I am not sure where this requirement comes from, but if you are in a position to question this policy I'd probably do so.
Strong passwords (or even no passwords at all!) are better than forcing users to change passwords at fixed intervals as that often leads to kinda weak passwords.
This is not my personal recommendation but from Bundesamt für Sicherheit in der Informationstechnik (german national cyber security authority) as can by read in
this article by Heise; BSI dropped the recommendation to regulary change passwords in 2020 while
NIST already did so in 2017: