Free tool · Generator

Your password policy, ready to share.

Set a few parameters and get a clear, compliant policy aligned with best practices, to copy or receive as a printable version.

Your policy

Get the ready-to-share version

A printable document (PDF) to share with your employees, in your company's colors.

Version unlocked ✓

Print or save your policy as PDF, then share it. Remember to train your teams to apply it.

Method

What this policy is based on

The defaults (14 characters, no periodic rotation, mandatory MFA) follow current NIST and Canadian Centre for Cyber Security recommendations, not an in-house standard.

Forced 90-day rotation, long the norm, is now discouraged by most frameworks: it pushes employees toward predictable passwords (incrementing a digit) rather than stronger ones. Length matters more than complexity — a long, unique password managed by a password manager protects better than a short one loaded with symbols you have to write down to remember.

MFA remains the control with the biggest real-world impact: it blocks the vast majority of account compromises even when the password has leaked elsewhere. A policy that omits it leaves a major blind spot, regardless of how strong the required password is.

The generated document is a starting point to adapt to your context — number of employees, systems in place, contractual or insurance requirements. A policy distributed without accompanying training is rarely followed; that's why the button after unlocking leads directly to training your teams.

FAQ

Frequently asked questions

Why isn't periodic rotation recommended by default?

Because it pushes employees to pick passwords that are easy to remember and evolve, often in predictable ways. Changing only on suspected compromise, combined with a long, unique password, protects better.

Is this document legally sufficient?

It's a technical best-practice template, not legal advice. Depending on your sector or contractual obligations, have it reviewed by your legal counsel or insurer.

Is a written policy enough to protect the company?

No — a policy that isn't enforced or understood by employees changes nothing in practice. It needs to be paired with training and, ideally, monitoring that catches compromised accounts anyway.