Compliance
KeyCare Pass and NIST guidance
NIST's digital identity guidelines and its Cybersecurity Framework are widely used references, inside and outside the United States. Here is where KeyCare Pass fits.
Prices and options by email
How to get started today
KeyCare Pass is not certified against this framework, and GovPAM does not claim that using it makes an organization compliant. This page describes how KeyCare Pass's features can support your own compliance work. It is not legal or audit advice.
What NIST asks for
NIST Special Publication 800-63B, part of the Digital Identity Guidelines, sets out how passwords and other authenticators should be handled. It favours long passwords, checking new passwords against lists of compromised ones, allowing paste so password managers can be used, and multi-factor authentication, over composition rules and routine expiry.
The NIST Cybersecurity Framework (CSF) 2.0 organizes cybersecurity outcomes into functions such as Protect and Detect. Neither is a certification.
Where KeyCare Pass fits
The parts of SP 800-63B and CSF 2.0 that a password manager touches.
| What is asked for | How KeyCare Pass can help | Plans |
|---|---|---|
| SP 800-63B: long, random secrets | The generator makes passwords of up to 128 characters and passphrases of up to 20 words, and the extension fills them so nobody has to type them. | All plans |
| SP 800-63B: check against compromised passwords | The exposed passwords report checks each password against Pwned Passwords using k-anonymity, without sending the password. | All plans |
| SP 800-63B: multi-factor authentication | Two-step login with authenticator apps, FIDO2 security keys and passkeys, email codes or Duo; required for everyone by policy. | Policy: Enterprise |
| CSF 2.0 PR.AA: identity management, authentication and access control | Collections, groups, roles, member confirmation and removal. | Teams, Enterprise |
| CSF 2.0 PR.DS: data security | Vault data is encrypted on each person's device (AES-256 with HMAC-SHA256); keys come from the master password through PBKDF2-SHA256 or Argon2id; traffic uses TLS. | All plans |
| CSF 2.0 DE.CM: continuous monitoring | Event logs and sign-in activity show who accessed what and from where. | Teams, Enterprise |
What stays with you
A password manager is one control among many. These remain your organization's work:
- Choosing the assurance levels and profiles that apply to you
- Your organization's own password and authentication policies
- Monitoring and responding to what the event logs show
- Mapping CSF outcomes across all your systems, not just passwords
Frequently asked questions
Does KeyCare Pass force password changes every 90 days?
No. Following current guidance, KeyCare Pass helps you change passwords when there is a reason to, such as a breach or reuse, rather than on a timer.
Is KeyCare Pass FedRAMP authorized?
No.
Need details for your auditor?
Ask us about KeyCare Pass's design, hosting and data handling.