Skip to content

What is password rotation?

Password rotation means changing passwords at fixed intervals, typically every 60 or 90 days. Modern guidance has reversed on this: NIST SP 800-63B now recommends against arbitrary expiry, because forced changes push people toward predictable patterns like Spring2026 followed by Summer2026.

Topic
Passwords
Also called
password expiry, forced password change
Reading time
1 min
Reviewed
On this page

Why scheduled expiry backfires

A person forced to invent a new password every quarter does not generate a new random one. They increment. The observable result across large organisations is a population of passwords following visible patterns, which is far easier to attack than a stable set of strong unique ones.

When you should rotate

On evidence, not on a calendar. Change a password immediately if it appeared in a breach, if you reused it somewhere that was breached, if you shared it and the sharing has ended, or if you suspect any compromise of the device you typed it on.

What people often get wrong

"Changing my passwords every 90 days makes me safer."

It usually makes you less safe. NIST reversed this guidance because forced rotation produces predictable sequences. Rotate in response to evidence of exposure instead.

Sources

These primary references support the terminology and current security guidance used in this definition.

Make one account easier today.

Start with the password you keep reusing or the bank card that still shares a PIN. MoolKey is free, and you do not need to move everything at once.

Free forever Works offline Phone or computer