Strong password rules are technically enforced, not just recommended.
What it actually means
Password length/complexity requirements have to be enforced by the system (your identity provider), not left to good intentions. Align to current NIST guidance — length matters more than arbitrary symbol rules.
Pass or fail — an assessor needs a "yes" to each
- Minimum complexity/length is technically enforced.
- A change of characters is required when new passwords are set.
What to have ready
- Password policy configuration in the identity provider
- Documented standard aligned to NIST guidance
Where teams trip up
- A written policy with no technical enforcement
- Conflicting rules across systems
See where this control puts your score
Run all 110 requirements free in about 10 minutes — or draft your SSP language for this control. No signup.
Calculate your SPRS score →Draft your SSP language →Connected requirements
More in Identification & Authentication (3.5)
3.5.1 — Uniquely identify users, processes, and devices3.5.2 — Authenticate before access3.5.3 — Multifactor authentication (MFA)3.5.4 — Replay-resistant authentication3.5.5 — Don't recycle identifiers3.5.6 — Disable dormant accounts3.5.8 — Block password reuse3.5.9 — Force change of temporary passwords3.5.10 — Protect stored and transmitted passwords3.5.11 — Obscure authentication feedback