@glyph I can cite precisely one NIST standard from memory, and this is it: “According to NIST SP 800-63b, section 5.1.1.2, we shouldn’t rotate passwords unless we expect they’ve been compromised.”
I busted that out on a call once and it stopped an entire argument. My CTO was also on the call and I saw him looking over at me, mouth agape.