Skip to content

Password Complexity

What is Password Complexity?

Requirements for password composition including minimum length, character variety, and prohibition of common or previously used passwords.

Information Security

Each of these is named in at least one of the same controls as password complexity. The number is how many controls name both.

What the standards actually require on password complexity

Requirements naming password complexity across 6 standards, quoted from the control text.

CMMC 2.01 control

Set a minimum complexity for passwords, and require that a newly created password differ in its characters from the one it replaces.

IA.L2-3.5.7 · Password Complexity
FedRAMP High1 control

Enforce password complexity per NIST SP 800-63B; minimum 12 characters (FedRAMP); compare against breach lists.

IA-5(1) · Password-Based Authentication

Enforce password complexity per NIST SP 800-63B; minimum 12 characters (FedRAMP); compare against breach lists.

IA-5(1) · Password-Based Authentication
IEEE 16861 control

Section 5.1 establishes electronic access account management capabilities required of IEDs. Per public IEEE 1686 + IEEE Std abstract + vendor capability statements (full IEEE text NOT reproduced): individual user accounts with unique identification (5.1) + no...

IEEE1686-Section5.1-AccessControl-Accounts-Roles-Password-Session-Remote · IEEE 1686 Section 5.1 - Electronic Access Account Management + Roles + Password + Failed Login + Session + Remote Access + Personnel

The Privacy Protection (Data Security) Regulations 5777-2017 (Takhanot Hagannat Hapratiyot - Avtahat Meidah) supplement the 1981 Law with detailed technical and organisational security requirements + graduated by Security Level Classification (Basic/Medium/Hig...

IsraelPPL-DataSecurity-Regulations2017-ISO-CISO-Access-Logging-Backup-Physical-Removable-Annual-Audit · Israel POPL Data Security Regulations 5777-2017 + ISO Information Security Officer + Access Control + Logging + Backup + Physical Security + Removable Media + Risk Assessment + Penetration Testing + Annual Internal Audit + Amendment 13 Cyber Updates

Questions people ask about password complexity

What is Password Complexity?
Requirements for password composition including minimum length, character variety, and prohibition of common or previously used passwords.
Why is Password Complexity important for compliance?
Password Complexity is a key concept in Information Security. Understanding password complexity helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Password Complexity?
Password Complexity appears in the requirement text of CMMC 2.0, FedRAMP High, FedRAMP Moderate, IEEE 1686, ISMAP (Japan). Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Password Complexity?
Explore our compliance framework pages to see how password complexity applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Password Complexity applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.