The Complete Password Security Checklist
A checklist format works well for password security precisely because the individual steps are simple even though there are a lot of them. Here's a complete, practical checklist, organized so you can work through it without getting overwhelmed.
Foundation: get the tools in place
- ☐ Choose and install a password manager.
- ☐ Set one strong, memorable master passphrase for it.
- ☐ Store that master passphrase's backup somewhere physically secure, separate from your devices.
High-priority accounts first
- ☐ Change your email password to a unique, generated one.
- ☐ Enable two-factor authentication on email.
- ☐ Change your banking password(s) to unique, generated ones.
- ☐ Enable every security feature your bank offers (alerts, MFA).
- ☐ Secure your password manager account itself with MFA if supported.
Work through remaining accounts
- ☐ Social media accounts — unique password, app-based MFA.
- ☐ Shopping and payment-linked accounts — unique password, remove saved cards you don't actively use.
- ☐ Work accounts — unique password, follow any organizational policy in place.
- ☐ Gaming and entertainment accounts — unique password, especially if a payment method is linked.
Verification pass
- ☐ Run your most important passwords through a breach checker.
- ☐ Run any password you're unsure about through a strength checker.
- ☐ Review connected third-party apps on your email and social accounts.
- ☐ Check for unfamiliar forwarding rules on your email account.
Habits going forward
- ☐ Let your password manager generate new passwords for every new account you create.
- ☐ Change a password immediately upon any breach notification or suspicious activity, not on a fixed schedule otherwise.
- ☐ Revisit this checklist roughly once a year.
Frequently asked questions
How long does it take to work through this entire checklist?
The foundation and high-priority sections typically take under an hour combined. Working through every remaining account can take longer depending on how many you have, but there's no requirement to finish everything at once.
Should I redo this checklist periodically?
A yearly review is a reasonable cadence, along with an immediate re-check of any specific account following a breach notification.
What if I don't have a password manager yet?
Start there — it's the foundation that makes every other step in this checklist practical to maintain long-term, rather than a one-time cleanup that gradually erodes back into reuse.
Is this checklist different for a business setting?
The individual-account steps are similar, but a business should also have a written policy and an offboarding process for departing employees — see our small business security guide for that additional layer.
Which items on this list matter most if I'm short on time?
The foundation section and the email/banking items in the high-priority section address the large majority of realistic risk on their own.
Should I print this checklist or track it digitally?
Either works — some people prefer a physical copy to check off by hand, while others prefer a note or task-manager entry. What matters is actually working through it, not the format.
What should I do after completing the entire checklist?
Set a reminder to revisit it in about a year, and check any specific account immediately if you receive a breach notification in the meantime, rather than waiting for the scheduled review.
Conclusion
A checklist turns password security from an abstract goal into a concrete, completable set of steps. Work through it in order — foundation, then high-priority accounts, then everything else — and you'll cover the overwhelming majority of realistic risk.
Related articles
20 Password Security Tips You Can Use Today
Twenty specific, actionable password security tips you can put into practice today, ranked roughly by how much impact each one has.
Read article →How to Keep Your Online Accounts Secure
A complete, layered checklist that ties passwords, 2FA, and safe habits into one system.
Read article →Multi-Factor Authentication Explained
Multi-factor authentication goes beyond passwords entirely. Here's what the different factor types actually are, and why combining them work
Read article →Password Managers Explained
How encrypted vaults work, whether they're actually safe, and how to choose the right type for you.
Read article →Free tools for this guide
Password Generator
Create a strong, random password in one click, right in your browser.
Open tool →Password Strength Checker
See entropy, crack-time estimates, and tips for any password you type.
Open tool →Passphrase Generator
Build a memorable Diceware-style passphrase with real entropy behind it.
Open tool →Username Generator
Memorable, random usernames for new accounts, games, and forums.
Open tool →PIN Generator
Random numeric PINs with optional repeating and sequential-digit avoidance.
Open tool →Random String Generator
Fully random strings for API keys, tokens, coupon codes, and test data.
Open tool →Hash Generator
Generate MD5, SHA-1, SHA-256, SHA-384, and SHA-512 hashes instantly.
Open tool →Base64 Encoder / Decoder
Convert text to and from Base64 instantly, with full Unicode support.
Open tool →UUID Generator
Generate RFC 4122 v4 UUIDs, one at a time or in a batch.
Open tool →Password Breach Checker
Check if a password has appeared in a known data breach, privately.
Open tool →Password Policy Generator
Generate a clear organizational password policy from NIST-style presets.
Open tool →