It would have been really nice if there had been an RFC or ISO standard for password composition. NIST 800-63B is probably the best advice available, but few people follow it and industry regulations (PCI) typically violate it.
Something like: https://auth0.com/blog/dont-pass-on-the-new-nist-password-gu...