What the buyer is really asking
State your rules on length, complexity, reuse, and lockout. Current NIST guidance favors long passwords and breach checks over forced rotation, and you can say plainly that you follow it.
Other ways buyers ask it
Every one of these wants the same answer:
- “What is your password policy?”
- “What are your password complexity requirements?”
- “How often must passwords be changed?”
- “Do you lock accounts after failed login attempts?”
Evidence to have ready
- A password or authentication policy
- Identity provider password settings
How Tyrvar answers this
Tyrvar treats every wording above as one question. You write the answer once, attach the evidence, and revisit it when your setup changes. Each buyer gets that approved answer no matter how their questionnaire words it. If you have not answered it yet, Tyrvar flags the question for you and does not make something up. Try it on your own questionnaire.