NetSuite Minimum Password Length and PCI Rules
Set NetSuite password length within policy limits, understand Customer Center treatment, and apply PCI rules for sensitive permissions.
The Minimum Password Length field sets the minimum number of characters required for user passwords. Configure it at Setup > Company > General Preferences, where the selected password policy sets the lowest value you can enter. Customer Center users and users with PCI-sensitive permissions follow important exceptions that administrators should account for.
Where do you configure Minimum Password Length?
Administrators can modify password settings at Setup > Company > General Preferences. This area includes the password policy, Minimum Password Length, and Password Expiration in Days settings.
The Minimum Password Length value is a character-count requirement. It works with, rather than replaces, the selected password policy: the policy establishes the minimum acceptable value for the field. The policy does not affect the Password Expiration in Days value.
How does the password policy set the length floor?
NetSuite provides four built-in password policies. Each policy specifies a minimum length and, except for Weak, content requirements based on uppercase letters, lowercase letters, numbers, and non-alphanumeric ASCII characters.
| Password policy | Minimum length | Character-type requirement |
|---|---|---|
| Very strong | 10 characters | All four character types |
| Strong | 10 characters | At least three of the four character types |
| Medium | 8 characters | At least two of the four character types |
| Weak (Not Recommended) | 6 characters | No additional character-type requirement stated |
All NetSuite accounts use the Strong policy by default. As a result, the default Minimum Password Length is 10 characters.
You can increase the Minimum Password Length beyond the policy minimum. You cannot set it below that minimum. For example, a Strong policy permits a value greater than 10 characters, but not a value below 10.
It is possible to change the password policy to Medium or Weak. Oracle notes that moving to a less strict policy weakens account security. Review both the character-count requirement and the character-type requirement before changing the selected policy.
Additional, thorough guidance on NetSuite Password Policy Settings and PCI Rules can help you align security and compliance.
How are Customer Center users handled?
Customer Center treatment differs from the password-policy rules for other NetSuite users. The selected password policy is not applied to users who log in with a Customer Center role or to customers who register on a website.
The minimum password length for Customer Center roles is eight characters.
Employee, partner, and vendor roles are non-Customer Center roles. Customers use Customer Center roles. One person can use the same email address for a non-Customer Center role and a Customer Center role, but NetSuite treats them as two different users because the information is maintained separately. Changing the password for non-Customer Center roles does not change the password for the Customer Center role.
This distinction matters when reviewing access populations. A password change or password-policy decision for an employee, partner, or vendor does not automatically establish the password of a separately maintained Customer Center user with the same email address.
What happens when a user can access multiple accounts?
A user is defined as an email-and-password pairing. If that user has access to multiple NetSuite accounts with different password policies, NetSuite enforces the strongest policy for that user.
This is separate from the Customer Center distinction. The same email address can represent separately maintained Customer Center and non-Customer Center users, while a single email-and-password pairing with access to multiple accounts is subject to the strongest applicable password policy.
How do PCI requirements change password length?
PCI password requirements take precedence when users have either of these permissions:
- View Unencrypted Credit Cards
- View Unencrypted ACH Account Numbers
Passwords for users with either permission must contain at least 12 characters. If the Minimum Password Length value on General Preferences is greater than 12, the greater company requirement remains in effect.
PCI also affects expiration. These users must change passwords at least every 90 days. If Password Expiration in Days is set to fewer than 90 days, the shorter company requirement remains in effect. If the company setting is longer than 90 days, it automatically becomes 90 days for users with either permission.
All users with access to unencrypted credit card numbers or unencrypted ACH accounts must change passwords to comply with the PCI requirements. Administrators should therefore identify users assigned either permission when evaluating a change to the company password settings.
How can administrators prompt password changes?
The Password Expiration in Days field specifies how many days a password remains valid before the user is prompted to change it. Valid values are 1 through 365, and the default is 180 days. The calculation is based on the date each user last changed a password, not on the date the company preference changes.
For employee records, administrators can select Require Password Change on Next Login to prompt employees to change passwords at their next login. CSV import can update this option for multiple employee records at the same time.
In most cases, password changes are self-service. A user can select Forgot Your Password? on the NetSuite login page and receives an email link to reset the password; that link expires after 60 minutes. Administrators can also use the User Access Reset Tool to assist users who cannot reset a password, update security questions, change a two-factor authentication device, or are locked out after five consecutive incorrect passwords.
Further configuration tips and deeper policy details are available in our guide to NetSuite Password Policy Settings and PCI Rules.
Which related settings should you review?
| Setting | What the source establishes |
|---|---|
| Password Policy | Sets the minimum acceptable value for Minimum Password Length and defines the policy's length and character-type requirements. It does not affect Password Expiration in Days. |
| Minimum Password Length | Specifies the minimum number of characters required for user passwords. It can be higher than, but not lower than, the policy minimum. |
| Password Expiration in Days | Sets password validity before a user is prompted to change it. Valid values are 1–365; the default is 180 days. |
| Require Password Change on Next Login | Can be selected on employee records to prompt a password change at next login; CSV import can update it for multiple employee records. |
Who This Affects
- Administrators: Configure the password policy, minimum length, and password-expiration settings under General Preferences.
- Employees, partners, and vendors: Use non-Customer Center roles and are within the population affected by the password-policy discussion.
- Customer Center users: Have an eight-character minimum password length, while the selected password policy does not apply to their logins.
- Users with unencrypted payment-data permissions: Must meet the PCI 12-character minimum and the 90-day password-change requirement unless the company expiration setting is shorter.
- Users with access to multiple accounts: Are subject to the strongest password policy among those accounts for the same email-and-password pairing.
Key Takeaways
- Configure password settings at Setup > Company > General Preferences.
- The selected policy establishes the lowest allowed Minimum Password Length; the field can be set higher, not lower.
- Strong is the default policy, so the default minimum password length is 10 characters.
- Customer Center roles have an eight-character minimum, and the selected password policy does not apply to Customer Center logins or website customer registration.
- Users with access to unencrypted credit card or ACH account information require at least 12-character passwords; a higher company minimum still applies.
- Password expiration is configured separately from password policy, and PCI-affected users must change passwords at least every 90 days unless the company setting is shorter.
Frequently Asked Questions (4)
Where do I configure the Minimum Password Length, and can I set it lower than the selected password policy?
Does the selected password policy apply to Customer Center users and customers who register on a website?
What are the PCI-related password length and expiration requirements for users with payment-data permissions?
How can administrators prompt password changes and what are the password-expiration settings I should know?
Was this article helpful?
More in Authentication
- OpenID Connect (OIDC) Configuration in NetSuite
OpenID Connect (OIDC) enables secure access to NetSuite web stores, improving user security management.
- Single Sign-On Only Role Configuration in NetSuite
Configure Single Sign-On Only roles in NetSuite to ensure users can access accounts solely through OIDC SSO.
- Outbound Single Sign-on Deprecation and Alternatives in NetSuite
Outbound Single Sign-on (SuiteSignOn) is deprecated in NetSuite 2024.1, affecting authentication processes.
- Credentials File Management in NetSuite 2026.1
Manage credentials file errors in NetSuite 2026.1, ensuring proper permissions and passkey handling for smooth authentication.
Advertising
Reach Authentication Professionals
Put your product in front of NetSuite experts who work with Authentication every day.
Sponsor This Category