NetSuite Minimum Password Length and PCI Rules

Set NetSuite password length within policy limits, understand Customer Center treatment, and apply PCI rules for sensitive permissions.

·6 min read·1 views·View Oracle Docs

The Minimum Password Length field sets the minimum number of characters required for user passwords. Configure it at Setup > Company > General Preferences, where the selected password policy sets the lowest value you can enter. Customer Center users and users with PCI-sensitive permissions follow important exceptions that administrators should account for.

Where do you configure Minimum Password Length?

Administrators can modify password settings at Setup > Company > General Preferences. This area includes the password policy, Minimum Password Length, and Password Expiration in Days settings.

The Minimum Password Length value is a character-count requirement. It works with, rather than replaces, the selected password policy: the policy establishes the minimum acceptable value for the field. The policy does not affect the Password Expiration in Days value.

How does the password policy set the length floor?

NetSuite provides four built-in password policies. Each policy specifies a minimum length and, except for Weak, content requirements based on uppercase letters, lowercase letters, numbers, and non-alphanumeric ASCII characters.

Password policyMinimum lengthCharacter-type requirement
Very strong10 charactersAll four character types
Strong10 charactersAt least three of the four character types
Medium8 charactersAt least two of the four character types
Weak (Not Recommended)6 charactersNo additional character-type requirement stated

All NetSuite accounts use the Strong policy by default. As a result, the default Minimum Password Length is 10 characters.

You can increase the Minimum Password Length beyond the policy minimum. You cannot set it below that minimum. For example, a Strong policy permits a value greater than 10 characters, but not a value below 10.

It is possible to change the password policy to Medium or Weak. Oracle notes that moving to a less strict policy weakens account security. Review both the character-count requirement and the character-type requirement before changing the selected policy.

Additional, thorough guidance on NetSuite Password Policy Settings and PCI Rules can help you align security and compliance.

How are Customer Center users handled?

Customer Center treatment differs from the password-policy rules for other NetSuite users. The selected password policy is not applied to users who log in with a Customer Center role or to customers who register on a website.

The minimum password length for Customer Center roles is eight characters.

Employee, partner, and vendor roles are non-Customer Center roles. Customers use Customer Center roles. One person can use the same email address for a non-Customer Center role and a Customer Center role, but NetSuite treats them as two different users because the information is maintained separately. Changing the password for non-Customer Center roles does not change the password for the Customer Center role.

This distinction matters when reviewing access populations. A password change or password-policy decision for an employee, partner, or vendor does not automatically establish the password of a separately maintained Customer Center user with the same email address.

What happens when a user can access multiple accounts?

A user is defined as an email-and-password pairing. If that user has access to multiple NetSuite accounts with different password policies, NetSuite enforces the strongest policy for that user.

This is separate from the Customer Center distinction. The same email address can represent separately maintained Customer Center and non-Customer Center users, while a single email-and-password pairing with access to multiple accounts is subject to the strongest applicable password policy.

How do PCI requirements change password length?

PCI password requirements take precedence when users have either of these permissions:

  • View Unencrypted Credit Cards
  • View Unencrypted ACH Account Numbers

Passwords for users with either permission must contain at least 12 characters. If the Minimum Password Length value on General Preferences is greater than 12, the greater company requirement remains in effect.

PCI also affects expiration. These users must change passwords at least every 90 days. If Password Expiration in Days is set to fewer than 90 days, the shorter company requirement remains in effect. If the company setting is longer than 90 days, it automatically becomes 90 days for users with either permission.

All users with access to unencrypted credit card numbers or unencrypted ACH accounts must change passwords to comply with the PCI requirements. Administrators should therefore identify users assigned either permission when evaluating a change to the company password settings.

How can administrators prompt password changes?

The Password Expiration in Days field specifies how many days a password remains valid before the user is prompted to change it. Valid values are 1 through 365, and the default is 180 days. The calculation is based on the date each user last changed a password, not on the date the company preference changes.

For employee records, administrators can select Require Password Change on Next Login to prompt employees to change passwords at their next login. CSV import can update this option for multiple employee records at the same time.

In most cases, password changes are self-service. A user can select Forgot Your Password? on the NetSuite login page and receives an email link to reset the password; that link expires after 60 minutes. Administrators can also use the User Access Reset Tool to assist users who cannot reset a password, update security questions, change a two-factor authentication device, or are locked out after five consecutive incorrect passwords.

Further configuration tips and deeper policy details are available in our guide to NetSuite Password Policy Settings and PCI Rules.

Which related settings should you review?

SettingWhat the source establishes
Password PolicySets the minimum acceptable value for Minimum Password Length and defines the policy's length and character-type requirements. It does not affect Password Expiration in Days.
Minimum Password LengthSpecifies the minimum number of characters required for user passwords. It can be higher than, but not lower than, the policy minimum.
Password Expiration in DaysSets password validity before a user is prompted to change it. Valid values are 1–365; the default is 180 days.
Require Password Change on Next LoginCan be selected on employee records to prompt a password change at next login; CSV import can update it for multiple employee records.

Who This Affects

  • Administrators: Configure the password policy, minimum length, and password-expiration settings under General Preferences.
  • Employees, partners, and vendors: Use non-Customer Center roles and are within the population affected by the password-policy discussion.
  • Customer Center users: Have an eight-character minimum password length, while the selected password policy does not apply to their logins.
  • Users with unencrypted payment-data permissions: Must meet the PCI 12-character minimum and the 90-day password-change requirement unless the company expiration setting is shorter.
  • Users with access to multiple accounts: Are subject to the strongest password policy among those accounts for the same email-and-password pairing.

Key Takeaways

  • Configure password settings at Setup > Company > General Preferences.
  • The selected policy establishes the lowest allowed Minimum Password Length; the field can be set higher, not lower.
  • Strong is the default policy, so the default minimum password length is 10 characters.
  • Customer Center roles have an eight-character minimum, and the selected password policy does not apply to Customer Center logins or website customer registration.
  • Users with access to unencrypted credit card or ACH account information require at least 12-character passwords; a higher company minimum still applies.
  • Password expiration is configured separately from password policy, and PCI-affected users must change passwords at least every 90 days unless the company setting is shorter.

Frequently Asked Questions (4)

Where do I configure the Minimum Password Length, and can I set it lower than the selected password policy?
Set Minimum Password Length at Setup > Company > General Preferences alongside Password Policy and Password Expiration in Days. The Minimum Password Length is a character-count requirement that works with the selected policy: the policy establishes the minimum allowed value, so you can increase the field above the policy minimum but cannot set it below that minimum.
Does the selected password policy apply to Customer Center users and customers who register on a website?
No. The selected password policy does not apply to Customer Center role logins or to customers who register on a website; Customer Center roles have an eight-character minimum. Customer Center users are maintained separately from employee/partner/vendor (non-Customer Center) roles, so changing a non-Customer Center password does not change a separately maintained Customer Center password even if the email address is the same.
What are the PCI-related password length and expiration requirements for users with payment-data permissions?
Users with either the View Unencrypted Credit Cards or View Unencrypted ACH Account Numbers permission must have passwords of at least 12 characters; if the company Minimum Password Length is greater than 12, that higher value remains in effect. PCI also requires these users to change passwords at least every 90 days: if the company Password Expiration in Days is shorter, the shorter setting applies; if it is longer, it becomes 90 days for those users.
How can administrators prompt password changes and what are the password-expiration settings I should know?
Password Expiration in Days (valid values 1–365, default 180) determines when users are prompted to change passwords and is calculated from each user’s last password change, not the date the company preference changed. Administrators can set Require Password Change on Next Login for employee records (and update many records via CSV import); users can also use Forgot Your Password? (reset link expires after 60 minutes), and admins can assist with the User Access Reset Tool for resets, security questions, two-factor device changes, or lockouts.
Source: Minimum Password Length Field Oracle NetSuite Help Center. This article was generated from official Oracle documentation and enriched with additional context and best practices.

Was this article helpful?

More in Authentication

View all Authentication articles →