Tips & Tricks

Password Policy for Small Businesses: What to Include and Avoid

Build a modern password policy using practical requirements for length, MFA, compromised-password blocking, recovery and secure administration.

August 6, 2026Updated August 2026
Security policiesSmall business cybersecuritysmall business cybersecurity policyFramework Pro

Short answer: A modern password policy should favour sufficient length, blocked compromised passwords, MFA where appropriate, secure storage and recovery, and changes after suspected compromise—not arbitrary complexity rules or routine forced rotation.

Credential misuse remains a common attack vector across organizations of all sizes. A Password Policy should directly address predictable weaknesses while remaining operationally realistic.

Overly complex rules create workarounds. Insufficient rules create exposure.

The policy must balance both.

What to Include

1. Minimum Length Requirements

Length has greater security impact than excessive character variety.

Define:

  • Length requirements that reflect the authentication design. Current NIST guidance specifies at least 15 characters for passwords used as a single factor and at least eight when the password is used only as part of MFA.

  • Encouragement of passphrases where feasible

Clarity matters more than complexity formulas.

2. Multi-Factor Authentication (MFA)

Passwords alone are insufficient for higher-risk access.

Specify:

  • Mandatory MFA for administrative accounts

  • MFA for remote access (VPN, cloud platforms)

  • MFA for systems containing sensitive or regulated data

The policy should clearly define where MFA is required, not suggest it optionally.

3. Prohibited Practices

Explicitly state what is not allowed:

  • Sharing credentials

  • Reusing corporate passwords across external services

  • Storing passwords in unsecured files or notes

  • Using default vendor passwords

Prohibitions remove ambiguity.

4. Secure Storage Guidance

Encourage:

  • Approved password managers

  • Encrypted storage mechanisms

  • Unique passwords per system

If a password manager is mandated, identify the approved solution.

5. Compromise Response Procedure

Define steps when exposure is suspected:

  • Immediate password reset

  • Session invalidation where applicable

  • Notification to IT or security

  • Review of account activity

Response clarity limits dwell time after compromise.

6. Rotation Rules Based on Risk

Avoid arbitrary timelines.

Instead:

  • Require a change when there is evidence of compromise

  • Avoid routine forced changes unless another applicable requirement or a specific risk decision justifies them

  • Document exceptions where legacy systems or contractual requirements impose different rules

Unnecessary forced changes often degrade password quality.

What to Avoid

Excessive Complexity Requirements

Rules such as mandatory special characters in fixed positions often produce predictable patterns. Complexity without usability reduces security.

Frequent Mandatory Rotation Without Cause

Current NIST guidance says verifiers should not require periodic password changes and should require a change when there is evidence of compromise.

Vague Language

Statements like “use strong passwords” provide no operational instruction. Policies must be specific and measurable.

Unrealistic Enforcement

If employees cannot comply easily, they will bypass controls. Policies must reflect actual system capabilities and workflow realities.

Structural Objective

An effective Password Policy should:

  • Be concise

  • Define measurable requirements

  • Align with authentication risk levels

  • Integrate MFA as a primary control

  • Remain enforceable through technical configuration

Security strength is determined by adoption and enforcement, not document length.

Sources and further reading

A practical next step

Use this guidance as a starting point, then check it against the way your business actually operates. Security policies should be reviewed, approved, implemented, and supported by evidence.

Aneo Framework Pro uses questionnaire answers and business context to generate tailored, editable security policy drafts. Its outputs support review and readiness work; they do not certify a business, replace implementation, provide legal advice, or remove the need for human review.