HabrAugust 10, 2026🇷🇺Translated from Russian

NIST Bans Periodic Password Rotation While Russia's FSTEC Mandates 90-Day Changes for Government Systems

In July 2025, NIST released the final edition of SP 800-63B, its core digital authentication guideline. Section 3.1.1.2 now states that verifiers and CSPs SHALL NOT require subscribers to change passwords periodically, upgrading the previous soft recommendation to a firm prohibition.

In April 2026, FSTEC approved a methodological document requiring passwords in government information systems and critical information infrastructure objects to be rotated at least every 90 days. Mobile devices face a stricter 30-day limit, and reuse of any of the last 12 passwords is forbidden.

Order No. 117 itself contains zero references to passwords. The order lists high-level protection measures, while concrete parameters such as length, complexity, and rotation periods are defined in subordinate methodological documents.

Three-layer document structure

The binding requirement appears only in the third document: the April 2026 methodological guide titled “Composition and Content of Information Protection Measures.” Measure IAF.3 explicitly mandates a minimum 12-character password, a 70-character alphabet, five failed attempts before lockout, 15-minute lockout duration, and rotation no later than 90 days. Measure ZMU.1 sets the 30-day mobile rule.

  • Order No. 117 (April 2025, effective March 2026): no password mentions
  • November 2025 KZI assessment methodology: checks complexity only
  • April 2026 methodological document: full rotation requirements in IAF.3 and ZMU.1

Point 68 of Order No. 117 makes the methodological documents mandatory by requiring operators to implement measures “using FSTEC methodological documents.” Ignoring the guide therefore violates the registered order itself.

Commercial organizations outside government systems and CII subjects are not bound by the 90/30-day rules and may choose policies based on their own threat models, provided they document the rationale.

Related articles

HabrPolicy & Regulation

Rethinking SSO: Centralized User Data Provision and Authorization Processing in Corporate Systems

The article examines Single Sign-On systems not merely as authentication gateways but as architectural hubs for delivering user attributes and executing additional authorization logic. It highlights how SSO can aggregate data from sources like Active Directory, HR systems, and IDM platforms, then deliver it via OIDC claims to downstream applications. The discussion covers the shift from fragmented integrations across dozens of apps to a single trusted enforcement point using standards such as aggregated and distributed claims. It also explores the authorization pipeline where SSO acts as a Policy Enforcement Point querying external Policy Decision Points via the AuthZEN Authorization API 1.0. Practical examples include electronic business cards, role assignment, access routing, and mandatory MFA checks before token issuance. The piece stresses maintaining data ownership with source systems while establishing SSO as the single point of trust for applications.

AntiMalwarePolicy & Regulation

Bitrix24 Releases Fully On-Premise BI Constructor for Regulated Enterprises

Bitrix24 has introduced a new delivery model for its BI Constructor that allows complete deployment inside a customer's own infrastructure. The update eliminates any requirement for external servers, cloud APIs, or internet connectivity, ensuring that all corporate data remains within the organization's closed perimeter. Previously, even the boxed version of the platform needed access to external infrastructure for updates and auxiliary services, creating conflicts with internal security policies and regulatory demands in highly regulated sectors. The new on-premise variant performs all data processing and storage exclusively on customer servers, giving organizations full control over access rights, backups, updates, and integration with internal protection tools. The solution is compatible with the boxed edition of Bitrix24 running on PostgreSQL and does not connect to external CDNs or cloud services. Bitrix24 expects strong interest from large enterprises and organizations handling restricted-access data that must stay inside the corporate network. Pilot implementations have already been completed, with broader customer pilots planned in the coming months.

HabrPolicy & Regulation

Russia's Data Leak Penalties: 2.6 Million Rubles in Fines Despite 1.58 Billion Records Exposed in 2025

Russia introduced turnover-based fines for personal data leaks through Federal Law 420-FZ in late 2024, fundamentally altering the economics of information security investments. Over the first 18 months, Roskomnadzor opened 52 administrative investigations and issued 40 protocols totaling just 2.6 million rubles in penalties, with zero turnover fines applied. This occurred against a backdrop of 1.58 billion compromised records in 2025 alone. Public data leaks dropped fourfold in the first half of 2026, yet trading activity on underground forums rose nearly 60 percent as operators shifted to private sales. The law now ties penalties directly to the number of affected individuals and adds a turnover component for repeat violations under Article 13.11 of the Code of Administrative Offenses. Analysts note that the mere threat of larger fines has prompted companies to reassess data retention policies and risk models even without actual enforcement precedents.

AntiMalwarePolicy & Regulation

Russia Authorizes Temporary State Takeover of Unprotected Critical Infrastructure

President Vladimir Putin has signed a decree that empowers the Russian government to appoint temporary managers for critical infrastructure facilities whose owners have failed to ensure adequate security. The measure directly targets operators of objects classified as critical infrastructure who have not met protection requirements. Under the new rules, the state can intervene by installing an interim administrator to oversee operations until security standards are satisfied. This approach aims to prevent potential disruptions or threats arising from insufficiently defended assets. The decree provides a legal mechanism for rapid governmental response without permanent nationalization of the facilities. It reflects ongoing efforts to strengthen oversight of sectors deemed essential to national security and stability.