HabrAugust 10, 2026🇷🇺Translated from Russian

NIST Bans Periodic Password Rotation While Russia's FSTEC Mandates 90-Day Changes for Government Systems

In July 2025, NIST released the final edition of SP 800-63B, its core digital authentication guideline. Section 3.1.1.2 now states that verifiers and CSPs SHALL NOT require subscribers to change passwords periodically, upgrading the previous soft recommendation to a firm prohibition.

In April 2026, FSTEC approved a methodological document requiring passwords in government information systems and critical information infrastructure objects to be rotated at least every 90 days. Mobile devices face a stricter 30-day limit, and reuse of any of the last 12 passwords is forbidden.

Order No. 117 itself contains zero references to passwords. The order lists high-level protection measures, while concrete parameters such as length, complexity, and rotation periods are defined in subordinate methodological documents.

Three-layer document structure

The binding requirement appears only in the third document: the April 2026 methodological guide titled “Composition and Content of Information Protection Measures.” Measure IAF.3 explicitly mandates a minimum 12-character password, a 70-character alphabet, five failed attempts before lockout, 15-minute lockout duration, and rotation no later than 90 days. Measure ZMU.1 sets the 30-day mobile rule.

  • Order No. 117 (April 2025, effective March 2026): no password mentions
  • November 2025 KZI assessment methodology: checks complexity only
  • April 2026 methodological document: full rotation requirements in IAF.3 and ZMU.1

Point 68 of Order No. 117 makes the methodological documents mandatory by requiring operators to implement measures “using FSTEC methodological documents.” Ignoring the guide therefore violates the registered order itself.

Commercial organizations outside government systems and CII subjects are not bound by the 90/30-day rules and may choose policies based on their own threat models, provided they document the rationale.

Related articles

HabrPolicy & Regulation

EU Extends Chat Control 1.0 Regulation to 2028 Despite Privacy Concerns and Parliamentary Opposition

The EU Council has extended Regulation (EU) 2021/1232, known as Chat Control 1.0, allowing voluntary scanning of unencrypted messages by providers such as Discord and Gmail until 2028. The measure targets detection of child sexual abuse material but has drawn criticism for its impact on encryption and privacy. A proposed Chat Control 2.0 version under COM(2022) 209 would mandate scanning of encrypted communications, which critics argue undermines end-to-end encryption. The extension passed after a July 2026 European Parliament vote failed to reach the required majority due to absent lawmakers. Investigations revealed lobbying ties between Commissioner Ilva Johansson's office and organizations including Thorn and WeProtect Global Alliance. The European Data Protection Supervisor found that targeted advertising supporting the regulation violated EU data rules.

HabrPolicy & Regulation

Web Certificate Trust Chains and State Access Risks Explained Amid Russian Banking Sanctions

The article explains the hierarchical structure of web certificates used for site authentication and traffic encryption, starting from highly protected root certificates stored in air-gapped facilities with Shamir's secret sharing for key protection. Intermediate certificates extend the chain of trust down to leaf certificates deployed on websites. Russian banks have turned to certificates issued under the MinTsifry root after Western and Chinese CAs refused service due to sanctions. The piece highlights that any nation-state with access to a root private key, whether FSB, NSA, or others, could theoretically issue fraudulent certificates for any domain. It notes the limitations of the X.509 standard, which lacks native support for multi-CA signatures, and suggests that separate browsing environments or PGP-style web-of-trust models could mitigate risks. The author concludes that security is already reduced by reliance on any state-controlled CA and that the choice is ultimately which intelligence agency one prefers to trust.

AntiMalwarePolicy & Regulation

MAX Messenger to Open Source Code and Launch Developer Program for Alternative Clients

The Russian messenger MAX is preparing to open its platform to third-party developers by launching a dedicated developer program and providing API access. Approved participants will receive the official client's source code, design system, technical documentation, and access tokens to integrate with the platform infrastructure. The initiative targets IT companies from Russia and friendly countries that demonstrate experience with large-scale projects and adherence to strict security standards. All selected developers must implement secure development practices, robust encryption mechanisms, and undergo code audits to protect user data. The program supplies ready-made user registration and anti-fraud tools, while alternative clients remain bound by API usage terms focused on security compliance. Applications will be accepted via the official developer portal, although exact launch dates have not yet been disclosed.

HabrPolicy & Regulation

InfoWatch Details ARMA Wall NGFW Development for Industrial Systems Under Russian Import Substitution Rules

InfoWatch has published the second part of its interview series describing the ongoing development of the ARMA Wall next-generation firewall for industrial control systems. The product prioritizes on-premise processing without cloud agents to meet strict customer security policies and certification requirements. Engineers combine proprietary detection feeds with external sources, including indicators from NKCKI, while maintaining hundreds of thousands of signatures without disabling legacy rules for older Siemens controllers. Migration support relies on manual pre-project audits rather than automated tools, and the company works closely with domestic SCADA vendors to embed NGFW capabilities inside long-lifecycle OT environments. ARMA Wall is positioned as a more flexible and cost-effective alternative to data diodes because it allows granular command-level filtering and can emulate one-way traffic when required. The solution is already deployed at Roscosmos subsidiary RKK Energia after full certification and categorization.