Scope: This is a proactive setup and migration guide. If you cannot sign in, see unknown recovery details, or suspect an attacker already controls your email, follow the secure-email recovery checklist first instead of importing compromised credentials.

A password manager is software that stores account credentials in an encrypted vault and can generate and fill unique passwords. The main benefit is not convenience alone: it helps you stop reusing the same password across unrelated services. CISA, NIST, and the FTC all recommend password managers as a practical way to support strong, unique passwords, together with multifactor authentication (MFA).

Step 1: Choose a password manager for your real devices

Do not start with a feature leaderboard. Start with the places you must sign in: your phone, personal computer, work computer if permitted, and the browsers you actually use. A manager that you cannot use consistently encourages old habits.

Before creating an account, confirm that the provider clearly documents:

  • support for your operating systems and browsers;
  • how it encrypts and syncs vault data;
  • MFA options for the vault account;
  • import and export procedures;
  • what recovery can and cannot restore; and
  • how to contact support without revealing a master password.

This guide is vendor-neutral and does not rank products. Product availability, recovery models, and security features change; verify them in the provider’s current documentation before deciding.

Step 2: Protect the password manager account first

Create a strong, unique master credential that you do not use anywhere else. If the manager supports a passkey for the vault account, review its recovery behavior before choosing it. If it uses a master password, favor length and uniqueness over a complicated pattern you will be tempted to reuse.

Then enable the strongest MFA method the service and your devices support. NIST specifically recommends protecting a password manager with MFA, and CISA recommends MFA for accounts that support it. Save recovery codes somewhere separate from the vault account—such as a locked physical record or another protected location you can reach if your primary device is unavailable.

Do not: paste your master password into notes, email it to yourself, or store the only recovery code inside the same vault it unlocks.

Step 3: Prepare recovery before importing passwords

Write down what would happen if you lost your phone, forgot the master credential, or could not use your usual MFA method. Some managers cannot recover vault contents if the master credential is lost; others offer account recovery that changes the security trade-off.

  1. Record the provider’s official recovery steps and support URL.
  2. Store recovery codes separately from the vault.
  3. Add a backup MFA method only if it is appropriately protected.
  4. Decide whether a trusted person needs emergency-access instructions.
  5. Test that you can sign in on a second authorized device before moving critical accounts.

Step 4: Import carefully and control export files

Browsers and other managers may export passwords in a CSV or similar file. These files are often readable without encryption, so treat them like a document containing every key to your online life.

  1. Use only the destination manager’s official import instructions.
  2. Export on a device you control; avoid shared or public computers.
  3. Import the file directly, then confirm several entries open the correct sites.
  4. Delete the export from Downloads, Desktop, cloud-sync folders, and removable drives.
  5. Empty the relevant trash or recycle bin.

Deletion reduces ordinary exposure but may not guarantee forensic erasure on every storage system or backup. The safer approach is to keep the plaintext export’s lifetime and copies to a minimum.

Step 5: Move the accounts that can unlock everything else

Migrate in an order that reduces the biggest consequences first:

  1. Primary email: it receives password-reset links for many other services.
  2. Financial and payment accounts: banks, cards, payment apps, and retailers with stored payment methods.
  3. Cloud storage and device accounts: these may contain backups, photos, and recovery controls.
  4. Mobile carrier: carrier access can affect phone numbers and text-message codes; see the SIM-swap response guide if service changes unexpectedly.
  5. Social, shopping, health, and government accounts: prioritize those holding sensitive data or enabling purchases.

Move one account at a time. Confirm the new password works and the recovery information is current before signing out everywhere.

Step 6: Replace reused passwords with unique generated ones

Importing old passwords is inventory, not completion. For each important account, use the manager to generate a long, random password that is unique to that service. Change it from the service’s official account settings, then confirm the saved entry points to the correct domain.

Start with passwords you know were reused. If a breach notice names an affected account, follow the service’s notice and the data-breach response guide; do not assume changing one copy fixes every account that reused it.

Step 7: Let autofill help you notice the wrong domain

A password manager normally associates a login with a website address. If it does not offer to fill a credential, pause and inspect the domain rather than searching the page for a way around the warning. This can help expose look-alike phishing sites, but it is not a guarantee that a page is legitimate.

Open sensitive sites from a saved bookmark or type the known address. If a message pressures you to sign in through a link, use the phishing-message checklist before entering credentials.

Step 8: Maintain the vault, devices, and recovery plan

  • Keep the password manager, browser extension, operating system, and browser updated.
  • Remove old devices and sessions from the manager’s account dashboard.
  • Review weak, reused, or exposed-password alerts as leads, then verify changes on the official site.
  • Recheck recovery codes after changing MFA methods.
  • Keep exports temporary; do not build an unencrypted archive “just in case.”

After the first migration, your practical completion condition is simple: important accounts have unique credentials, the vault has MFA, recovery works from outside the vault, and your everyday devices can sign in without falling back to reused passwords.

Frequently asked questions

Is a password manager safer than reusing one memorable password?

A reputable password manager makes it practical to give each account a long, unique password. That limits the damage when one service is breached. Protect the manager itself with a strong, unique master credential and MFA.

Which accounts should I move first?

Start with the email account used for password resets, then financial accounts, cloud storage, mobile carrier, social media, and other accounts that can unlock personal information or purchases. Change reused passwords as you go.

Should I delete an exported password CSV after importing it?

Yes. Treat the export as highly sensitive, confirm the import, delete every copy you created, and empty the relevant trash or recycle bin. Deletion may not guarantee forensic erasure on every device, which is why minimizing the file’s lifetime matters.

Sources and editorial notes

Digital Safety Desk reviewed the cited government guidance and wrote this vendor-neutral migration sequence for general educational use. No product was tested, ranked, or endorsed. The hero image is an original AI-generated editorial illustration; it does not depict a real password manager interface or credential.