Download Cheat sheet PDF 12 pages · syntax, editors, patterns, Unicode, performance, debugging
Pattern

Regex for Strong password

8+ chars, uppercase, lowercase, digit, symbol.

The Strong password regex is ^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{8,}$ — copy it below, or open it in the explainer for a token-by-token breakdown.

The pattern

^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{8,}$
Try in explainer → Download cheat sheet ↓

What it matches

  • MyP@ssw0rd
  • Secur3!Pass
  • Pa$$word1

What it doesn't match

  • password
  • PASSWORD1
  • Pass123
  • Pass!

Notes & gotchas

Four positive lookaheads check for each character class. Adjust the minimum length and required classes for your policy. Modern NIST guidance favors length over complexity.

Code in your language

Use the explainer's Code tab to generate ready-to-paste snippets in JavaScript, Python, Java, .NET, Go, Ruby, and PHP for this pattern.

Open in explainer →

Token-by-token breakdown

Every part of the pattern, left to right:

TokenMeaning
^start of string (or line in multiline mode)
(?=start of a positive lookahead — followed by
.*zero or more of any character
[a-z]any of: lowercase letters
)end of group
(?=start of a positive lookahead — followed by
.*zero or more of any character
[A-Z]any of: uppercase letters
)end of group
(?=start of a positive lookahead — followed by
.*zero or more of any character
\dany digit (0–9)
)end of group
(?=start of a positive lookahead — followed by
.*zero or more of any character
[^\w\s]any character except word chars (A–Z, a–z, 0–9, _), whitespace
)end of group
.{8,}8 or more times of any character
$end of string (or line in multiline mode)

About this pattern

Password and credential validation patterns enforce policy rules. Modern guidance (NIST 800-63B) favors length over complexity.

Quick usage in different languages

This exact pattern — with the correct escaping and idioms for each language:

  • JavaScript: /^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{8,}$/.test(value)
  • Python: re.match(r"^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{8,}$", value)
  • Java: Pattern.compile("^(?=.*[a-z])(?=.*[A-Z])(?=.*\\d)(?=.*[^\\w\\s]).{8,}$").matcher(value).matches()
  • C# / .NET: Regex.IsMatch(value, @"^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{8,}$")
  • Go: regexp.MustCompile(`^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{8,}$`).MatchString(value)
  • Ruby: /^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{8,}$/.match?(value)
  • PHP: preg_match('~^(?=.*[a-z])(?=.*[A-Z])(?=.*\d)(?=.*[^\w\s]).{8,}$~', $value)

The explainer’s Code tab regenerates these for any pattern you paste, and the downloadable cheat sheet bundles the breakdown, all seven snippets, and the pitfalls below onto one printable page.

Common pitfalls

  • Anchored to the whole string. This pattern uses ^ and $, so it requires the entire input to match. To find it inside a longer text, drop the anchors and use the global (g) flag.
  • Case sensitivity. Letter ranges are case-sensitive — use the i flag if the input case can vary.
  • Greedy “.*”. A greedy .* / .+ can match more than intended. Use a lazy version (.*?) or a negated class ([^…]) to stop at the right place.
  • Escape it correctly per language. In Java and JavaScript strings each backslash must be doubled (\\d); in Python, Go, and C# use raw/verbatim strings so the backslashes survive.
  • Validate beyond format. Matching the format doesn't guarantee the value is real. Confirm the strong password against a source of truth (database, API, or checksum) where it matters.

Related patterns

More patterns in the Passwords category:

See also

Browse all 300 patterns in the library, or open this regex in the interactive explainer for a token-by-token breakdown, live testing, and code in seven languages.


Want more patterns? Browse the full library →