How strong is PDF encryption? AES-256, older schemes and the password
By the getPDF team · Published 11 October 2026
The short answer
A PDF protected with current AES-256 encryption (revision 6) cannot be opened by trying keys; the only way in is guessing the password, so the password decides how strong it is. A 6-digit number falls in about 2 seconds on 1 graphics card; 5 random words would take about 2 million years. Older schemes are weaker: 40-bit files fall in minutes whatever the password. Check your file’s revision with Inspect.
Try it here, nothing is uploaded
The short history of PDF encryption
PDF has had 5 versions of its standard security handler, numbered by revision. Each one is still out there in old files. The table shows what each is and how fast it falls to 1 Nvidia RTX 4090 graphics card, using the speeds in a public hashcat 6.2.6 benchmark of that card (October 2022; newer cards are faster, so read the times as orders of magnitude, not promises).
| Revision (as Inspect shows it) | Cipher | Written by | Speed of guessing on 1 card | 8 random characters (letters, digits, symbols) | Verdict |
|---|---|---|---|---|---|
| 2 | RC4, 40-bit key | Acrobat 2 to 4 era (PDF 1.1 to 1.3) | The whole 40-bit key space in about 4.3 minutes, password irrelevant | Not needed | No protection |
| 3 and 4 | RC4 or AES, usually a 128-bit key | Acrobat 5 to 8 (PDF 1.4 to 1.6) | 122 million passwords a second | about 1.7 years | Depends on the password |
| 5 | AES-256, Acrobat 9 variant | Acrobat 9 | 22 billion passwords a second | about 3.5 days | Weak; left out of PDF 2.0 |
| 6 | AES-256 | Acrobat X and later, PDF 2.0, getPDF | 427,200 passwords a second | about 490 years | Strong, with a strong password |
All times are for trying the whole space on 1 card; on average a guess hits halfway. A group with 100 cards divides every figure by 100.
Two rows need a word. Revision 2 is broken at the key: a 40-bit key has about 1.1 trillion values, and hashcat has a mode that walks through all of them, so the password does not matter at all. Revision 5, the first AES-256 that Acrobat 9 wrote, checks passwords with a single fast hash, which is why guessing runs 50,000 times faster than against revision 6. Adobe itself said in 2008 that the change lets cracking tools test each guess with fewer processor cycles (it is on record as CVE-2008-5331), and PDF 2.0 replaced revision 5 with revision 6 rather than adopting it.
What AES-256 means in practice
AES is the US federal encryption standard, FIPS 197, published by NIST in 2001 and updated in 2023. AES-256 is its 256-bit key variant. NIST SP 800-57 Part 1 (revision 5, May 2020) rates it at a security strength of 256 bits and lists that strength as acceptable both through 2030 and from 2031 on (Table 4). Trying all 2 to the power of 256 keys is not a matter of better hardware; it is beyond physics.
So nobody attacks the key. Revision 6 derives the key from your password with a hash defined in ISO 32000-2 (algorithm 2.B), which runs at least 64 rounds of AES and SHA-2 for every single guess. That deliberate slowness is the whole point: it is why 1 card manages 427,200 guesses a second against revision 6 but 22 billion against revision 5. getPDF writes revision 6. Our test file comes out with /V 5 /R 6, the cipher filter AESV3, and PDFium (the engine Chrome uses) reports revision 6 when it opens it.
The real numbers: which passwords hold
All figures are for revision 6, 1 RTX 4090, trying the whole space (checked on 11 October 2026 against the benchmark above). The word lists assume the EFF long list, 7,776 words, where each word is picked at random.
| Password | Possible values | Time on 1 card |
|---|---|---|
| 6 digits, such as a birth date | 1 million | about 2 seconds |
| 8 lowercase letters | 209 billion | about 6 days |
| 8 random characters from the whole keyboard | 6.6 quadrillion | about 490 years |
| 4 random words | 3.7 quadrillion | about 270 years |
| 5 random words | 28 quintillion | about 2.1 million years |
| 10 random characters from the whole keyboard | 60 quintillion | about 4.4 million years |
These assume the password is random. A real word with a year on the end is not 8 random characters: it sits in every guessing list, and it falls in seconds whatever the encryption. Length and randomness win; cleverness does not.
Check what an existing file uses
- Drop the PDF into Inspect above.
- If the file needs a password to open, type it into the box that appears; it is used in this tab only.
- Read the Security section: “Encrypted: yes, revision 6” means current AES-256. Revision 5 or lower, or “no”, means the file needs fresh protection.
Inspect shows the revision number, not the cipher’s name; the table above translates it.
Old protected files: re-protect them
If Inspect shows revision 2, the file is protected in name only. Revision 5 is weak against guessing. Revision 3 or 4 is only as good as a long random password. To bring any of them up to date:
- Drop the old file into Protect PDF and type a long new password under Password to open.
- Click Protect. When it says the file has a password, type the old one and click Open. The result carries only the new password, at revision 6; the old one no longer opens it. (Unlock PDF first, then Protect, gets the same result in 2 steps.)
On our test files this costs little: a 500-page text file took 1.6 seconds and grew from 117 KB to 239 KB (Protect writes every object on its own, without the compressed object streams the original used); a 5.7 MB photo file grew by under 1 KB.
The honest part
- Encryption protects a file while it travels and while it sits in an inbox or a folder. It does nothing once the right person opens it.
- The password is the weak point, and so is the way it travels. A password sent in the same email as the file protects against almost nothing; send it by text message or say it on a call, as password protect a PDF before emailing shows step by step.
- A permission flag such as no printing is not encryption strength at all; see user vs owner password.
- Revision 6 files do not open in very old viewers built before PDF 1.7 extension level 8. Acrobat X and later opens them, and so do the engines inside Chrome (PDFium) and Firefox (pdf.js); we checked both engines’ source on 11 October 2026.
- getPDF does not crack passwords, for weak schemes or strong. If you are locked out of your own file, read what is possible when you forgot the password.
Sources, checked on 11 October 2026: NIST FIPS 197 (updated 9 May 2023) and SP 800-57 Part 1 Rev. 5, Table 4; ISO 32000-2:2020 (PDF 2.0), section 7.6.4, free from the PDF Association; the hashcat 6.2.6 RTX 4090 benchmark published on GitHub in October 2022; CVE-2008-5331 (Acrobat 9’s faster password check); EFF’s long word list (July 2016).
For the whole picture of keeping a PDF private, see the PDF privacy and protection guide.
Questions
Can AES-256 PDF encryption be cracked?
The cipher, no: trying every 256-bit key is beyond any computer that exists. What attackers do is guess the password. A 6-digit number falls in seconds; 5 random words would take millions of years on 1 graphics card at today's published speeds.
How do I know which encryption my PDF uses?
Drop it into Inspect. The Security section shows the revision: 6 is current AES-256, 5 is the older Acrobat 9 variant, 4 and 3 are 128-bit, 2 is 40-bit.
Is 40-bit PDF encryption still safe?
No. The 40-bit key can be found by trying every key, whatever the password, in about 4 minutes on 1 graphics card. Treat such a file as unprotected.
Does getPDF use AES-256?
Yes. Protect PDF writes AES-256 at revision 6, the scheme of ISO 32000-2 (PDF 2.0). Inspect on the result shows revision 6.
Does encryption stop the recipient from sharing the file?
No. Encryption protects the file while it travels and while it sits somewhere. Once the right password opens it, the reader can save, print or forward the content.
The tools for this job
Keep reading
- PDF user password vs owner password: what each one really protectsA user password encrypts a PDF; an owner password only asks viewers to obey its limits.
- Password protect a PDF before emailing it, and send the password the right wayAdd an AES-256 password to a PDF in your browser, free, nothing uploaded.
- Forgot your PDF password? What is actually possibleThe honest answer: a current AES-256 PDF with a strong password stays shut.
- Password protect a PDF without Acrobat: 5 free ways compared5 free ways to password protect a PDF without Acrobat: getPDF in the browser, Mac Preview, LibreOffice, Word and 7-Zip, compared by cipher, effort and catch.
- PDF privacy and protection: the complete guideWhat a PDF password really protects, how true redaction works, what metadata leaks, and how to send files safely.