July 28, 2026

    Why Blumira No Longer Requires 90-Day Password Changes

    The short version: Blumira no longer forces you to change your password every 90 days. Modern protections like passkeys, breached-password detection, and enforced multi-factor authentication (MFA) protect your account far better than routine password resets ever could. This change follows current NIST guidance, keeps you aligned with PCI DSS 4.0, and makes accounts more secure, not less.

    What changed

    We have removed the 90-day password expiration and forced-rotation requirement from the Blumira app. You will no longer be prompted to reset your password on a fixed schedule. You can still change your password at any time, and we will still require a change if we ever detect that your credentials may be compromised.

    Why we made this change

    Scheduled password rotation was designed for a time before strong multi-factor authentication and real-time breach monitoring existed. Today, Blumira protects your account with layered, modern controls that address the ways accounts actually get compromised. A calendar-based password reset could never do that.

    Passkeys and advanced authentication

    Blumira supports passkeys, a phishing-resistant sign-in method built on the FIDO2/WebAuthn standard. A passkey replaces a typed password with a cryptographic key that stays on your device and is unlocked by your fingerprint, face, or device PIN. There is no shared secret to steal, phish, or reuse, which removes the single biggest reason forced rotation ever existed.

    Breached-password detection

    When you set or change your password, Blumira checks it against large databases of known-breached and commonly used credentials. If the password appears in a known breach or on a common-password list, we will not let you use it. This targets the real risk, a password that is actually exposed, instead of assuming every password becomes dangerous simply because 90 days have passed.

    Enforced multi-factor authentication (MFA)

    Blumira enforces strong MFA on accounts, so a password by itself is never enough to sign in. Even if a password were stolen, an attacker still could not reach your account without your second factor. As explained below, this is also what keeps the change compliant.

    How your account is protected now

    Risk

    What forced 90-day rotation did

    What Blumira does now

    Stolen or phished password

    Little, since the password stayed valid for up to 90 days

    MFA and passkeys make a password alone useless to an attacker

    Password exposed in a data breach

    Nothing. You only changed it on schedule

    Breached-password detection blocks or flags it right away

    Weak or reused password

    Nothing, and often made it worse (see below)

    Blocked at creation by breached/common-password screening, with passphrase guidance

    Does this affect PCI compliance?

    No. Under PCI DSS 4.0 (v4.0.1), the 90-day password-change rule in Requirement 8.3.9 applies only to accounts where a password is the single authentication factor. For those accounts, the standard gives two options: change the password every 90 days, or dynamically analyze the account's security posture and control access in real time.

    Because Blumira enforces MFA, a password is no longer the only factor protecting your account, so the 90-day requirement in 8.3.9 does not apply. Combined with breached-password monitoring, you stay aligned with PCI DSS 4.0 without routine rotation.

    Why frequent rotation actually weakens security

    Security researchers have shown for years that forcing frequent password changes tends to reduce security rather than improve it. When people are made to change passwords on a schedule, they tend to pick weaker starting passwords and then modify them in small, predictable ways.

    The U.S. Federal Trade Commission put it plainly: users required to change passwords frequently “select weaker passwords to begin with, and then change them in predictable ways that attackers can guess easily.” A widely cited University of North Carolina study found that once an attacker knew one of a user's previous passwords, they could guess the next one within a handful of tries about 17% of the time, because people rotate in patterns like Spring2025Summer2025, or Pumpkin1!Pumpkin2!Pumpkin3!.

    This is why NIST's current digital identity guidance (SP 800-63B) directs organizations not to require periodic password changes, and to force a reset only when there is evidence that a password has been compromised.

    What we recommend instead: use a passphrase

    The most effective thing you can do for a password today is make it long. Length beats complexity. A passphrase, several random words strung together, is both far harder to crack and far easier to remember than a short, symbol-heavy password.

    • Use four or more random words, for example correct-battery-harbor-melon. NIST favors length and supports passwords up to at least 64 characters, including spaces.
    • Aim for at least 15 characters. The longer the passphrase, the stronger it is.
    • Make it unique to Blumira. Never reuse a password from another site.
    • Use a password manager to generate and store long, unique passwords so you do not have to memorize them.
    • Enroll a passkey if your device supports it. It is the strongest and simplest option.
    • Keep MFA enabled. It is your single most important protection against account takeover.

    What you need to do

    Nothing is required. Your current password will keep working, and you will not be prompted to reset it on a schedule. When you are ready, we encourage you to switch to a long passphrase or enroll a passkey, and to keep MFA enabled. If we ever detect that a credential may be compromised, we will prompt you to change it.

    References

    Tag(s): Product Updates

    Mike Toole

    Mike Toole, Head of Security and IT at Blumira, has over a decade of experience in IT. Prior to joining Blumira, he managed IT for Duo Security and Censys. He has broad experience with a range of IT and security focus areas, including compliance, network design, log monitoring, project management, and cross-platform...

    More from the blog

    View All Posts