You cannot know if an existing user’s password doesn’t meet your new password policy, because you cannot know their actual password (a password isn’t stored as a text - roughly speaking, it’s hashed, and when you enter your password, that’s also hashed so you compare the hashes rather than the password).