Matches your standard
Each template uses that standard's actual rules: NIST's length-first approach, CMMC's 3.5.x requirements, CJIS v6.1 IA-5(1), or PCI DSS Requirement 8, with requirement numbers cited.
Pick the standard your business follows, add your company name, and get a complete written password and authentication policy you can edit, print, or save as a PDF. Built for small businesses and contractors. Nothing you type is sent anywhere.
A starting template, not legal or compliance advice. Review it with your compliance lead or assessor.
Last updated
Most small businesses need a written password policy for an assessment, a contract, or an insurance form. Start from one that already matches your standard.
Each template uses that standard's actual rules: NIST's length-first approach, CMMC's 3.5.x requirements, CJIS v6.1 IA-5(1), or PCI DSS Requirement 8, with requirement numbers cited.
Fifteen sections from purpose to signature lines. Copy it into your own document, or download a text file to edit.
The policy is built in this page. Your company name and choices aren't sent or saved anywhere.
This is a starting template, not legal or compliance advice. Your assessor, QSA, or CJIS Systems Agency has the final word.
NIST SP 800-63B-4 for most businesses. CMMC Level 2 if you handle Controlled Unclassified Information (CUI) on DoD contracts. CJIS if you access criminal justice information for law enforcement. PCI DSS if you store, process, or transmit payment card data.
No. A written policy is one piece. You also have to configure your systems to enforce it, train your staff, and keep records. Each standard covers much more than passwords.
NIST found that forced changes lead people to make small, predictable edits. NIST SP 800-63B-4 says to require a change only when there is evidence of compromise, and to check new passwords against breached-password lists instead. PCI DSS still requires 90-day changes when a password is the only factor.
Yes. Copy the text or download it, then paste it into your own document and change anything you need, such as lockout numbers or the policy owner.
Monitoring assessments, NOC runbooks, network administration, and hands-on hardware deployment from a service-disabled veteran-owned small business in Waco, Texas.