In this articleTap to open
Ask ten people how long a password should be and you will get ten answers. Websites make it worse by accepting eight characters and calling that "strong". Security guides say 12, then 14, then 16, and never really explain why the number keeps going up.
Here is a plain explanation, a rule you can actually follow, and the maths behind it, so you can decide for yourself instead of trusting a number from a pop-up.
A length guide by account type
Not every account needs the same effort. Spend the most on the ones that unlock other accounts, because a thief who owns your email can reset almost everything else.
| Account type | Suggested minimum | Why |
|---|---|---|
| Email, banking, work, cloud storage | 16+ characters | These unlock your other accounts |
| Social media, shopping, subscriptions | 12+ characters | Real damage, but limited reach |
| Password manager master password | 6+ random words | You must remember this one yourself |
| Throwaway sign-ups and forums | 12+ characters | Unique, so a leak cannot spread |
Why longer wins
Each character you add multiplies the number of possible passwords. If the characters are chosen at random from the 94 printable keyboard symbols, one extra character makes the search 94 times bigger. That is about 6.55 bits of strength per character, and bits are the unit security people use: every extra bit doubles the guesses needed.
Here is what that looks like in time. The table assumes an attacker who has stolen a site's password database and can try 10 billion guesses per second against a fast hash. Real sites often use slower hashes, which helps, but you cannot tell which kind a site uses, so plan for the worse case. Times are the average, when half the possibilities have been tried.
| Random characters | Bits | Average time to crack |
|---|---|---|
| 8 | 52 | about 3.5 days |
| 10 | 65 | about 85 years |
| 12 | 79 | about 750,000 years |
| 14 | 92 | billions of years |
| 16 | 105 | far longer than the age of the universe |
Notice how steep it is. Going from 8 to 10 characters turns days into decades. Going from 10 to 12 turns decades into hundreds of thousands of years. After that you are well past anything an attacker will attempt, which is why 12 random characters is a sensible floor and 16 gives a big safety margin.
Why people's passwords are weaker than the maths
The table is for random passwords. Humans are not random. We start with a word, capitalize the first letter, add a year, and end with an exclamation mark. Attackers know every one of those habits and try them first, which is why a password that looks like Summer2024! falls in seconds even though it is 11 characters long.
That is also why a long password made of real words can still be weak. "Welcome to my house" feels long, but a guessing tool that tries common phrases will get there quickly. Length protects you only when the characters, or the words, are picked by chance.
Two other things matter as much as length:
- Uniqueness. When a site is hacked, attackers try the leaked password on your email, your bank and your shops. A unique password means one leak stays one leak.
- Where you type it. The strongest password in the world does nothing if you type it into a fake login page. Two-factor authentication covers that gap.
What official guidance says
The US standards body NIST publishes the guidelines many companies follow. Its current digital identity guidance, NIST SP 800-63B, sets a minimum of 15 characters when a password is the only way to sign in, and 8 characters only when it is paired with a second factor such as an authenticator app. It says sites should accept at least 64 characters, should not force rules like "one capital and one symbol", and should not make you change your password on a schedule.
In short, the people who write the standards agree with the maths: longer is better, and clever composition rules are not.
How to put this into practice
- Generate it, do not invent it. Random characters beat clever ideas every time.
- Make it 16 characters or more for important accounts. For everything else, 12 is the lowest sensible number.
- Use a unique password per site. One breach should never open a second door.
- Store it in a password manager. Then length costs you nothing, because you never type it.
- Add two-factor authentication. Do it first for email, banking and your password manager.
If a site limits you to a short length, pick the maximum it allows and make every character random. And if you need something you can remember, such as the master password for your manager, a passphrase of six random words is easier than a long jumble. The next post covers how to choose between the two.

Read next · Security
Password vs Passphrase: Which Is Safer?
Password or passphrase? See real strength numbers and crack times, learn when each one wins, and pick the right secret for each account.
Read articleMake one and check one
Generate a random password at the length you need, then test any password you already use. The checker shows an estimate of how long it would take to crack and flags weak patterns such as common words, sequences and years. Both run in your browser, and nothing you type is sent to a server.
Free tool
Secure Password Generator
Generate strong, random passwords and check their strength with an entropy meter.
Free tool
Password Strength Checker
Check how strong a password is and roughly how long it would take to crack.
Common questions
How long should a password be in 2026?
For accounts that matter, use at least 16 random characters. For everyday accounts, 12 random characters is a sensible floor. NIST's guidance sets 15 characters as the minimum when a password is the only protection, and 8 when a second factor is also used.
Is a 12-character password good enough?
If the 12 characters are random, yes for most accounts. It would take an attacker hundreds of thousands of years on average, even against a fast hash. If the 12 characters follow a pattern such as a word plus a year, it is not safe at all. Use 16 or more for email, banking and work.
Does a longer password always mean a safer password?
No. Length only helps if the characters are random. A long password made from a song lyric, a name and a date can be guessed quickly. Pick a random one from a generator, make it unique, and keep it in a password manager.
Should I use a passphrase instead of a long password?
For anything you must remember and type, yes. Six random words are easier to type than 12 random characters and have similar strength. For everything a password manager can store, a long random password is simpler and fits sites that limit passphrases.
What if a website only allows a short password?
Use the maximum length it allows, make every character random, and make sure the password is unique to that site. Turn on two-factor authentication if the site offers it, and consider whether you really need an account there.
Try it now
Secure Password Generator
Generate strong, random passwords and check their strength with an entropy meter.

