Contact salesSign inSign up
AuthsignalAuthsignal
Product
Passwordless / multi-factor authentication (MFA)
Drop-in authentication
Risk-based authentication
Passkeys
Biometric authentication
WhatsApp OTP
Authenticator apps (TOTP)
Push authentication
SMS OTP
Email OTP
Magic links
See all authenticators
See less authenticators
Palm biometrics
Contactless payments & identity verification
Flexible integration modes
Pre-built UI
Low code
UI components
Customizable
Custom UI
Flexible
Digital credentials API Beta
Authenticate customers instantly using digital credentials
Session management
Keep users signed in across web and mobile after authentication
Fraud Controls
Rules and policies engine
Step-up authentication
No-code rule creation
Risk alerts
User observability
Audit trails
Dynamic linking
Why Authsignal?
Complete authentication infrastructure from enrollment to step-up auth, modular by design
Solutions
By USE CASE
View All
Account takeovers (ATO)
Go passwordless
Call center
SMS cost optimization
Existing apps
QR code payments
Step-up MFA
Palm biometrics payments
By INDUSTRY
View All
Financial services
Marketplace
e-Commerce
FinTech
Crypto
Healthcare
By Integration (identity provider)
Amazon Cognito
Azure AD B2C
Duende IdentityServer
Keycloak
Auth0
NextAuth.js
Custom identity provider
By ROLe
Engineers
Product
Passwordless / Multi-factor Authentication (MFA)
Flexible Integration Modes
Pre-built UI · Low code
UI Components · Customizable
Custom UI · Flexible
Digital credentials API Beta
Authenticate customers instantly using digital credentials
Session management
Issue JWT access and refresh tokens
Why Authsignal?
Plug in Authsignal to elevate your IDP — effortless integration with any architecture.
Drop-in Authentication
Risk-based authentication
Passkeys
Biometric authentication
WhatsApp OTP
SMS OTP
Email OTP
Magic links
Authenticator apps (TOTP)
Push notifications
Palm Biometrics
Contactless payments & identity verification
Fraud Controls
Rules and Policies Engine
Step-up Authentication
No Code Rule Creation
Risk Alerts
User Observability
Audit Trails
Use Cases
Financial services
Account takeovers (ATO)
Marketplace
Go passwordless
e-Commerce
Solutions
By Use Case
Account takeovers (ATO)
Go passwordless
Call center
SMS cost optimization
Existing apps
QR code payments
Step-up MFA
Palm Biometric Payments
View all Use Cases
By Industry
Financial services
Marketplace
e-Commerce
FinTech
Crypto
Healthcare
View all Industries
By Integration (identity provider)
Amazon Cognito
Azure AD B2C
Duende IdentityServer
Keycloak
Auth0
NextAuth.js
Custom identity provider
By Role
Engineers
PricingAboutDocsBlog
Schedule a call
Try Authsignal
AUS Flag

Authsignal secures millions of passkey transactions out of our hosted Sydney region.

AUS Flag

Authsignal secures millions of passkey transactions out of our hosted Sydney region.

Join us today!
Right icon
Blog
/
Current article
NIST

NIST's September 2024 Update to Password Guidelines: Improved User Experience.

Ben Rolfe
⬤
May 14, 2025
Share
NIST's September 2024 Update to Password Guidelines: Improved User Experience.

In September 2024, the National Institute of Standards and Technology (NIST) released updated guidance on password practices as part of the second public draft of its Digital Identity Guidelines (SP 800-63-4). Rather than focusing on complexity, the new guidelines emphasize usability, password length, and Password Blocklists, aiming to balance improved security and user-friendly practices. Below, we explore the core elements of NIST's updates.

These updates provide a modest enhancement in password security, but they only address a small part of the broader challenges with passwords. As organizations adapt to these changes, they should explore implementing modern multi-factor authentication (MFA) and passkeys.

‍

Key Changes in NIST's Updated Password Guidelines.

Focus on Password Length Over Complexity.

‍ Historically, security policies demanded passwords that mixed uppercase and lowercase letters, numbers, and special characters. However, NIST's updated guidance refocuses on password length as the most critical factor.

‍"Humans have a limited ability to memorize complex, arbitrary secrets, so they often choose passwords that can be easily guessed." - NIST SP 800-63B.

Studies show that longer passwords are much harder to crack and, more importantly, easier for users to remember. For example, a passphrase like "SeedsInTheBreezeFlowersByTrees" provides greater security than a short, complex password like "P@ssw0rd!".

‍"Password length is a primary factor in characterizing password strength. Passwords that are too short yield to brute-force attacks and dictionary attacks." - NIST SP 800-63B.

The 2024 NIST update requires Verifiers and CSPs to allow passwords of up to 64 characters and a minimum length of 15 characters, with support for ASCII and Unicode characters.‍

Remove Mandatory Password Resets.

Gone are the days of requiring password changes every 60 or 90 days. NIST's research shows that frequent password resets lead to weaker passwords as users tend to make minor alterations to existing passwords or resort to writing them down. The 2024 update recommends only requiring password resets after a confirmed credential breach, thereby minimizing user fatigue and reducing the likelihood of insecure password practices.‍

Implement Password Blocklists.

Another significant change is the introduction of password blocklists. This practice ensures that users cannot choose weak or commonly used passwords, especially those that have been compromised in previous data breaches.

‍

Though these updates provide a small enhancement for password security and user experience, they are only a small fix for the ongoing issue with passwords. Integrating Authsignal into your identity stack has made deploying modern and adaptive multi-factor authentication (MFA) and passkeys easier and faster. Thousands of organizations, including Google, Apple, Microsoft, and PayPal, now rely on passkeys for a more seamless and secure user experience.

For a deeper dive into NIST's guidance on syncable passkeys, check out Authsignal's two-part blog series:

  • Part 1: NIST Supplementary Guidelines for Passkeys - April 2024
  • Part 2: NIST Supplementary Guidelines for Passkeys - Implementation Considerations

For the fastest way to implement adaptive MFA and passkeys to secure your entire authentication workflow (chain), learn more about integrating Authsignal with Auth0, AWS Cognito, Azure AD B2C, Duende IdentityServer, and more.

Question icon
Have a question?
Talk to an expert
NewsletterDemo PasskeysView docs
NIST

You might also like

Authsignal joins IATA Strategic Partnership Program to advance digital identity adoption in travel and aviation
Partnerships
Airlines

Authsignal joins IATA Strategic Partnership Program to advance digital identity adoption in travel and aviation

April 10, 2026
How to add push authentication to your app with Authsignal and React Native
Push authentication
React native
Node.js
Multi-factor authentication
Guides

How to add push authentication to your app with Authsignal and React Native

March 27, 2026
BSP Circular 1213: Philippine banks must replace SMS OTPs by June 2026
BSP Circular 1213
Philippine banking
SMS OTP
Risk based authentication

BSP Circular 1213: Philippine banks must replace SMS OTPs by June 2026

March 18, 2026

Secure your customers’ accounts today with Authsignal

Passkey demoCreate free account

Authsignal delivers passwordless and multi-factor authentication as a service. Focused on powering mid-market and enterprise businesses to rapidly deploy optimized good customer flows that enable a flexible and risk-based approach to authentication.

AICPA SOCFido Certified
LinkedInTwitter
Passwordless / multi-factor authentication (MFA)
Pre-built UI (low code)UI components (customizable)Custom UI (flexible)
Why Authsignal?
Drop-in authentication
Risk-based authentication PasskeysBiometric authenticationWhatsApp OTPSMS OTPEmail OTPMagic linksAuthenticator apps (TOTP)Push authenticationPalm biometricsDigital Credential Verification API
Rules and policies engine
User observability
Industries
Financial services
Marketplace
e-Commerce
FinTech
Crypto
View all industries
Teams
Engineers
Use cases
Account takeovers (ATO)
Go passwordless
Call center
SMS cost optimization
Existing apps
View all use cases
Identity providers (IDPs)
Amazon Cognito
Auth0
Azure AD B2C
Custom identity provider
Duende IdentityServer
Keycloak
NextAuth.js
Integrations
ASP.NET
C#
Java
Node.js
Open ID Connect (OIDC)
PHP
Python
React
Ruby
Ruby on Rails
Compare
Twilio Verify vs AuthsignalAuth0 vs AuthsignalAWS Cognito vs Authsignal + AWS Cognito
Resources
BlogDeveloper docsFree Figma mobile passkeys templateFree Figma desktop passkeys templateFree Figma webapp passkeys template
Company
About usWhy AuthsignalCareersPress releasesPartnersContact us
What is
SMS OTP
Risk Based Authentication
IP Spoofing
Passwordless authentication
Multi-Factor Authentication (MFA)
United States
+1 214 974-4877
Ireland
+353 12 676529
Australia
+61 387 715 810
New Zealand
+64 275 491 983
© 2026 Authsignal - All Rights Reserved
Terms of servicePrivacy policySecuritySystem statusCookies