ISM-2080: Why Password Complexity Rules Are Out
Reviewed by Greg Tereszczyn on 4 October 2026 against ISM 2026.09.4

Password complexity requirements are not imposed for passwords.
ISM-2080, Information Security Manual, Australian Signals Directorate. ISM text © Commonwealth of Australia, CC BY 4.0, via cyber.gov.au.
- Where it sits
- Guidelines for system access › Credential management › Password strength
- Applies to
- Non-classified, OFFICIAL: Sensitive, PROTECTED, SECRET, TOP SECRET
- Essential Eight
- Not an Essential Eight requirement
- ASD revision
- Revision 0, December 2025. Checked against ISM 2026.09.4.
Stop forcing character mixes
People may use symbols; no system may demand them.
Require length instead
15 characters or more, and block common and breached passwords.
Put MFA in front
Multi-factor authentication matters more than any password rule.
On this page
ISM-2080 tells organisations to stop forcing passwords to contain a mix of capital letters, numbers and symbols. In place of those complexity rules, the Information Security Manual relies on length, a check against lists of common and breached passwords, and multi-factor authentication. A long passphrase that people can remember does more to protect an account than a short password dressed up with symbols.
#What does ISM-2080 require?
In plain English: no system should reject a password because it has no capital letter, digit or symbol. People can still use any of those characters, and ISM-2081 requires every printable ASCII character to be accepted; they just cannot be forced to.
The control applies at every classification level ASD marks, from non-classified systems to TOP SECRET, so it is not a relaxation for low-risk systems only. It sits with the other password strength controls under credential management, and it reads together with them: ISM-2080 removes a rule that does not work, and the controls around it (covered below) set the ones that do.
It is not an Australian quirk either. The US National Institute of Standards and Technology says verifiers "SHALL NOT impose other composition rules (e.g., requiring mixtures of different character types) for passwords" in NIST SP 800-63B, Revision 4, published in August 2025.
#Why are password complexity rules a problem?
Complexity rules make passwords look strong to a computer and predictable to an attacker. Faced with "one capital, one number, one symbol", most people produce the same few shapes: a capital at the start, a word, a year or a 1 at the end, and an exclamation mark. Password guessing tools try exactly those shapes first.
The common substitutions are just as predictable. Microsoft's password protection, for example, swaps "@" back to "a", "0" back to "o" and "$" back to "s" before it compares a new password with its list of weak ones, as Microsoft documents. "P@ssw0rd!" passes a complexity rule and is still one of the first guesses an attacker makes.
Complexity rules also push people towards passwords that are short enough to remember, which leads to passwords on sticky notes, the same password reused across systems, and a number incremented every time a change is forced. Microsoft's own reference for the Windows complexity setting notes it "may cause some more Help Desk calls for locked-out accounts" (Microsoft).
#What should replace complexity rules?
ISM-2080 only works alongside the rest of the password strength controls:
- Length. ISM-0421 sets a minimum of 15 characters for passwords used on their own (single-factor authentication) on non-classified, OFFICIAL: Sensitive and PROTECTED systems. SECRET and TOP SECRET systems need 17 and 20 characters (ISM-1557 and ISM-0422).
- Passphrases done properly. ISM-1558 says a passphrase built from words needs at least four random words on non-classified, OFFICIAL: Sensitive and PROTECTED systems, and must not be a real sentence, song lyrics, a quote or a list of words from one category.
- No common or breached passwords. ISM-2078 says passwords that appear in lists of commonly used or compromised passwords are not used, so the system has to check new passwords against such a list.
- No low ceiling. ISM-2079 says any maximum length limit is at least 64 characters, so long passphrases and password manager output fit.
- Any character. ISM-2081 says all printable ASCII characters are supported, spaces included, so nobody has to strip the spaces out of a passphrase.
- Multi-factor authentication. Where a password is one factor of multi-factor authentication, ISM-1559 allows a minimum of 6 characters on non-classified, OFFICIAL: Sensitive and PROTECTED systems, because the second factor carries much of the load.
ASD's advice for everyone says the same thing in fewer words: a passphrase of "four or more random words" that is long, unpredictable and unique (ASD, Passphrases).
#How do you meet ISM-2080?
- Find every place a password is set. The cloud identity platform, any on-premises directory, remote access, business applications with their own logins, network and security devices, and customer-facing portals.
- Turn complexity off, and turn length and blocklists on in the same change. Removing complexity alone would weaken a short-password policy. Change the three together.
- Raise the minimum length to 15 characters for single-factor sign-in (ISM-0421). Check what each system can enforce: Microsoft documents the classic Active Directory policy as accepting a minimum of 1 to 14 characters (Microsoft).
- Block common and breached passwords at every password change (ISM-2078).
- Allow at least 64 characters and every printable character (ISM-2079 and ISM-2081), then test it with a long passphrase that contains spaces.
- Put multi-factor authentication in front of everything that matters. It is the bigger win, and it is one of the eight strategies in the Essential Eight.
- Update the written password standard and the guidance people see when they choose a password. Apply the new rules at the next password change rather than forcing everyone to change at once.
#What evidence shows ISM-2080 is met?
| Ask | Look at | Good looks like |
|---|---|---|
| Does any system still demand a mix of character types? | Password settings in the identity platform, directory policies, business applications and device admin pages | Complexity rules off wherever passwords are set |
| How long must a password be? | The same settings, and a test password change | At least 15 characters for single-factor sign-in (ISM-0421) |
| Are common and breached passwords blocked? | The blocklist setting, and a test with a well-known weak password | The weak password is rejected (ISM-2078) |
| Can people use long passphrases with any character? | A test with a 64-character passphrase that includes spaces and symbols | It is accepted (ISM-2079, ISM-2081) |
| Does the written standard match the systems? | The password policy and onboarding material | No complexity rule; length, blocklist and multi-factor authentication described |
| Are the exceptions known? | The exceptions register | Any system that still forces complexity is listed, with a reason, a compensating control and a date to fix it |
#What gets in the way?
Defaults and legacy systems. Microsoft lists "Password must meet complexity requirements" as enabled by default in the default domain policy of Active Directory (Microsoft), and older business applications and network devices often have complexity rules or short length limits built in. Those systems go on the exceptions register with multi-factor authentication or network restrictions in front of them until they can be changed or replaced.
Questionnaires that have not caught up. Audit checklists, customer security questionnaires and insurance forms still ask whether password complexity is enforced. The honest answer is "no, by design", backed by ISM-2080, NIST SP 800-63B and the evidence above. Answering "yes" to please a form means keeping a control ASD has told you to remove.
Habit. Many people, IT staff included, learned that complexity means strength. A short explanation when the policy changes, and a passphrase example, saves a lot of help desk calls.
Smaller organisations versus large ones. A small organisation usually has one cloud identity platform, so the change is a handful of settings, but it often depends on a managed service provider and on applications it cannot configure. A large organisation has several directories, fine-grained policies, service accounts and legacy applications, so the work is mostly inventory, testing and change management. In both, the cost is mostly time: finding every system that sets a password.
#What tools and skills help?
- An identity platform that enforces length and checks new passwords against weak and breached ones. Microsoft, for example, documents a global banned password list that its cloud identity service applies to every user automatically, a custom list on its paid plans, and agents that extend the check to on-premises Active Directory (Microsoft).
- A password manager, so long unique passwords cost people nothing to remember. ASD recommends one for anyone with multiple accounts (ASD, Passphrases).
- Multi-factor authentication, which matters more than any password rule.
- The skills to audit identity settings across every system, write a password standard that matches them, and explain the change to staff.
Which of your current licences already provide these? The free coverage check shows which ISM and Essential Eight controls the products you already pay for can reach, in about three minutes. To see the ISM's password controls in context, open ISM-2080 in our sample coverage report, or read what an ISM assessment involves.
#What changed in recent ISM releases?
ISM-2080 is new: ASD's catalogue records it at revision 0, last updated in December 2025. In the September 2026 release it moved, with the rest of the password strength controls, from "Guidelines for system hardening › Authentication hardening" to "Guidelines for system access › Credential management", with its wording unchanged. Our ISM September 2026 summary covers the rest of that release.
#Sources
- ASD, Information security manual: ISM-2080 and the password strength controls quoted on this page
- ASD, Passphrases
- NIST, SP 800-63B Revision 4, Digital Identity Guidelines: Authentication and Authenticator Management, August 2025
- Microsoft, Password protection in Microsoft Entra ID
- Microsoft, Password must meet complexity requirements and Minimum password length
Which of your licences already cover this?
The free coverage check shows which ISM and Essential Eight controls the products you already pay for can reach, in about three minutes. For a structured look at your own environment, an ISM assessment maps your controls and the evidence that proves them.
More ISM controls explained
- ISM-1648: Disable Idle Admin Access After 45 Days →
ISM-1648 says privileged access is disabled after 45 days without use. What counts as inactive, how to automate it, the exceptions and evidence to keep.
- ISM-0428: Lock Idle Sessions After 15 Minutes →
ISM-0428 says online services lock after 15 idle minutes or 12 hours in all, and unlock only with every factor. What that means and the evidence to keep.
- ISM-1685: Passwords for Admin and Service Accounts →
ISM-1685 says break glass, local admin and service account credentials must be long, unique, random and managed. What that means and the evidence to keep.
- ISM-2121: Security Skills for Software Developers →
ISM-2121 says developers without the security skills a task needs are not used for it. What that means for staff, contractors and AI, and the evidence.
Written by
Greg Tereszczyn
Greg Tereszczyn is the founder and principal consultant of TERESEC, an Australian cyber security consultancy for small and medium business. He turns the Essential Eight, the ISM, ISO/IEC 27001, NIST CSF and IEC 62443 into plain-English advice a business can act on.