Toolslay
Security

How Long Should a Password Be? A Simple Rule

How long should a password be? A simple length guide by account type, the maths behind it, crack times and what NIST says today.

October 8, 2026 6 min readUpdated October 11, 2026
How Long Should a Password Be? A Simple Rule
In this articleTap to open

Ask ten people how long a password should be and you will get ten answers. Websites make it worse by accepting eight characters and calling that "strong". Security guides say 12, then 14, then 16, and never really explain why the number keeps going up.

Here is a plain explanation, a rule you can actually follow, and the maths behind it, so you can decide for yourself instead of trusting a number from a pop-up.

A length guide by account type

Not every account needs the same effort. Spend the most on the ones that unlock other accounts, because a thief who owns your email can reset almost everything else.

Account typeSuggested minimumWhy
Email, banking, work, cloud storage16+ charactersThese unlock your other accounts
Social media, shopping, subscriptions12+ charactersReal damage, but limited reach
Password manager master password6+ random wordsYou must remember this one yourself
Throwaway sign-ups and forums12+ charactersUnique, so a leak cannot spread

Why longer wins

Each character you add multiplies the number of possible passwords. If the characters are chosen at random from the 94 printable keyboard symbols, one extra character makes the search 94 times bigger. That is about 6.55 bits of strength per character, and bits are the unit security people use: every extra bit doubles the guesses needed.

52 bits8 random characters
79 bits12 random characters
105 bits16 random characters
131 bits20 random characters

Here is what that looks like in time. The table assumes an attacker who has stolen a site's password database and can try 10 billion guesses per second against a fast hash. Real sites often use slower hashes, which helps, but you cannot tell which kind a site uses, so plan for the worse case. Times are the average, when half the possibilities have been tried.

Random charactersBitsAverage time to crack
852about 3.5 days
1065about 85 years
1279about 750,000 years
1492billions of years
16105far longer than the age of the universe

Notice how steep it is. Going from 8 to 10 characters turns days into decades. Going from 10 to 12 turns decades into hundreds of thousands of years. After that you are well past anything an attacker will attempt, which is why 12 random characters is a sensible floor and 16 gives a big safety margin.

Why people's passwords are weaker than the maths

The table is for random passwords. Humans are not random. We start with a word, capitalize the first letter, add a year, and end with an exclamation mark. Attackers know every one of those habits and try them first, which is why a password that looks like Summer2024! falls in seconds even though it is 11 characters long.

That is also why a long password made of real words can still be weak. "Welcome to my house" feels long, but a guessing tool that tries common phrases will get there quickly. Length protects you only when the characters, or the words, are picked by chance.

Two other things matter as much as length:

  • Uniqueness. When a site is hacked, attackers try the leaked password on your email, your bank and your shops. A unique password means one leak stays one leak.
  • Where you type it. The strongest password in the world does nothing if you type it into a fake login page. Two-factor authentication covers that gap.

What official guidance says

The US standards body NIST publishes the guidelines many companies follow. Its current digital identity guidance, NIST SP 800-63B, sets a minimum of 15 characters when a password is the only way to sign in, and 8 characters only when it is paired with a second factor such as an authenticator app. It says sites should accept at least 64 characters, should not force rules like "one capital and one symbol", and should not make you change your password on a schedule.

In short, the people who write the standards agree with the maths: longer is better, and clever composition rules are not.

How to put this into practice

  1. Generate it, do not invent it. Random characters beat clever ideas every time.
  2. Make it 16 characters or more for important accounts. For everything else, 12 is the lowest sensible number.
  3. Use a unique password per site. One breach should never open a second door.
  4. Store it in a password manager. Then length costs you nothing, because you never type it.
  5. Add two-factor authentication. Do it first for email, banking and your password manager.

If a site limits you to a short length, pick the maximum it allows and make every character random. And if you need something you can remember, such as the master password for your manager, a passphrase of six random words is easier than a long jumble. The next post covers how to choose between the two.

Password vs Passphrase: Which Is Safer?

Read next · Security

Password vs Passphrase: Which Is Safer?

Password or passphrase? See real strength numbers and crack times, learn when each one wins, and pick the right secret for each account.

Read article

Make one and check one

Generate a random password at the length you need, then test any password you already use. The checker shows an estimate of how long it would take to crack and flags weak patterns such as common words, sequences and years. Both run in your browser, and nothing you type is sent to a server.

Free tool

Secure Password Generator

Generate strong, random passwords and check their strength with an entropy meter.

Try it now

Free tool

Password Strength Checker

Check how strong a password is and roughly how long it would take to crack.

Try it now

Common questions

How long should a password be in 2026?

For accounts that matter, use at least 16 random characters. For everyday accounts, 12 random characters is a sensible floor. NIST's guidance sets 15 characters as the minimum when a password is the only protection, and 8 when a second factor is also used.

Is a 12-character password good enough?

If the 12 characters are random, yes for most accounts. It would take an attacker hundreds of thousands of years on average, even against a fast hash. If the 12 characters follow a pattern such as a word plus a year, it is not safe at all. Use 16 or more for email, banking and work.

Does a longer password always mean a safer password?

No. Length only helps if the characters are random. A long password made from a song lyric, a name and a date can be guessed quickly. Pick a random one from a generator, make it unique, and keep it in a password manager.

Should I use a passphrase instead of a long password?

For anything you must remember and type, yes. Six random words are easier to type than 12 random characters and have similar strength. For everything a password manager can store, a long random password is simpler and fits sites that limit passphrases.

What if a website only allows a short password?

Use the maximum length it allows, make every character random, and make sure the password is unique to that site. Turn on two-factor authentication if the site offers it, and consider whether you really need an account there.

Try it now

Secure Password Generator

Generate strong, random passwords and check their strength with an entropy meter.

Generators & Random ToolsFreeNo sign-up
Try it now

Keep reading

View all