Omsätt insikter i handling: Bitwarden Access Intelligence är nu tillgängligt Läs mer >

Bitwarden-resurser

NCSC guidance on passwords: what it recommends and where a password manager fills the gap

The National Cyber Security Centre (NCSC) guidance on passwords now centers on length, uniqueness, and tools that make good habits sustainable. Learn more today!

Password advice has shifted. The National Cyber Security Centre (NCSC) guidance on passwords now centers on length, uniqueness, and tools that make good habits sustainable. Forced complexity rules and routine password changes are no longer recommended; research shows they do more harm than good.

Understanding what guidance recommends, where it has limits, and how a password manager makes it practical is the foundation of a stronger credential strategy.

What does the NCSC guidance on passwords say?

The NCSC recommends four core practices:

  • Creating passwords from three random words, known as a passphrase

  • Avoiding guessable personal details like names, birthdays, and favorite teams

  • Steering clear of common weak passwords

  • Using a password manager for accounts where memorization is not practical

NCSC guidance has also shifted to prioritize passkeys where supported. Passkeys replace the password entirely with a cryptographic key pair, removing the risk of a stolen or reused credential. For most accounts today, passwords remain the default; the three-random-words approach and password managers still anchor the guidance.

Why does the NCSC recommend three random words?

A passphrase like correct-horse-battery-staple is longer, more memorable, and harder to crack than P@ssw0rd1!. That is the core logic behind the NCSC three-random-words approach: length is a stronger defense than complexity, and a passphrase someone can actually remember is more likely to remain unique across accounts.

Predictable substitutions, such as swapping "o" for "0," "a" for "@," or adding a "!" at the end, are well-known to attackers. Automated cracking tools account for these patterns. A short, symbol-laden password built on a formula offers far less protection than it appears to.

Before: Fluffy2012! Guessable from personal details, short, and pattern-based.

After: cobalt-ferry-window. Random, longer, and not tied to anything personal.

Why length beats forced complexity

An 8-character password using letters, numbers, and symbols can be cracked in minutes with modern hardware. A 20-character passphrase made of three random words can take centuries to brute-force, even without special characters. Length multiplies the number of possible combinations far faster than complexity rules do.

A 20-character passphrase made of three random words can take centuries to brute-force. An 8-character password with symbols can be cracked in minutes.

Why the NCSC moved away from forced rotation

For years, organizations required staff to change passwords every 90 days and to meet complexity requirements that included uppercase letters, numbers, and symbols. The NCSC now advises against both practices. Forced rotation leads to predictable changes; Password1 becomes Password2. Complexity rules produce patterns that attackers have already mapped. The NCSC recommends longer memorable phrases paired with password managers instead.

What makes a passphrase random enough to work

Length alone is not enough. The words themselves need to be genuinely unpredictable. A phrase like SunnyLondonMarathon is built from experiences that appear in social profiles, making it predictable even if it feels obscure. A genuinely random passphrase pulls words from an unrelated set: cobalt ferry window or lantern soup bridge. A password manager generates these automatically.

How password managers support NCSC guidance

Three random words solve the memorability problem. They do not solve the scale problem. A password manager does both.

Three random words solve the memorability problem. They do not solve the scale problem. A password manager does both; it generates strong, unique passwords for every account, stores them securely, and fills them in automatically. The only credential that needs to be memorized is one master passphrase.

The practical difference is significant. Instead of cycling through variations of the same phrase across dozens of accounts, every login gets a credential that is genuinely unique and impossible to guess.

The NCSC recommends password managers precisely because unique passwords at scale require a tool, not willpower. Bitwarden builds on this with an open source architecture that independent security researchers and auditors can verify directly. Cross-device access means that passwords are available on every device a user uses. Shared vault support lets small teams manage credentials without resorting to spreadsheets or shared documents.


Where three random words stop being practical

Three random words work well for a small number of important logins. The challenge is uniqueness. NCSC guidance is explicit: passwords should not be reused across accounts. Human memory is not built to scale.

A person managing five core logins (email, banking, a streaming service, a work account, and a government portal) can reasonably memorize five distinct passphrases. Add another ten accounts, and the system starts to fail. Phrases blur together, people fall back on variations of the same base phrase, and uniqueness disappears.

For small business teams, the problem scales faster. Password advice for small businesses needs to account for reality: a team of five regularly managing email platforms, finance tools, admin dashboards, and cloud storage is handling 30 or more credentials. Expecting staff to memorize a unique passphrase for each one is not realistic. When that system fails, people reuse passwords. That is where credential management tools become essential.

When to memorize a passphrase and when to generate one

One rule covers it: memorize the vault master passphrase, generate everything else. Every other account gets a unique credential that users never need to think about again.

The master passphrase is the one credential that protects everything else. Unlike other logins, it's never stored in the vault; it lives only in the user's memory, which means it should be strong, unique, and built from genuinely random words rather than personal details.

Pairing it with multifactor authentication (MFA) raises the bar considerably. Even if the master passphrase were somehow exposed, MFA requires a second verification step that an attacker cannot easily replicate. Bitwarden supports multiple two-factor authentication (2FA) methods.

What to look for in a password manager

When evaluating options, these features matter most:

  • Independent security audits with published results

  • Open source code that can be reviewed externally

  • Cross-device sync so credentials are accessible everywhere

  • Shared vault support for families and small teams

  • Passkey storage and autofill for accounts that support them

Bitwarden meets all of these criteria.

Multifactor authentication and passkeys: the next layer

Strong, unique passwords are the foundation. A password alone, however strong, is not the whole picture. Multifactor authentication and passkeys are what make that foundation significantly harder to undermine.

A strong, unique password can still be compromised through a phishing attempt, a service provider data breach, or malware on a device. MFA blocks most automated attacks even when the password is known, because it requires a second factor that the attacker does not have. NCSC guidance recommends enabling MFA wherever it is available.

NCSC guidance now identifies passkeys as the preferred option where services support them. Rather than a password that a user creates and must protect, a passkey is a cryptographic credential generated by the device; it cannot be phished or reused. Most accounts do not yet support passkeys. For those, passwords paired with MFA remain the recommended approach.

Put the NCSC guidance into practice

The NCSC guidance on passwords is clear: longer passphrases, unique credentials for every account, a password manager to make that practical, and multifactor authentication wherever it is available. Following it consistently is harder without the right tool.

Bitwarden Password Manager handles generation, storage, and autofill across every account, so good credential habits do not depend on memory or willpower. Setup takes minutes. The open source architecture means security can be independently verified rather than taken on trust, and cross-device sync means the vault is available wherever users work.

Bitwarden is free to get started for individuals and families. Business and Enterprise plans are available for teams that need shared vaults, admin controls, and audit trails.

Få kraftfull, pålitlig lösenordssäkerhet nu. Välj din plan.