Home / Password & Passphrase Tools / NIST Password Policy Checker
Password & Passphrase Tools

NIST Password Policy Checker

Check length, composition, rotation, blocklist, password-manager, paste, Unicode, and full-verification settings against NIST Rev. 4 guidance; this is a policy aid, not certification.

—Based on NIST SP 800-63B Revision 4 password-verifier guidance. This tool is not a compliance certification.

Sensitive values stay in this browser page. Theoretical entropy/search-space math assumes uniform random generation and is not a crack-time promise for human-chosen passwords. Use a reputable password manager for real account storage.

Modern password guidance without false certainty

keeps password/passphrase generation and review browser-local while shifting guidance toward length, uniqueness, common-password blocking, password-manager compatibility, MFA, and compromise-driven changes rather than arbitrary composition rules or guaranteed crack-time claims.

Security boundary

A local meter can flag obvious patterns but cannot prove that a password is safe, unused elsewhere, or absent from every breach corpus. Do not paste sensitive production password exports into batch tools; generate unique secrets locally and store them in an appropriate password manager.

Search by task, tool name, or category. Press Esc to close.
Start typing to find a tool.