Tech & produit

NIST password and MFA rules (SP 800-63B-4) explained for small businesses

NIST SP 800-63B-4, dated July 2025, sets detailed requirements for passwords and multi-factor authentication. Ask the assistant how its rules on length, password changes and authenticator types apply to the systems you run or choose.

Posez votre question

Compte gratuit requis

Chaque question est indépendante · 1 offertes par mois, puis avec l'abonnement.

Les réponses sont rédigées par un modèle de langage à partir des seuls documents de cette base, avec leurs sources numérotées. Elles peuvent être inexactes et ne constituent pas un conseil juridique, médical ou financier : vérifiez les sources avant toute décision importante.

Password length and composition

Under SP 800-63B-4, a password used as the only authentication factor must be at least 15 characters long. A password used only as part of multi-factor authentication may be shorter, but never under eight characters.

Verifiers should allow passwords of at least 64 characters and must not impose composition rules such as requiring a mix of character types.

New passwords must be checked against a blocklist of commonly used, expected or compromised values, for example passwords from earlier breaches, dictionary words or the name of the service. If a password is rejected, the user must be told why.

Password changes, hints and password managers

The guideline says verifiers must not require users to change passwords periodically. A change must be forced only when there is evidence the authenticator has been compromised. Note that the older NISTIR 7621 Rev. 1 small-business guide still suggested changing passwords every three months, so the newer authentication guideline is the one to follow on this point.

Password hints accessible to an unauthenticated person are not allowed, nor are security questions such as the name of a first pet. Verifiers must allow password managers and autofill, and should allow pasting when autofill is not available, because password managers help people choose stronger passwords.

Questions fréquentes

Which MFA methods count as phishing-resistant?

SP 800-63B-4 states that passwords, look-up secrets, out-of-band methods and one-time password (OTP) authenticators are not phishing-resistant, because a manually entered code is not bound to the session. Cryptographic authentication can be phishing-resistant when it meets the additional requirements in the guideline.

What does it mean that SMS or voice codes are a restricted authenticator?

At publication, using the public telephone network (SMS or voice) for out-of-band authentication is the only restricted authenticator in the guideline, and accepting it requires the organization to assess, understand and accept its risks. Verifiers should consider risk signals such as a SIM change, device swap or number porting before sending a code that way.

What is the difference between AAL1 and AAL2?

AAL1 gives basic confidence and accepts single-factor authentication, although verifiers should offer MFA options and encourage their use. AAL2 gives high confidence and requires proof of two distinct authentication factors, and applications at AAL2 must offer a phishing-resistant option.

Pour les développeurs et les agents

Intégrer / API / MCP

Branchez cette base à Claude, Cursor, ChatGPT ou votre propre application. Chaque requête API ou MCP coûte 0,10 €, débitée de votre crédit Kopik (non facturée si rien n'est trouvé). Il vous faut une clé API : créez-la depuis votre tableau de bord.

MCP pour vos agents

Adresse du serveur MCP de cette base (outils ask_base et search_base) :

URL MCP
https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity
Claude Code, Cursor et autres clients
Claude Code
claude mcp add --transport http kopik-nist-csf-2-small-business-cybersecurity "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity" --header "Authorization: Bearer kpk_…"
Configuration JSON (mcpServers)
{
  "mcpServers": {
    "kopik-nist-csf-2-small-business-cybersecurity": {
      "url": "https://kopik.io/api/mcp?base=nist-csf-2-small-business-cybersecurity",
      "headers": {
        "Authorization": "Bearer kpk_…"
      }
    }
  }
}

API REST pour vos applications

mode vaut "answer" (réponse rédigée + sources) ou "passages" (passages bruts seulement). Ajoutez un maxPriceCents facultatif pour plafonner le prix : si la base coûte plus cher, l'appel est refusé sans rien débiter.

curl
curl -X POST https://kopik.io/api/v1/bases/nist-csf-2-small-business-cybersecurity/query \
  -H "Authorization: Bearer kpk_…" \
  -H "Content-Type: application/json" \
  -d '{"question": "Votre question ici", "mode": "answer"}'

Pour commencer

  1. Créez une clé dans votre tableau de bord et rechargez votre crédit.
  2. Remplacez kpk_… par votre clé.
  3. Tout le détail (réponses, erreurs, exemples JS et Python) : documentation développeurs.