mSecure 7 is here – our biggest update yet. Get the app.

How to Switch Password Managers Without Losing Anything

September 15, 2026   |    mSecure, Security

You can switch password managers in an afternoon, and the only part that genuinely risks losing data is the part most people rush: verifying the new vault before deleting the old one. Everything else is mechanical. Export, format, import, check, clean up. This guide walks through all five steps, including the two that cause almost… Read more

You can switch password managers in an afternoon, and the only part that genuinely risks losing data is the part most people rush: verifying the new vault before deleting the old one.

Everything else is mechanical. Export, format, import, check, clean up. This guide walks through all five steps, including the two that cause almost every support ticket we see — CSV formatting, and the plaintext export file people forget to delete.

Before you switch password managers, count what you have

Open your current password manager and write down two numbers: how many items you have in total, and how many of those are something other than a login — credit cards, secure notes, identities, software licences, Wi-Fi passwords.

That first number is the only way you will know, an hour from now, whether the import brought everything across. Write it on paper. It takes thirty seconds and it is the difference between “I think that worked” and “that worked.”

The second number matters because logins move cleanly and everything else usually needs attention. A credit card record in one product has different fields from a credit card record in another, and the import will not invent the mapping for you.

Step 1: Export from your old password manager

Nearly every password manager exports to CSV. The command is usually under File, Settings, or an account menu, often labelled Export, Export Vault, or Backup.

Two things to understand before you click it:

The export file is plaintext. Your passwords will be sitting in a readable file on your disk. That is normal and unavoidable — it is also why Step 5 exists and is not optional.

The export side usually needs a computer. Other password managers’ mobile apps frequently do not offer export at all, so plan on doing that part at a desk — even though mSecure will happily do the import on your phone.

Check the Import screen in mSecure before you start, because you may not need a spreadsheet at all. Alongside plain CSV there are dedicated importers for 1Password (both the older .1pif and the newer .1pux), SplashID, DataViz Passwords Plus, and a Keychain CSV option. If your old manager is on that list, the file goes straight in — the support guide covers the 1Password steps.

Step 2: Format the file

This step is only for the managers without a dedicated importer — LastPass, Bitwarden, Dashlane and Proton Pass among them. Those go through the generic CSV option, and a CSV exported from another product will almost never import cleanly as-is. You will spend fifteen minutes in a spreadsheet, and that is the real cost of switching.

What you are doing is rearranging columns so each row says what kind of record it is and what each field means. mSecure’s importer also expects a specific line at the very top of the file — get that wrong and nothing imports at all. Both the column layout and that first line are spelled out in mSecure’s CSV import guide, and it is worth reading it once rather than guessing twice.

Two things that save time:

  • Create your record types and tags in mSecure first. If a record type does not exist before the import, rows using it will fail. Set them up, then import.
  • Do logins first, on their own. Get the biggest, simplest group in and verified, then handle cards, notes and identities in a second pass. A hundred-row failure is much easier to diagnose than a thousand-row one.

Diagram mapping columns from a password manager export file to the matching fields in an mSecure record, with the password column highlighted

Step 3: Import

On iPhone: open and unlock mSecure, then Settings → Import, and choose the file type you are importing from.

On Mac: open and unlock mSecure, then File → Import, and choose the file type.

On Windows: open and unlock mSecure, then Settings → Backups, and choose the import option.

Whichever device you use, your others will pick the records up on their next sync.

Step 4: Verify before you delete anything

This is the step that decides whether you lost something.

Check the count first. Does the number of records in mSecure match the number you wrote down? If it is short, the missing rows are almost always a single record type that did not exist before the import — fix it and re-import that group.

Then spot-check the content, not just the count:

  • Open five logins and confirm the password field actually holds a password, not a URL. Column drift is the classic CSV failure and it is invisible until you look.
  • Open every credit card and every identity record. These have the most fields and the most room for misalignment.
  • Check that long notes survived. Notes with line breaks in them are the single most common thing to arrive mangled, because the line breaks confuse the CSV parser.
  • Actually sign in to two or three accounts using mSecure’s autofill.

Only when all of that passes should you go back to the old password manager and delete your account.

Step 5: Delete the export file properly

You still have a plaintext file full of your passwords sitting on your computer.

Delete it, then empty your Trash or Recycle Bin. Then check the places a copy may have travelled to without you thinking about it: your Downloads folder, any cloud-synced folder like Desktop or Documents, and your email if you sent the file to yourself to get it between machines.

If the export file ever touched cloud storage or email, treat the passwords in it as exposed and change the ones that matter — your email account, your bank, and anything holding a saved payment method. You can check whether any of those addresses have shown up in a known breach at Have I Been Pwned.

Two things that will not come across

Two-factor codes. If your old manager stored TOTP codes, those secrets are rarely included in a standard export. Plan to re-enrol two-factor on your important accounts. mSecure flags which of your logins support two-factor authentication, so you can work through them in order rather than from memory.

Passkeys. Passkeys are bound to the place that created them, and portable transfer between password managers is still arriving across the industry. Assume you will recreate a passkey in the new manager rather than move it, and keep the old account alive until you have.

While you are in there, fix the passwords

A migration is the one time you will look at every account you own in a single sitting. Use it.

Do not rotate everything on principle — NIST’s guidance has moved away from routine periodic changes, which mostly produce weaker, more predictable passwords. Change the ones with a reason: anything reused across two accounts, anything short enough that you can remember it, and anything attached to an address that appears in a breach.

Once your vault is in one place and encrypted end-to-end, that list gets shorter every time you look at it.

Moving to mSecure? Your data is encrypted with AES-256 on your device under a zero-knowledge architecture — we do not store your account password or account key, so we cannot read your vault. See what else is in there, or start a 30-day free trial. Still deciding? How to Choose a Password Manager covers the criteria that actually matter.