Authentication_Cheat_Sheet: password rules which only apply to US-ASCII. That means people with non-US keyboards may not even be able to set a password which meet the rules (eg. Θ and ẞ are upper case, but does not count as upper case in their suggested rules).
Password_Storage_Cheat_Sheet: misses the critical step of unicode canonicalisation and encoding before feeding the password into the slow one-way function (which invariably take an octet string, not textual strings). If you fail to do this, your system will spuriously reject correct passwords if the user logs in via different devices or input methods.
Password_Storage_Cheat_Sheet: '32-bit or 64b' length salt is certainly too short to be called cryptographically strong. Particularly, a 32-bit salt is not enough to avoid leaking password equality with good probability between users once you get past the birthday bound.
Password_Storage_Cheat_Sheet: implies that the caller is responsible for prepending the salt to the credential before inputting it into the slow one-way function. That's not how PBKDF2, scrypt or bcrypt work.