TL;DR: NIST says passwords should be at least 15 characters with no forced rotation, CISA calls FIDO/WebAuthn the only widely available phishing-resistant MFA, and SMS codes are a last resort. A password manager plus app-based or key-based MFA covers most people.

👉 Check my digital footprint — free 30-second check →

Instead of ranking apps, this guide sets out what the standards bodies and regulators actually say about the four tools that protect logins: password managers, authenticator apps, passkeys and hardware security keys. Pick any product that meets these points.

Passwords and password managers

NIST's current digital identity guidelines say passwords used alone should be at least 15 characters, that services should allow at least 64, and that they should not impose composition rules such as mixed character types or force periodic changes. They should check new passwords against a list of common or compromised ones, and should allow password managers and pasting. The FTC advises at least 12 characters and using a third-party password manager. The UK's NCSC says a password manager lets you use a unique password for every service, and advises turning on 2-step verification for the manager itself. Many managers offer recovery options such as secure hints or emergency access through trusted contacts, so set one up before you need it. Some managers alert you to weak, reused or leaked passwords. See the strong password system guide and how to check if your password has leaked.

The MFA ladder

CISA says users who enable MFA are significantly less likely to be hacked, and that any MFA is better than none. Its ranking is more specific:

CISA and partner agencies also note that SMS messages are not encrypted and can be read by a threat actor with access to a carrier's network, and suggest authenticator apps such as Google Authenticator, Microsoft Authenticator or Authy as alternatives for less critical accounts. The FTC lists three types of two-factor authentication: a one-time code by text or email, an authenticator app, and a security key. Step-by-step setup is in the two-factor authentication guide.

Hardware security keys

The FTC describes security keys as physical devices used as a second factor. They use encryption to confirm the key is associated with your account, and the FTC calls them the strongest method of two-factor authentication. The ACSC recommends creating a backup passkey on a second FIDO2 security key in case the first is lost, stolen or damaged. Buy two, register both, and keep one somewhere safe.

Passkeys

The FIDO Alliance defines a passkey as a credential based on FIDO standards that can be stored on a phone, a computer or a hardware key, and used with the same process you use to unlock the device. It calls passkeys phishing-resistant, with no passwords to steal. Synced passkeys are end-to-end encrypted and available on devices that use the same passkey provider. The NCSC says passkeys cannot be intercepted, reused or stolen like passwords, and that the credential manager backs them up so losing a device should not lock you out. It adds that the strength of the authentication protecting the sync account is the critical safeguard. The ACSC advises avoiding syncing a passkey to untrusted or shared devices.

Backup and lost-device plan

The NCSC says backup codes work even if you lose your phone and each code works only once, and that any 2-step verification is better than none. Set up more than one method. Keep backup codes offline.

A sensible setup

1. Use a password manager with a long unique master password and MFA turned on.

2. Turn on passkeys or app-based MFA for email, banking and the password manager.

3. Add security keys for the accounts you cannot afford to lose.

4. Store backup codes and a spare key offline.

Tools protect accounts, but they cannot un-leak data that is already out. A free digital footprint check shows whether your email or number appears in exposed data.

Frequently Asked Questions

How long should a password be, according to NIST?

NIST's guidelines require single-factor passwords to be at least 15 characters, and say services should not force periodic changes or composition rules.

Are SMS codes safe enough?

CISA says SMS and voice codes are vulnerable to phishing, SS7 and SIM-swap attacks and should be a last resort.

What is the strongest form of MFA?

CISA calls phishing-resistant MFA the gold standard and says FIDO/WebAuthn is the only widely available phishing-resistant authentication. The FTC calls security keys the strongest method.

What is a passkey?

A FIDO-based credential stored on a phone, computer or hardware key and unlocked with your device PIN, biometric or pattern, per the FIDO Alliance.

What if I lose my security key?

The ACSC recommends registering a backup passkey on a second FIDO2 key. The NCSC says backup codes also work if you lose your phone.

Sources

Related Reading