# NCSC guidance on passwords: what it recommends and where a password manager fills the gap

The National Cyber Security Centre (NCSC) guidance on passwords now centers on length, uniqueness, and tools that make good habits sustainable. Learn more today!

---

Password advice has shifted. The National Cyber Security Centre (NCSC) guidance on passwords now centers on length, uniqueness, and tools that make good habits sustainable. Forced complexity rules and routine password changes are no longer recommended; research shows they do more harm than good.

Understanding what guidance recommends, where it has limits, and how a password manager makes it practical is the foundation of a stronger credential strategy.

## What does the NCSC guidance on passwords say?

The NCSC recommends four core practices:

- Creating passwords from three random words, known as a passphrase
- Avoiding guessable personal details like names, birthdays, and favorite teams
- Steering clear of common weak passwords
- Using a password manager for accounts where memorization is not practical

NCSC guidance has also shifted to prioritize [<u>passkeys</u>](https://bitwarden.com/pt-br/products/personal/) where supported. Passkeys replace the password entirely with a cryptographic key pair, removing the risk of a stolen or reused credential. For most accounts today, passwords remain the default; the three-random-words approach and password managers still anchor the guidance.

| **Recommendation** | **How to Implement** | **Challenges** |
|------|------|------|
| Three random words | A small number of memorable logins, including a vault master passphrase | Hard to scale across dozens of accounts |
| Password manager-generated passwords | Every account where memorisation is not required | Requires a trusted tool and one strong master passphrase |
| Passkeys | Any account or service that supports them | Not yet universally available |

## Why does the NCSC recommend three random words?

A passphrase like *correct-horse-battery-staple* is longer, more memorable, and harder to crack than *P@ssw0rd1!*. That is the core logic behind the NCSC three-random-words approach: length is a stronger defense than complexity, and a passphrase someone can actually remember is more likely to remain unique across accounts.

Predictable substitutions, such as swapping "o" for "0," "a" for "@," or adding a "!" at the end, are well-known to attackers. Automated cracking tools account for these patterns. A short, symbol-laden password built on a formula offers far less protection than it appears to.

**Before:** Fluffy2012! Guessable from personal details, short, and pattern-based.

**After:** cobalt-ferry-window. Random, longer, and not tied to anything personal.

### **Why length beats forced complexity**

An 8-character password using letters, numbers, and symbols can be cracked in minutes with modern hardware. A 20-character passphrase made of three random words can take centuries to brute-force, even without special characters. Length multiplies the number of possible combinations far faster than complexity rules do.

> A 20-character passphrase made of three random words can take centuries to brute-force. An 8-character password with symbols can be cracked in minutes.

### **Why the NCSC moved away from forced rotation**

For years, organizations required staff to change passwords every 90 days and to meet complexity requirements that included uppercase letters, numbers, and symbols. The NCSC now advises against both practices. Forced rotation leads to predictable changes; Password1 becomes Password2. Complexity rules produce patterns that attackers have already mapped. The NCSC recommends longer memorable phrases paired with password managers instead.

### **What makes a passphrase random enough to work**

Length alone is not enough. The words themselves need to be genuinely unpredictable. A phrase like *SunnyLondonMarathon* is built from experiences that appear in social profiles, making it predictable even if it feels obscure. A genuinely random passphrase pulls words from an unrelated set: *cobalt ferry window* or *lantern soup bridge*. A password manager generates these automatically.

## How password managers support NCSC guidance

Three random words solve the memorability problem. They do not solve the scale problem. A [<u>password manager</u>](https://bitwarden.com/pt-br/products/personal/) does both.

Three random words solve the memorability problem. They do not solve the scale problem. A password manager does both; it generates strong, unique passwords for every account, stores them securely, and fills them in automatically. The only credential that needs to be memorized is one master passphrase.

The practical difference is significant. Instead of cycling through variations of the same phrase across dozens of accounts, every login gets a credential that is genuinely unique and impossible to guess.

The NCSC recommends password managers precisely because unique passwords at scale require a tool, not willpower. Bitwarden builds on this with an [<u>open source architecture</u>](https://bitwarden.com/pt-br/open-source/) that independent security researchers and auditors can verify directly. Cross-device access means that passwords are available on every device a user uses. Shared vault support lets small teams manage credentials without resorting to spreadsheets or shared documents.

## Where three random words stop being practical

> Three random words work well for a small number of important logins. The challenge is uniqueness. NCSC guidance is explicit: passwords should not be reused across accounts. Human memory is not built to scale.

A person managing five core logins (email, banking, a streaming service, a work account, and a government portal) can reasonably memorize five distinct passphrases. Add another ten accounts, and the system starts to fail. Phrases blur together, people fall back on variations of the same base phrase, and uniqueness disappears.

For small business teams, the problem scales faster. Password advice for small businesses needs to account for reality: a team of five regularly managing email platforms, finance tools, admin dashboards, and cloud storage is handling 30 or more credentials. Expecting staff to memorize a unique passphrase for each one is not realistic. When that system fails, people reuse passwords. That is where credential management tools become essential.

## When to memorize a passphrase and when to generate one

One rule covers it: memorize the vault master passphrase, generate everything else. Every other account gets a unique credential that users never need to think about again.

The master passphrase is the one credential that protects everything else. Unlike other logins, it's never stored in the vault; it lives only in the user's memory, which means it should be strong, unique, and built from genuinely random words rather than personal details.

Pairing it with [multifactor authentication (MFA)](https://bitwarden.com/pt-br/resources/mfa-for-shared-accounts/) raises the bar considerably. Even if the master passphrase were somehow exposed, MFA requires a second verification step that an attacker cannot easily replicate. Bitwarden supports multiple two-factor authentication (2FA) methods.

### **What to look for in a password manager**

When evaluating options, these features matter most:

- [Independent security audits](https://bitwarden.com/pt-br/open-source/) with published results
- Open source code that can be reviewed externally
- Cross-device sync so credentials are accessible everywhere
- [Shared vault support](https://bitwarden.com/pt-br/products/families/) for families and small teams
- Passkey storage and autofill for accounts that support them

Bitwarden meets all of these criteria.

## Multifactor authentication and passkeys: the next layer

Strong, unique passwords are the foundation. A password alone, however strong, is not the whole picture. Multifactor authentication and passkeys are what make that foundation significantly harder to undermine.

A strong, unique password can still be compromised through a phishing attempt, a service provider data breach, or malware on a device. MFA blocks most automated attacks even when the password is known, because it requires a second factor that the attacker does not have. NCSC guidance recommends enabling MFA wherever it is available.

NCSC guidance now identifies passkeys as the preferred option where services support them. Rather than a password that a user creates and must protect, a passkey is a cryptographic credential generated by the device; it cannot be phished or reused. Most accounts do not yet support passkeys. For those, passwords paired with MFA remain the recommended approach.

## Put the NCSC guidance into practice

The NCSC guidance on passwords is clear: longer passphrases, unique credentials for every account, a password manager to make that practical, and multifactor authentication wherever it is available. Following it consistently is harder without the right tool.

[<u>Bitwarden Password Manager</u>](https://bitwarden.com/pt-br/products/personal/) handles generation, storage, and autofill across every account, so good credential habits do not depend on memory or willpower. Setup takes minutes. The open source architecture means security can be independently verified rather than taken on trust, and cross-device sync means the vault is available wherever users work.

Bitwarden is free to get started for individuals and families. [<u>Business and Enterprise plans</u>](https://bitwarden.com/pt-br/pricing/business/) are available for teams that need shared vaults, admin controls, and audit trails.

## Tenha agora uma segurança de senhas poderosa e confiável. Escolha seu plano.

## Pessoal

### Acabou de começar?

*Obtenha o gerenciamento básico de senhas hoje mesmo. Sempre gratuito.*

[Criar conta gratuita](https://bitwarden.com/go/start-free/)

---

### Premium

**$1.65** *por mês*

*Cobrado anualmente por US$ 19,80*

Aproveite recursos premium

- Autenticador integrado
- Anexos de arquivos
- Acesso de emergência
- Bloqueador de phishing
- Relatórios de segurança e muito mais

Compartilhe itens do cofre com mais um usuário

[Criar conta Premium](https://bitwarden.com/go/start-premium/)

---

### Famílias

**$3.99** *por mês*

*Até 6 usuários, cobrado anualmente por US$ 47,88*

Proteja os logins da sua família

- 6 contas premium
- Compartilhamento ilimitado
- Coleções ilimitadas
- Armazenamento da organização

Compartilhe itens do cofre entre seis pessoas

[Iniciar teste gratuito do Families](https://bitwarden.com/go/start-families-trial/)

---

Preços exibidos em USD e baseados em uma assinatura anual. Impostos não incluídos.

## Empresas

### Teams

*Para equipes e empresas em crescimento que precisam avançar rapidamente.*

**$4** *por mês / por usuário, cobrado anualmente*

**Sem concessões**

Todos os recursos Premium, além de recursos avançados como:

- Compartilhe credenciais com segurança
- Audite atividades com logs de eventos
- Sincronize seu diretório existente
- Automatize o provisionamento com SCIM

[Iniciar teste gratuito](https://bitwarden.com/go/start-teams-trial/)

---

### Enterprise

*Para empresas que precisam de proteção e controle avançados.*

**$6** *por mês / por usuário, cobrado anualmente*

**Proteção máxima**

Todos os recursos Premium e Teams, além de recursos de nível empresarial como:

- Controle de acesso granular
- Integração com SSO sem senha
- Recuperação de conta fácil
- Flexibilidade para auto-hospedagem
- Remediação de riscos com o Access Intelligence [novo]
- Plano Families gratuito para todos os usuários

[Iniciar teste gratuito](https://bitwarden.com/go/start-enterprise-trial/)

---

### Fale com Vendas

*Para grandes organizações, fale com um especialista sobre um plano sob medida e saiba como a Bitwarden pode:*

*por mês*

- Reduzir riscos de cibersegurança
- Aumentar a produtividade
- Integrar-se perfeitamente

A Bitwarden se adapta a empresas de qualquer porte para levar segurança de senhas à sua organização

[Fale com Vendas](https://bitwarden.com/talk-to-sales)

---

Preços exibidos em USD e com base em uma assinatura anual. Impostos não incluídos.