A practical starting point: 16 or more characters

CISA recommends passwords of 16 or more characters in its guidance for organizations. In ComplexPass, you can enter 16 directly or select the 20-character preset. Check the account’s length limit before saving the result.

ComplexPass opens at 12 characters. That default is not a claim that 12 characters satisfy every service’s policy or every threat model. Longer settings are available without needing to invent a memorable pattern.

Length choices in ComplexPass
SettingHow to use it
12 charactersThe default; consider increasing it when the account permits
16 charactersEnter the length directly for a longer random result
20 charactersThe Stronger preset, convenient with a password manager
32 charactersA longer preset for accounts that support it

What the current NIST guidance actually says

NIST SP 800-63B-4 requires services following that standard to use a minimum of 15 characters for passwords used alone. It allows a shorter minimum of eight when a password is part of multi-factor authentication. These are requirements for the service, rather than a guarantee that a password at the minimum is safe in every situation.

The same standard rejects mandatory character-composition rules and routine password changes without evidence of compromise. Some websites still require a symbol or a number. ComplexPass lets you meet those practical restrictions while keeping the selection random.

Length helps most when the choices are random

A long string based on a familiar phrase, date, or repeated pattern can still be predictable. A random generator distributes its choices across the permitted results. When the rules allow more positions and choices, the number of possible results grows.

Character restrictions also matter. A digits-only password has fewer choices per position than one that permits letters and punctuation. Excluding lookalikes can make typing easier, but it also changes the search space. ComplexPass calculates its entropy display from the actual rules instead of treating every setting as interchangeable.

Why there is no reliable “time to crack” promise

An attacker trying passwords against a live website may face login limits. An attacker with a stolen password database faces different conditions, including the way the service stores password hashes. Hardware, the attack method, and the attacker’s information also vary.

That is why ComplexPass displays an estimate of search-space entropy rather than a countdown claiming a password will last a fixed number of years. The estimate concerns a generated random result, not a secret chosen from your personal habits.

Use a separate password for each account, store it safely, and use the service’s additional authentication options. If you need to remember the result, compare a random word passphrase with a character password. Then choose a length in the generator that fits your account.