# NCSC guidance on passwords: what it recommends and where a password manager fills the gap

The National Cyber Security Centre (NCSC) guidance on passwords now centers on length, uniqueness, and tools that make good habits sustainable. Learn more today!

---

Password advice has shifted. The National Cyber Security Centre (NCSC) guidance on passwords now centers on length, uniqueness, and tools that make good habits sustainable. Forced complexity rules and routine password changes are no longer recommended; research shows they do more harm than good.

Understanding what guidance recommends, where it has limits, and how a password manager makes it practical is the foundation of a stronger credential strategy.

## What does the NCSC guidance on passwords say?

The NCSC recommends four core practices:

- Creating passwords from three random words, known as a passphrase
- Avoiding guessable personal details like names, birthdays, and favorite teams
- Steering clear of common weak passwords
- Using a password manager for accounts where memorization is not practical

NCSC guidance has also shifted to prioritize [<u>passkeys</u>](https://bitwarden.com/en-gb/products/personal/) where supported. Passkeys replace the password entirely with a cryptographic key pair, removing the risk of a stolen or reused credential. For most accounts today, passwords remain the default; the three-random-words approach and password managers still anchor the guidance.

| **Recommendation** | **How to Implement** | **Challenges** |
|------|------|------|
| Three random words | A small number of memorable logins, including a vault master passphrase | Hard to scale across dozens of accounts |
| Password manager-generated passwords | Every account where memorisation is not required | Requires a trusted tool and one strong master passphrase |
| Passkeys | Any account or service that supports them | Not yet universally available |

## Why does the NCSC recommend three random words?

A passphrase like *correct-horse-battery-staple* is longer, more memorable, and harder to crack than *P@ssw0rd1!*. That is the core logic behind the NCSC three-random-words approach: length is a stronger defense than complexity, and a passphrase someone can actually remember is more likely to remain unique across accounts.

Predictable substitutions, such as swapping "o" for "0," "a" for "@," or adding a "!" at the end, are well-known to attackers. Automated cracking tools account for these patterns. A short, symbol-laden password built on a formula offers far less protection than it appears to.

**Before:** Fluffy2012! Guessable from personal details, short, and pattern-based.

**After:** cobalt-ferry-window. Random, longer, and not tied to anything personal.

### **Why length beats forced complexity**

An 8-character password using letters, numbers, and symbols can be cracked in minutes with modern hardware. A 20-character passphrase made of three random words can take centuries to brute-force, even without special characters. Length multiplies the number of possible combinations far faster than complexity rules do.

> A 20-character passphrase made of three random words can take centuries to brute-force. An 8-character password with symbols can be cracked in minutes.

### **Why the NCSC moved away from forced rotation**

For years, organizations required staff to change passwords every 90 days and to meet complexity requirements that included uppercase letters, numbers, and symbols. The NCSC now advises against both practices. Forced rotation leads to predictable changes; Password1 becomes Password2. Complexity rules produce patterns that attackers have already mapped. The NCSC recommends longer memorable phrases paired with password managers instead.

### **What makes a passphrase random enough to work**

Length alone is not enough. The words themselves need to be genuinely unpredictable. A phrase like *SunnyLondonMarathon* is built from experiences that appear in social profiles, making it predictable even if it feels obscure. A genuinely random passphrase pulls words from an unrelated set: *cobalt ferry window* or *lantern soup bridge*. A password manager generates these automatically.

## How password managers support NCSC guidance

Three random words solve the memorability problem. They do not solve the scale problem. A [<u>password manager</u>](https://bitwarden.com/en-gb/products/personal/) does both.

Three random words solve the memorability problem. They do not solve the scale problem. A password manager does both; it generates strong, unique passwords for every account, stores them securely, and fills them in automatically. The only credential that needs to be memorized is one master passphrase.

The practical difference is significant. Instead of cycling through variations of the same phrase across dozens of accounts, every login gets a credential that is genuinely unique and impossible to guess.

The NCSC recommends password managers precisely because unique passwords at scale require a tool, not willpower. Bitwarden builds on this with an [<u>open source architecture</u>](https://bitwarden.com/en-gb/open-source/) that independent security researchers and auditors can verify directly. Cross-device access means that passwords are available on every device a user uses. Shared vault support lets small teams manage credentials without resorting to spreadsheets or shared documents.

## Where three random words stop being practical

> Three random words work well for a small number of important logins. The challenge is uniqueness. NCSC guidance is explicit: passwords should not be reused across accounts. Human memory is not built to scale.

A person managing five core logins (email, banking, a streaming service, a work account, and a government portal) can reasonably memorize five distinct passphrases. Add another ten accounts, and the system starts to fail. Phrases blur together, people fall back on variations of the same base phrase, and uniqueness disappears.

For small business teams, the problem scales faster. Password advice for small businesses needs to account for reality: a team of five regularly managing email platforms, finance tools, admin dashboards, and cloud storage is handling 30 or more credentials. Expecting staff to memorize a unique passphrase for each one is not realistic. When that system fails, people reuse passwords. That is where credential management tools become essential.

## When to memorize a passphrase and when to generate one

One rule covers it: memorize the vault master passphrase, generate everything else. Every other account gets a unique credential that users never need to think about again.

The master passphrase is the one credential that protects everything else. Unlike other logins, it's never stored in the vault; it lives only in the user's memory, which means it should be strong, unique, and built from genuinely random words rather than personal details.

Pairing it with [multifactor authentication (MFA)](https://bitwarden.com/en-gb/resources/mfa-for-shared-accounts/) raises the bar considerably. Even if the master passphrase were somehow exposed, MFA requires a second verification step that an attacker cannot easily replicate. Bitwarden supports multiple two-factor authentication (2FA) methods.

### **What to look for in a password manager**

When evaluating options, these features matter most:

- [Independent security audits](https://bitwarden.com/en-gb/open-source/) with published results
- Open source code that can be reviewed externally
- Cross-device sync so credentials are accessible everywhere
- [Shared vault support](https://bitwarden.com/en-gb/products/families/) for families and small teams
- Passkey storage and autofill for accounts that support them

Bitwarden meets all of these criteria.

## Multifactor authentication and passkeys: the next layer

Strong, unique passwords are the foundation. A password alone, however strong, is not the whole picture. Multifactor authentication and passkeys are what make that foundation significantly harder to undermine.

A strong, unique password can still be compromised through a phishing attempt, a service provider data breach, or malware on a device. MFA blocks most automated attacks even when the password is known, because it requires a second factor that the attacker does not have. NCSC guidance recommends enabling MFA wherever it is available.

NCSC guidance now identifies passkeys as the preferred option where services support them. Rather than a password that a user creates and must protect, a passkey is a cryptographic credential generated by the device; it cannot be phished or reused. Most accounts do not yet support passkeys. For those, passwords paired with MFA remain the recommended approach.

## Put the NCSC guidance into practice

The NCSC guidance on passwords is clear: longer passphrases, unique credentials for every account, a password manager to make that practical, and multifactor authentication wherever it is available. Following it consistently is harder without the right tool.

[<u>Bitwarden Password Manager</u>](https://bitwarden.com/en-gb/products/personal/) handles generation, storage, and autofill across every account, so good credential habits do not depend on memory or willpower. Setup takes minutes. The open source architecture means security can be independently verified rather than taken on trust, and cross-device sync means the vault is available wherever users work.

Bitwarden is free to get started for individuals and families. [<u>Business and Enterprise plans</u>](https://bitwarden.com/en-gb/pricing/business/) are available for teams that need shared vaults, admin controls, and audit trails.

## Get powerful, trusted password security now. Pick your plan.

## Personal

### Just getting started?

*Get basic password management today. Always free.*

[Create Free Account](https://bitwarden.com/go/start-free/)

---

### Premium

**$1.65** *per month*

*Billed annually at $19.80*

Enjoy premium features

- Integrated authenticator
- File attachments
- Emergency access
- Phishing blocker
- Security reports and more

Share vault items with one other user

[Create Premium Account](https://bitwarden.com/go/start-premium/)

---

### Families

**$3.99** *per month*

*Up to 6 users, billed annually at $47.88*

Secure your family logins

- 6 premium accounts
- Unlimited sharing
- Unlimited collections
- Organisation storage

Share vault items between six people

[Start Free Families Trial](https://bitwarden.com/go/start-families-trial/)

---

Pricing shown in USD and based on an annual subscription. Taxes not included.

## Business

### Teams

*For teams and growing companies that need to move quickly.*

**$4** *per month / per user, billed annually*

**No compromise**

All Premium features, plus advanced capabilities such as:

- Share credentials securely
- Audit activity with event logs
- Synchronise your existing directory
- Automate provisioning with SCIM

[Start Free Trial](https://bitwarden.com/go/start-teams-trial/)

---

### Enterprise

*For businesses that need advanced protection and control.*

**$6** *per month / per user, billed annually*

**Maximum protection**

All Premium and Teams features, plus enterprise-level capabilities such as:

- Granular access control
- Passwordless SSO integration
- Easy account recovery
- Flexibility to self-host
- Access Intelligence risk remediation [new]
- Free Families plan for all users

[Start Free Trial](https://bitwarden.com/go/start-enterprise-trial/)

---

### Talk to Sales

*For large organisations, talk to an expert about a tailored plan and learn how Bitwarden can:*

*per month*

- Reduce cyber security risk
- Boost productivity
- Integrate seamlessly

Bitwarden scales with businesses of any size to bring password security to your organisation

[Talk to Sales](https://bitwarden.com/talk-to-sales)

---

Pricing shown in USD and based on an annual subscription. Taxes not included.