Tip: in the print dialog choose “Save as PDF”. Paper size is US Letter.

Free printable

Password Change Log: Free Printable

By Jason Su · Updated September 30, 2026

Most password advice you have been given is out of date, and this sheet is built on the newer rule.

You do not need to change passwords on a schedule. The federal standard for digital identity now tells services they must not require subscribers to change passwords periodically. It also says they must force a change when there is evidence the password has been compromised. (NIST SP 800-63B)

So a calendar was never the right trigger. Events are. This log records the events: what changed, when, why — and where the new password lives. It never records the password itself. For that, use the Password Log Sheet, which is designed around where things are, not what they are.

When a change is actually worth it

  • You got a breach notice from a service, or you saw it in the news.
  • You used that password on more than one account. This is the real risk most people carry. One breach becomes three.
  • Someone who knew it is no longer in your life — a former partner, a departing helper, a roommate.
  • You sent it to someone, by text, email, or a note.
  • You see a login you do not recognize. Change it there, then change it anywhere it was reused.
  • A device is leaving your hands — sold, traded in, or given away.

Notice what is not on that list: “it has been 90 days.” That habit costs you time and produces weaker, more guessable variations of the same password.

What goes in the log — and what never does

Write thisNever write this
Which account changedThe password
The date you changed itThe password, scrambled, with hints
Why it changedAnything you would not want read aloud
Where the new one is storedYour security-question answers

The reason is simple: a piece of paper that lists passwords is a single point of failure that copies easily. A sheet that lists where the passwords are is not worth stealing. See how to share a password safely for the same idea applied to other people.

The sheet

How to use it

  1. Do the reuse table first. It is the part that lowers your actual risk, and it takes ten minutes.
  2. Change the duplicated ones by priority: email, then banking, then everything else. Email resets the rest.
  3. Write the date and the reason in the first table as you go, so a year from now you can tell why a password changed.
  4. Store the new password where you already store passwords — one place, not three. The Digital Account Inventory is where you note which accounts exist at all.
  5. Reread the sheet once a year. Old logs keep accounts you have since closed.
  6. Keep it where it will be found, and tell one person that the sheet exists.

Frequently asked

Do I really not need to change passwords every few months?

Not on a schedule, no. The standard behind this sheet used to merely discourage it and now prohibits services from requiring it. Change on events — a breach notice, a shared password, someone leaving, a login you did not make.

Is writing any of this down unsafe?

Writing where passwords are stored is safe and useful. Writing the passwords themselves is the mistake. Keep that line clean and the sheet becomes an asset rather than a liability.

What about the password hint or security questions?

The same standard says services must not use security questions at all, and must not store a hint that an unauthenticated person can reach. If a service still asks you “what was your first pet’s name,” treat the answer as a password: use something made up, and store it with the password.

Should I use a password manager?

The standard requires services to allow password managers and autofill, which is worth knowing if a website ever tells you to type a password by hand. If you have not started one, see one password for the whole family for how the sharing side works.

What if the accounts are someone else’s — a parent I help?

Use the same tables, and add a column for who did the change. If the account has two-factor codes going to a phone, note that too — see how to back up two-factor codes for why that detail matters later.

Next step

Fill in the reuse table today with the two or three passwords you know are duplicated. Change those, date them, and note where the new ones live.

Then record which accounts exist at all on the Master Checklist, so a change log is not the only place that knows an account is there.

This is a blank record sheet, not security advice for a specific account. Password rules and account policies vary by service and change over time — confirm the details in the service’s own help pages.

General information only. ClearLegacyGuide is not a law firm and does not provide legal, medical, financial, or tax advice. Rules vary by state and change over time. Please confirm every form with the official source linked on the page, and talk with a licensed professional before making decisions. Full medical & legal disclaimer