NIST password and MFA rules (SP 800-63B-4) explained for small businesses
NIST SP 800-63B-4, dated July 2025, sets detailed requirements for passwords and multi-factor authentication. Ask the assistant how its rules on length, password changes and authenticator types apply to the systems you run or choose.
Ask your question
Free account requiredAnswers are written by a language model solely from this base's documents, with numbered sources. They can be wrong and aren't legal, medical or financial advice: check the sources before any important decision.
Password length and composition
Under SP 800-63B-4, a password used as the only authentication factor must be at least 15 characters long. A password used only as part of multi-factor authentication may be shorter, but never under eight characters.
Verifiers should allow passwords of at least 64 characters and must not impose composition rules such as requiring a mix of character types.
New passwords must be checked against a blocklist of commonly used, expected or compromised values, for example passwords from earlier breaches, dictionary words or the name of the service. If a password is rejected, the user must be told why.
Password changes, hints and password managers
The guideline says verifiers must not require users to change passwords periodically. A change must be forced only when there is evidence the authenticator has been compromised. Note that the older NISTIR 7621 Rev. 1 small-business guide still suggested changing passwords every three months, so the newer authentication guideline is the one to follow on this point.
Password hints accessible to an unauthenticated person are not allowed, nor are security questions such as the name of a first pet. Verifiers must allow password managers and autofill, and should allow pasting when autofill is not available, because password managers help people choose stronger passwords.
Frequently asked questions
Which MFA methods count as phishing-resistant?
SP 800-63B-4 states that passwords, look-up secrets, out-of-band methods and one-time password (OTP) authenticators are not phishing-resistant, because a manually entered code is not bound to the session. Cryptographic authentication can be phishing-resistant when it meets the additional requirements in the guideline.
What does it mean that SMS or voice codes are a restricted authenticator?
At publication, using the public telephone network (SMS or voice) for out-of-band authentication is the only restricted authenticator in the guideline, and accepting it requires the organization to assess, understand and accept its risks. Verifiers should consider risk signals such as a SIM change, device swap or number porting before sending a code that way.
What is the difference between AAL1 and AAL2?
AAL1 gives basic confidence and accepts single-factor authentication, although verifiers should offer MFA options and encourage their use. AAL2 gives high confidence and requires proof of two distinct authentication factors, and applications at AAL2 must offer a phishing-resistant option.
Embed / API / MCP
Connect this base to Claude, Cursor, ChatGPT or your own app. Each API or MCP request costs €0.10, charged to your Kopik credit (not charged if nothing is found). You need an API key: create one from your dashboard.
MCP for your agents
This base's MCP server URL (tools ask_base and search_base):
https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurityClaude Code, Cursor and other clients
claude mcp add --transport http kopik-nist-csf-2-small-business-cybersecurity "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity" --header "Authorization: Bearer kpk_…"{
"mcpServers": {
"kopik-nist-csf-2-small-business-cybersecurity": {
"url": "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity",
"headers": {
"Authorization": "Bearer kpk_…"
}
}
}
}REST API for your apps
mode is "answer" (written answer + sources) or "passages" (raw passages only). Add an optional maxPriceCents to cap the price: if the base costs more, the call is refused and nothing is charged.
curl -X POST https://kopik.io/api/v1/bases/nist-csf-2-small-business-cybersecurity/query \
-H "Authorization: Bearer kpk_…" \
-H "Content-Type: application/json" \
-d '{"question": "Your question here", "mode": "answer"}'Getting started
- Create a key in your dashboard and top up your credit.
- Replace
kpk_…with your key. - Full details (responses, errors, JS and Python examples): developer docs.