It would be more complicated to do this once you stored millions of passwords.
So now you have to create 2 flows, those before the new policy and those that were set after the normalization.
So now you have to create 2 flows, those before the new policy and those that were set after the normalization.
If you're actually using a 'strong enough' hash to prevent easy cracking if your hashed password database is leaked then you're doubling the server load which can be quite substantial in some cases.
And obviously this is server side
https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpubli...