KeyGuard Password is now KeyCare Pass. Same vault, same account, a new name and address.

Compliance

KeyCare Pass and NIST guidance

NIST's digital identity guidelines and its Cybersecurity Framework are widely used references, inside and outside the United States. Here is where KeyCare Pass fits.

Get a quote

Prices and options by email

Start business trial

How to get started today

Please read this first

KeyCare Pass is not certified against this framework, and GovPAM does not claim that using it makes an organization compliant. This page describes how KeyCare Pass's features can support your own compliance work. It is not legal or audit advice.

What NIST asks for

NIST Special Publication 800-63B, part of the Digital Identity Guidelines, sets out how passwords and other authenticators should be handled. It favours long passwords, checking new passwords against lists of compromised ones, allowing paste so password managers can be used, and multi-factor authentication, over composition rules and routine expiry.

The NIST Cybersecurity Framework (CSF) 2.0 organizes cybersecurity outcomes into functions such as Protect and Detect. Neither is a certification.

Where KeyCare Pass fits

The parts of SP 800-63B and CSF 2.0 that a password manager touches.

What is asked forHow KeyCare Pass can helpPlans
SP 800-63B: long, random secretsThe generator makes passwords of up to 128 characters and passphrases of up to 20 words, and the extension fills them so nobody has to type them.All plans
SP 800-63B: check against compromised passwordsThe exposed passwords report checks each password against Pwned Passwords using k-anonymity, without sending the password.All plans
SP 800-63B: multi-factor authenticationTwo-step login with authenticator apps, FIDO2 security keys and passkeys, email codes or Duo; required for everyone by policy.Policy: Enterprise
CSF 2.0 PR.AA: identity management, authentication and access controlCollections, groups, roles, member confirmation and removal.Teams, Enterprise
CSF 2.0 PR.DS: data securityVault data is encrypted on each person's device (AES-256 with HMAC-SHA256); keys come from the master password through PBKDF2-SHA256 or Argon2id; traffic uses TLS.All plans
CSF 2.0 DE.CM: continuous monitoringEvent logs and sign-in activity show who accessed what and from where.Teams, Enterprise

What stays with you

A password manager is one control among many. These remain your organization's work:

  • Choosing the assurance levels and profiles that apply to you
  • Your organization's own password and authentication policies
  • Monitoring and responding to what the event logs show
  • Mapping CSF outcomes across all your systems, not just passwords

Frequently asked questions

Does KeyCare Pass force password changes every 90 days?

No. Following current guidance, KeyCare Pass helps you change passwords when there is a reason to, such as a breach or reuse, rather than on a timer.

Is KeyCare Pass FedRAMP authorized?

No.

Need details for your auditor?

Ask us about KeyCare Pass's design, hosting and data handling.