HomeControl Library › 3.5.7
3.5 Identification & Authentication1 ptPOA&M-eligible

3.5.7 — Enforce password complexity

Enforce a minimum password complexity and change of characters when new passwords are created.

Strong password rules are technically enforced, not just recommended.

What it actually means

Password length/complexity requirements have to be enforced by the system (your identity provider), not left to good intentions. Align to current NIST guidance — length matters more than arbitrary symbol rules.

Pass or fail — an assessor needs a "yes" to each

What to have ready

Where teams trip up

See where this control puts your score

Run all 110 requirements free in about 10 minutes.

Calculate your SPRS score →

Connected requirements

← Back to the Control Library