A draft draft of the National Institute of Standards and Technologys (NIST’s) digital identity guidelines has met with approval by vendors. The draft guidelines revise password security recommendations and altering many of the standards and best practices security professionals use when forming policies for their companies. The new framework recommends, among other things:Remove periodic password change requirements. Require screening of new passwords against lists of commonly used or compromised passwords. NIST is excited to introduce password storage requirements, which makes an offline attack much harder.”]
Source: https://www.csoonline.com/article/3195181/vendors-approve-of-nist-password-draft.html

