NIST's second draft of its “SP 800-63-4“—its digital identify guidelines—contains rules about passwords.Passwords should be a minimum of eight characters in length and preferably 15 characters.Passwords can be up to 64 characters long and can include ASCII and Unicode characters.There should be no other composition rules for passwords, and periodic password changes are not required.