How long should your password be? It's one of the most common questions in cybersecurity — and the answer has changed dramatically over the years.
In 2026, the recommendation is simple: longer is always better. A 16-character password is the new minimum, and 20–30 characters is ideal. But why exactly does length matter so much? And how long is long enough for your email, banking, social media, or password manager?
This guide answers all of that — with real math, expert recommendations, and practical examples you can use immediately.
Why Password Length Matters More Than Most People Think
Every character you add to a password multiplies the number of possible combinations exponentially. This makes brute-force attacks — where attackers try every possible combination — exponentially harder.
Consider this: a password with only lowercase letters (26 options per character) has 26ⁿ possible combinations, where n is the length. The difference between 8 and 16 characters is staggering:
26⁸
8 lowercase letters
~208 billion combinations
Cracked in minutes
26¹⁶
16 lowercase letters
~43 sextillion combinations
Cracked in billions of years
Length isn't just a recommendation — it's the single most important factor in password security. Every additional character multiplies the search space. A 16-character password with only lowercase letters is stronger than a 10-character password with uppercase, lowercase, numbers, and symbols.
See the math for yourself
Use the Password Entropy Calculator to see exactly how length and character set affect crack time — step-by-step math, visualised.
Password Length vs Complexity: Which Matters More?
For years, websites forced users to create complex passwords with uppercase, lowercase, numbers, and special symbols. But security experts now agree: length beats complexity.
Why? Because adding a single character increases the search space more than adding a symbol to a shorter password. Here's the proof:
| Password | Length | Character Set | Combinations | Crack Time |
|---|---|---|---|---|
| P@ssw0rd! | 9 | 94 | ~5.7 × 10¹⁷ | ~2 days |
| correcthorsebatterystaple | 25 | 26 | ~2.3 × 10³⁵ | ~6 trillion years |
A 25-character lowercase passphrase is exponentially stronger than a 9-character complex password.
The TL;DR : make your passwords longer. Add characters before you add symbols. A 16-character lowercase password is stronger than a 12-character mixed-case password with symbols.
How Password Entropy Increases With Length
Entropy measures the unpredictability of a password — essentially, how many guesses an attacker would need to crack it. It's calculated as:
Entropy = log₂(Character Set Sizeⁿ) = n × log₂(Character Set Size)
Where n = password length
Here's how entropy increases with length for different character sets:
| Length | Lowercase Only (26) | Mixed Case (52) | Full Set (95) |
|---|---|---|---|
| 8 | 38 bits | 46 bits | 52 bits |
| 12 | 57 bits | 68 bits | 79 bits |
| 16 | 76 bits | 91 bits | 105 bits |
| 20 | 94 bits | 114 bits | 131 bits |
| 24 | 113 bits | 137 bits | 157 bits |
Bits of entropy — higher = exponentially harder to crack. 80+ bits is considered secure for most accounts.
Password Length Recommendations by Security Experts
Different security organisations have varying recommendations. Here's what the leading experts say in 2026:
NIST
Recommend at least 8 characters, but encourage longer passwords up to 64 characters. Focus on length over complexity.
NCSC (UK)
Recommend 15+ characters. Emphasise using three random words to create a passphrase.
OWASP
Recommend 16+ characters for general accounts, 20+ for sensitive accounts.
MahaVault
16 characters minimum for all accounts, 20+ for critical accounts. Use a Password Generator to create them.
Recommended Password Length by Account Type
Not all accounts need the same level of protection. Here's what we recommend for different account types:
| Account Type | Recommended Length | Why |
|---|---|---|
| 20+ characters | Email is the reset key for every other account. It must be the most protected. | |
| Password Manager Master | 20+ characters | This unlocks all your other passwords — it needs maximum protection. |
| Banking / Financial | 16–20 characters | Direct financial access — 2FA is also essential. |
| Social Media | 16 characters | Identity theft risk — 16 characters with 2FA is recommended. |
| Work / Corporate | 16–20 characters | Corporate data breaches often start with compromised credentials. |
| E-commerce / Shopping | 16 characters | Payment details need protection. 16 characters is a strong baseline. |
| Forums / Low-value | 12–16 characters | Less sensitive, but still use a unique password to avoid credential stuffing. |
Generate the perfect length password
Use the Password Generator to create passwords of any length with full control over character sets — then let your password manager store them.
How Long Passwords Resist Different Attacks
Length protects against several common attack types:
Brute-force attacks
A 16-character password takes billions of years to crack with modern hardware. Every character multiplies the search space exponentially.
Dictionary attacks
Longer passwords with random words (passphrases) are far less likely to appear in word lists. A 4-word passphrase is effectively uncrackable.
Credential stuffing
Unique long passwords for every account stop credential stuffing entirely — a leak at one site doesn't affect others.
The reality
Modern GPUs can try billions of passwords per second . An 8-character password can be cracked in under an hour. Length is your strongest defence.
Password Length vs Estimated Crack Time (2026)
These estimates assume a modern GPU at 10 billion guesses per second — conservative for today's hardware:
| Length | Lowercase Only | Mixed Case (52) | Full Set (95) | Security Level |
|---|---|---|---|---|
| 8 | ~2 min | ~8 hours | ~1 year | Very weak |
| 10 | ~1 day | ~2 years | ~2,000 years | Weak |
| 12 | ~2 years | ~34,000 years | ~3 million years | Moderate |
| 14 | ~2,000 years | ~920 million years | ~27 billion years | Strong |
| 16 | ~54,000 years | ~47 trillion years | ~2.6 quadrillion years | Excellent |
| 20+ | Trillions of years | Quintillions of years | Uncrackable | Uncrackable |
Estimates assume 10 billion guesses per second. Real-world crack times depend on hashing algorithms and hardware — these are best-case scenarios for attackers.
Test your passwords
Curious about your current passwords? Use the Password Strength Checker to see entropy score, crack time, and improvement tips — completely offline.
Password Examples: Weak vs Strong
Seeing the difference side by side makes it concrete:
| Password | Length | Strength | Why |
|---|---|---|---|
| 123456 | 6 | Very weak | Sequential numbers — the most common password. Cracks instantly. |
| password123 | 11 | Weak | Common dictionary word + numbers. Cracks in seconds. |
| P@ssw0rd!2024 | 13 | Moderate | Predictable substitutions. Attackers know these patterns. |
| T#k9$mP2!qL8@vR5 | 16 | Strong | 16 random characters, mixed case, numbers, symbols. Excellent entropy. |
| Coral$7Trout!Hike9 | 20 | Very strong | 20-character passphrase with symbols. Memorable, impossible to crack. |
Passphrases vs Traditional Passwords
A passphrase is a sequence of random words, like PurpleMountainRiverFlows7! . It's easier to remember and often stronger than a shorter complex password.
Traditional Password
T#k9$mP2!qL8@vR5
High entropy per character, but hard to memorize. Best stored in a password manager.
16 characters · 105 bits entropy
Passphrase
Coral$7Trout!Hike9
Easier to remember and often stronger — length wins over complexity.
20 characters · 130+ bits entropy
Pro tip
Use the Passphrase Generator to create memorable yet secure passphrases with custom word count and separators.
Common Password Length Myths, Busted
"8 characters is enough if it's complex."
8 characters can be cracked in under an hour with modern GPUs. Length matters more than complexity.
"Passphrases are too long to type."
With a password manager, you never type them — only your master password. A passphrase is easier to remember than random characters.
"Adding special characters makes any password secure."
A 10-character password with symbols is still weaker than a 16-character lowercase-only password. Length wins.
"I can't remember long passwords, so I'll use shorter ones."
Use a password manager — you only need to remember one master password. The manager handles the rest.
Common Password Length Mistakes to Avoid
- ✗ Stopping at the minimum — minimum requirements are just that: minimums. Aim well above.
- ✗ Using the same password length everywhere — critical accounts need longer passwords than low-value ones.
- ✗ Sacrificing uniqueness for length — a long password you reuse is worse than a shorter unique password.
- ✗ Using only length, no randomness — "aaaaaaaaaaaaaaaa" is long but trivial to crack. Entropy needs both length and randomness.
- ✗ Believing 2FA removes the need for length — 2FA and length complement each other. Both are essential.
Best Practices for Password Length
Best practices for password length
-
Aim for 16+ characters for all accounts
This is the new minimum for strong security. Use a Password Generator to create them.
-
Use 20+ characters for critical accounts
Email, password manager master, and banking deserve extra length.
-
Use a passphrase for master passwords
4–6 random words with a number and symbol — memorable and uncrackable.
-
Store passwords in an offline password manager
An offline password manager lets you use maximum-length passwords without needing to remember them.
-
Enable 2FA on all accounts
Long passwords + MFA = the strongest protection available.
-
Review your passwords monthly
Use a Password Strength Checker to catch weak or short passwords.
Password Length Checklist
Use this checklist to ensure your passwords are long enough:
-
Every account has 16+ characters
Use a Password Generator to create them.
-
Critical accounts are 20+ characters
Email, banking, and password manager master password.
-
Master password is a passphrase
4–6 random words with a number and symbol. Use the Passphrase Generator .
-
No password is reused
Unique passwords for every account — even if they're long.
-
Passwords are stored in an offline vault
An offline password manager keeps everything encrypted and accessible.
-
Passwords are tested regularly
Use the Password Strength Checker to verify.
Final Thoughts
How long should your password be? As long as possible. In 2026, 16 characters is the new minimum, and 20+ characters is ideal for critical accounts. Length is the single most important factor in password security — it multiplies the effort required to crack your password exponentially.
Combine long passwords with uniqueness (no reuse) and a password manager to store them. Use passphrases for your master password, enable 2FA on every account, and regularly audit your passwords. The result? Uncrackable security.
Stop guessing password length. Start generating them.
MahaVault's built-in generator creates truly random passwords of any length — then stores them in an encrypted offline vault with biometric lock.