Strong password requirements are technically enforced at the system level
Rejecting weak or short passwords in system configuration enforces A.5.17's credential rules technically, closing the gap between what the policy says and what the system allows.
Password rules are enforced in system configuration so weak passwords are rejected by the identity provider and key applications, not merely discouraged on paper.