A complete guide to the new 2025 NIST password guidelines – Proton
proton.me
proton.me
> 3.1.1.2 Password Verifiers
> ...
> 2. Verifiers and CSPs SHOULD permit a maximum password length of at least 64 characters.
In other words, if you want to put a max length, don't put 20, put at least 64.