Recovery phrases are most commonly 12 or 24 words, with 18 words also used by some wallets. All are valid BIP39 mnemonics.
Longer phrases contain more entropy, so they are technically harder to brute force. But 12 words already provide far more security than any practical attack can overcome.
Ledger and many hardware wallets use 24 words by default. The extra words add redundancy for error detection and are reassuring to users, even though 12 is cryptographically sufficient.
The strength of your security depends far more on how you store the phrase than on its length. A 12-word phrase on paper beats a 24-word phrase in a compromised notes app.
Any standard length is secure. Focus on keeping the phrase private and backed up, regardless of length.