What Is a Password Manager and Do You Need One in 2026?

Reviewed · Updated

Daria Klochko

Daria Klochko

Founder and editor

I built Vetted Privacy to see what privacy services actually do, not what they promise. Found a mistake? Email me.

in

Quick answer: A password manager is an app that creates, stores and fills in a different strong password for each of your accounts, locked behind one master password. CISA recommends passwords of at least 16 characters, unique to every account (checked 10/09/2026).

  • It protects you from password reuse and weak passwords. It doesn't stop malware on your device or a scam where you type the password in yourself.
  • Free options exist: Apple's Passwords app, Google Password Manager and the one in your browser.
  • A paid app makes sense when you need one vault across Apple, Windows and Android, or want to share logins with family.

How a password manager works

A password manager keeps your logins in a vault: an encrypted file that holds usernames, passwords and often notes, card details and two-factor codes. You open the vault with one master password. CISA puts it simply: a password manager “generates, stores and even fills in all your passwords.”

CISA's definition: a program that generates, stores and fills in your passwords. Screenshot taken on 10/09/2026

Three things happen in day-to-day use. When you create an account, the app offers a long random password and saves it. When you come back, it fills the username and password in for you. When a saved password turns out to be weak, reused or found in a breach, it warns you.

The part that makes this safe is where the encryption happens. In the common design, the app encrypts the vault on your phone or computer with a key made from your master password. The company then syncs a copy it can’t read.

LastPass calls this “Zero Knowledge” and says the master password “is never known to LastPass.” Other apps use different names for the same idea.

Sites are expected to work with this. NIST’s digital identity guidelines say sites “SHALL allow the use of password managers and autofill functionality” and should allow pasting a password (SP 800-63B, revision 4, 08/26/2025). NIST adds that password managers have been shown to make people choose stronger passwords.

NIST SP 800-63B (rev. 4, 08/26/2025): sites “SHALL allow the use of password managers and autofill.” Screenshot taken on 10/09/2026

What it does and doesn’t protect you from

The main job is ending password reuse. Verizon’s research for its 2025 Data Breach Investigations Report found that in the median case, only 49% of a user’s passwords across services were distinct from each other. Reuse turns one leaked password into many open accounts, because attackers test leaked logins on other sites.

What a password manager handles well:

  • Reuse. Every account gets its own password, so a breach at one site doesn’t open the others.
  • Weak passwords. The generator creates long random strings you never have to type or remember.
  • Breach alerts. Many apps, including Apple’s Passwords, flag passwords that appear in known data leaks.
  • Lookalike sites. Autofill matches the saved web address, so a fake login page on a different address usually gets nothing filled in. That’s a warning sign, not a block.

What it doesn’t do:

  • Malware. If your device is infected, what you see and type there can be exposed, vault included.
  • Scams where you type the password yourself. If you copy a password into a fake page or read it to a caller, the manager can’t stop you.
  • Account takeover without a second factor. The FTC notes that even strong passwords can be stolen, and two-factor authentication means a stolen password alone can’t open your account.
  • Your data elsewhere. It does nothing about your address on people-search sites or your SSN in a breach. That’s what removing your information from the internet and identity theft protection cover.

What a breach of the password manager itself looks like

The fear is reasonable: one vault holds everything, and the LastPass incident shows what’s at stake.

In its notice of 12/22/2022, LastPass said an attacker copied backups of customer vaults. Website addresses in them were unencrypted. Usernames, passwords, secure notes and form data were encrypted with a key derived from each user’s master password.

LastPass's 12/22/2022 notice: website addresses in the stolen vault backups were unencrypted, passwords and notes were encrypted. Screenshot taken on 10/09/2026

Two lessons follow. The strength of your master password is what stands between a stolen vault file and your accounts, so make it long and use it nowhere else. And it’s worth knowing which fields an app leaves unencrypted, because those can still reveal which sites you use. Read the full LastPass notice for the details.

Do you need one?

Probably yes, in any of these situations:

  • You reuse passwords, even with small changes. Adding a digit or a symbol to an old password doesn’t help much, because attackers try those variations too.
  • You have more accounts than you can remember. Bank, email, health portals, shopping and streaming add up. CISA says that for most people, remembering long, random and unique passwords for every account “is not possible.”
  • You share logins with family. A shared vault beats texting passwords. Apple’s Passwords has Shared Groups for this, and most paid apps have family plans.
  • You’ve had an account broken into or got a breach notice. A manager shows which other accounts used the same password, so you know what to change first.

If you already use your browser to save passwords, you have a basic password manager. The question is whether it covers all your devices, which we look at on the page about browser password managers.

Free vs paid options

You don’t have to pay. CISA says some password managers “are free, like the built-in password managers in your web browser, and some cost money.”

  • Apple Passwords. Built into iOS 18, iPadOS 18, macOS Sequoia and visionOS 2. It stores passwords, passkeys, Wi-Fi passwords and verification codes, and warns about reused or leaked ones. On Windows, Apple says you can use it in Chrome or Edge through iCloud for Windows.
  • Google Password Manager. Built into Chrome and Android. Google says it can create, save and autofill passwords and passkeys.
  • Free plans of standalone apps. Several independent password managers have a free tier with limits on devices or features.
Apple's free Passwords app, built into iOS 18, iPadOS 18, macOS Sequoia and visionOS 2. Screenshot taken on 10/09/2026

Built-in managers work best if all your devices come from one company. Mixing an iPhone with a Windows laptop and an Android tablet is where standalone apps earn their price. Paid plans tend to add family sharing and file storage, and each vendor lists the details on its pricing page.

We compare them, with checkout prices and what’s in each free plan, in our password manager ranking and in the best free password managers.

How to choose a password manager

  • Works on every device you use, including the browser on your work computer if you’re allowed to install it.
  • Two-factor authentication for the vault itself, ideally with an authenticator app or security key. The FTC calls those more secure than text-message codes.
  • A recovery option you understand before you need it.
  • A way to export your vault, so switching apps later is possible.
  • A public security record: published independent audits and how the company handled past incidents.

Common misconceptions

“Putting every password in one place is riskier.” Reusing a few passwords across dozens of sites is the bigger risk. That’s why CISA, the FTC and NIST all point people to password managers. The single point of failure is your master password, so give it real length.

“I should change all my passwords every 90 days.” NIST now says sites “SHALL NOT require subscribers to change passwords periodically,” only when there’s evidence of compromise. With a manager, change a password when a site is breached or the app flags it.

“A strong password needs symbols and capitals.” NIST says sites shall not impose other composition rules, and it sets the minimum at 15 characters for passwords used alone. Length does the work. CISA asks for at least 16 characters and the FTC for at least 12.

“The company can see my passwords.” In the common design it can’t, because the vault is encrypted on your device. That’s also why many apps can’t reset your master password for you.

“A password manager makes two-factor authentication unnecessary.” They solve different problems.

Use both, starting with your email account, since it can reset everything else. For the master password itself, CISA suggests a long, memorable passphrase. Our password generator can make one.

See also: browser password managers · best password managers · 1Password review · Proton Pass review · how we score services · how this site makes money

What we checked

  • Government guidance: CISA's Use Strong Passwords page, the FTC's article on strong passwords (November 2024) and NIST SP 800-63B revision 4 (08/26/2025), section 3.1.1.2 — read and captured 10/09/2026
  • Built-in options: Apple Support article 120758 on the Passwords app (published 06/05/2026) and Google Account Help on Google Password Manager — read 10/09/2026
  • Breaches and reuse: LastPass's incident notice of 12/22/2022 and Verizon's credential stuffing research from the 2025 DBIR — read 10/09/2026. No apps were installed or tested for this page.

FAQ

Are password managers safe?

For most people, yes, and they are safer than reusing passwords. CISA, the FTC and NIST all point people toward them. The risk is real but narrow: when LastPass was breached in 2022, the stolen vault copies were encrypted with a key from each user's master password. A long, unique master password plus two-factor authentication is what keeps a vault safe.

How do password managers work?

The app keeps your logins in an encrypted vault that opens with one master password. It creates a random password when you sign up for a site, saves it, and fills it in the next time you log in. In the common design, encryption happens on your device, so the company stores a file it can't read.

Do I need a password manager?

If you have more accounts than you can give unique passwords from memory, yes. In Verizon's 2025 breach research, only 49% of a typical user's passwords were distinct from each other. A manager removes the need to reuse anything, and it can be free.

Is a free password manager good enough?

Often, yes. Apple's Passwords app, Google Password Manager and browser password managers cost nothing and cover creating, saving and filling passwords. Paid apps matter more if you need one vault across Apple, Windows and Android, family sharing, or extra recovery options. See which free and paid options we compare on our password manager ranking.

What happens if I forget my master password?

It depends on the app, so set up recovery before you need it. Many managers can't reset it for you. LastPass, for example, says the master password is never known to it and isn't stored by it. Look for the recovery option your app offers, such as a recovery code or a trusted device, and write it down offline.

Is a password vault the same as a password manager?

Mostly, yes. The vault is the encrypted storage inside a password manager. Some apps sold as a vault only store passwords, while a full manager also creates new passwords and fills them in on sites and apps.

This page contains no affiliate links.