change it at once and turn on two-factor authentication. Outside of a real trigger like these, a strong unique password does not need a routine change.
What should I do instead of changing passwords often?
Three things. Use a long, unique password for every account - a password manager generates and remembers them so you never reuse one. Turn on two-factor authentication, which blocks a stolen password on its own. And monitor for breaches, so you know exactly when a specific password actually needs changing. That combination protects you far better than rotating passwords on a calendar.
