Knowledge · Check before you click or pay · 7 minutes

How to create a strong password: length, examples, managers

How to create a strong password: length per NIST and CERT Polska, a random-word pattern, generators, password managers on phone and browser, passkeys.

Last updated: October 6, 2026

How do you create a strong password?

A strong password is one that a program cannot guess and that does not appear in a breach database. Criminals rarely guess by hand. According to CERT Polska, they use programs that test millions of combinations per second, plus lists of passwords from old breaches.

So two rules matter. First, every account gets a different password, because one breach must not open every door. Second, the password is long. According to CERT Polska (article updated 2 September 2026), length matters more today than whether a password has special characters.

In practice: you build and memorize one strong password yourself (for the password manager or your email), and the password manager generates and remembers the rest.

How many characters should a strong password have?

The US NIST guidelines SP 800-63B-4, published 26 August 2025, require services to demand passwords of at least 15 characters when the password is the only way to sign in, and at least 8 when it is part of multi-factor sign-in. Services should also allow passwords of at least 64 characters, spaces included.

CERT Polska recommends aiming for at least 14 characters, ideally more. A password made of four or five words is usually 20-30 characters long, so it clears both thresholds comfortably.

Sources differ here. An older guide in the Polish government knowledge base (gov.pl) says at least 8 characters, better 12-14, and asks you to mix lower and upper case, digits and special characters. The newer NIST and CERT Polska guidance favours length over character mixing. We follow the newer guidance.

Strong password examples: a pattern, not a ready-made password

Do not copy passwords from examples online, including this article. A password someone has published may end up on lists that criminals test. Copy the pattern, not the password.

The passphrase pattern works like this: take 4-5 words that have nothing in common (for example: a piece of furniture, a vegetable, a vehicle, a colour), turn them into an odd mental image and write them together, with capitals or with spaces. If a service demands a digit or a symbol, add one anywhere. The result is long for a computer and easy for you to remember.

What to avoid: words that often go together, names, birth dates, street and pet names, the word-plus-digit-plus-exclamation-mark pattern, and variants of an old password with a new year at the end. CERT Polska notes that cracking tools try exactly these patterns first.

What should a strong password contain, and what should a service not demand?

A strong password contains above all many characters and nothing that can be linked to you. Capitals, digits and symbols do no harm, but on their own they do not solve anything: according to CERT Polska, a short "complex" password is easier for a computer than a long one made of ordinary words.

NIST goes further. Under SP 800-63B-4, services should not force you to mix character types or change your password periodically. You change a password when there is evidence it has leaked. Services should instead check new passwords against lists of breached passwords and dictionary words, and allow pasting and password managers.

What is a password manager and how does it work?

A password manager is a program that generates long random passwords, stores them in an encrypted vault, fills them in on login pages and syncs them between your computer and phone. You remember one master password.

The generator in a password manager is the simplest answer to the search for a strong password generator. Google Password Manager, built into Chrome and Android, creates strong, unique passwords and passkeys. According to Apple, the Passwords app in iOS 18 and macOS Sequoia suggests a unique, complex password when you create an account. Do not type your real passwords into random "strength testers" on websites.

A password manager also protects against phishing. It ties each password to a specific domain, so it will not offer it on a fake site. According to CERT Polska, if autofill suddenly stops working where it always worked, treat that as a warning. Read more about fake sites in what phishing is and how to spot it, and you can check a suspicious login page address for free.

Is a password manager safe? Google, Chrome and your phone

A password manager is not perfect protection, but CERT Polska calls it the most important password tool you can have. For people who use a browser, CERT Polska calls the built-in password saving a simple and good solution.

Google Password Manager works in Chrome, on Android and at passwords.google.com. Google says passwords and passkeys are encrypted, synced when you are signed in to your Google Account, and that the service warns you about leaked passwords. On iPhone the equivalent is the Passwords app, which syncs through iCloud Keychain.

What really threatens a password manager: takeover of the account it is tied to (Google, Apple or a standalone manager account) and malware on the device. CERT Polska describes infostealers that steal saved credentials and sessions. So: turn on two-factor authentication on the manager account, set a screen lock on your phone, keep the system updated and do not install apps from outside official stores.

Passkeys: signing in without a password

A passkey is a sign-in credential stored on your device, in a password manager or on a hardware key, that replaces a password. You sign in with your fingerprint, face or PIN.

According to CERT Polska, passkeys are currently the only widely available sign-in method resistant to phishing, because the key is bound to the site address and a fake site cannot extract anything useful. CERT Polska's advice is simple: if a service offers a passkey instead of a password, create one.

How to check whether a password is secure

You cannot reliably test a password on a site that asks you to type it in. Check differently: Google Password Manager has Password Checkup (passwords.google.com), and the Passwords app on iPhone warns about weak passwords and ones that appeared in breaches.

Check your email address in breach databases. We explain how to use bezpiecznedane.gov.pl and Have I Been Pwned in how to check if my data has leaked. If a password has leaked, change it there and everywhere you used the same or a similar one.

In short

  • Length and uniqueness beat special characters: aim for 15 characters or more, a different password for every account.
  • Build one master password from 4-5 random words. Let a password manager generate the rest.
  • A password manager in your browser or phone is a good choice, provided the account it is tied to has two-factor authentication.
  • Do not change passwords every 90 days for no reason. Change them after a breach or a suspected break-in.
  • When a service offers a passkey, create one: it is a sign-in method that fake sites cannot phish.

Have a website, app or email address that looks suspicious?

Frequently asked questions

Is Google Password Manager safe?

Google says passwords are encrypted and that the manager warns you about breached passwords. Its safety still depends on your Google Account: turn on two-factor authentication there and use a screen lock on your phone.

Where is the password manager on my phone?

On Android it is Google Password Manager: you will find it in your Google Account settings, in Chrome and at passwords.google.com. On an iPhone with iOS 18 or later it is the Passwords app.

Should I use an online password generator?

It is better to use the generator built into your password manager, because it saves the password straight away and you never have to copy it anywhere. Do not type your real passwords into random sites that promise to rate them.

Do I need to change my password every 90 days?

No. NIST SP 800-63B-4 says services must not force periodic password changes without evidence of compromise. Change a password after a breach or when you suspect a break-in.

How does a password manager protect against phishing?

The manager ties each password to the site's domain and will not offer it on a lookalike domain. If autofill does not appear where it normally does, you may be on a fake site.

Is it OK to write a password down on paper?

A sticky note on your monitor is a bad idea, and so is a plain text file. CERT Polska does accept keeping two-factor backup codes on paper hidden somewhere safe at home.

Sources

  1. NIST SP 800-63B-4: Digital Identity Guidelines, Authentication and Authenticator Management (26 August 2025)
  2. CERT Polska: How to create secure passwords and protect your accounts (updated 2 September 2026, in Polish)
  3. CERT Polska: Phishing, how to recognise a scam (updated 2 September 2026, in Polish)
  4. CERT Polska: Multi-factor authentication (MFA) (in Polish)
  5. Polish government knowledge base (gov.pl): How to create a secure password (in Polish)
  6. Google Help: Google Password Manager
  7. Apple Support: Passwords app on iPhone, iPad and Mac

Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.

See also