Essential cookies only — Cookie Policy.

Policy

Writing a Password Policy for a Small Business

📅 30 Apr 2026·⏱ 8 min·✍ Rachel Morris

A password policy is a documented statement of your organisation's requirements for credential management. For most SMEs it is a one-to-two-page document that belongs in the staff handbook, the security policy, or both. Writing one is neither difficult nor time-consuming — but skipping it creates gaps in Cyber Essentials compliance, complicates insurance claims after incidents, and leaves staff without clear expectations.

What to Include

A complete SME password policy covers six areas:

  1. Scope: Which accounts and systems this policy applies to (all company accounts, cloud services, shared systems)
  2. Password requirements: Generated by the company password manager; minimum length; no personal information; unique per system
  3. Password manager: Which tool is designated, that all staff must use it for work credentials, how to get access
  4. MFA requirements: Which accounts require MFA and the accepted methods
  5. Change requirements: When passwords must be changed (on security concern, on a service breach notification, not on a fixed schedule)
  6. Prohibited actions: Sharing credentials, writing in plaintext, reusing personal passwords, emailing credentials

What to Avoid

Use the Policy Builder: The Work Password Policy Builder generates a ready-to-copy policy paragraph based on your chosen settings — including Cyber Essentials compliance status for each configuration.
password policy SME documentation Cyber Essentials HR
For informational purposes only. Consult a qualified IT security professional for advice specific to your organisation.

⚡ Try NordPassGet NordPass at 56% off + 3 months extra and experience enterprise-grade password security at an affordable price. Features include zero-knowledge encryption, cross-platform sync, and breach monitoring.