FBI's CJIS Security Policy 6.1: Key Updates for IT Security Professionals
The **FBI's Criminal Justice Information Services (CJIS)** Security Policy has evolved with the release of Version 6.1. This update refines the control-based structure, aligning it more closely with **NIST SP 800-53** and introducing critical changes to encryption, vulnerability management, and audit expectations for agencies handling sensitive criminal justice information (CJI). IT security professionals must understand these revisions to maintain compliance and bolster their security posture.

The **FBI's CJIS Security Policy** has undergone a significant modernization effort, culminating in Version 6.0 and further refined by the recent Version 6.1, published on June 25, 2026. This latest iteration continues the shift towards a control-based framework, mirroring the robust standards of **NIST SP 800-53**.
While the overall direction remains consistent with v6.0, several key updates in v6.1 warrant immediate attention from organizations responsible for **CJI**. With increasing crackdowns on non-compliance, understanding these changes is crucial for aligning security controls and compliance programs with the latest federal mandates.
## What's Changed Between CJIS v6.0 and v6.1?
One of the most significant technical updates concerns encryption. Under **SC-13**, which governs cryptographic protection for **CJI** in transit outside physically secure locations, v6.0 mandated a symmetric cipher key of at least 128-bit strength. Version 6.1 has elevated this requirement to a minimum of **256-bit strength**.
Similarly, **SC-28**, addressing the protection of **CJI** at rest outside physically secure locations, has been tightened to specify an encryption strength of at least **256-bit strength**.
Another critical change is in vulnerability management. While v6.0 required agencies to conduct vulnerability scans at least quarterly and after security incidents involving **CJI**, Version 6.1 now mandates these scans at least **monthly**.
## Does CJIS v6.1 Change the Audit Requirements?
While v6.1 is the current **CJIS Security Policy**, agencies should not assume an immediate, universal switch to a new audit baseline. The modernized policy utilizes priority levels and phased audit and sanction dates. **Priority 1** controls have been sanctionable since October 1, 2024, while **Priority 2, 3, and 4** controls are in a βzero-cycleβ status until September 30, 2027.
**State CJIS Systems Agencies (CSAs)** may also provide specific implementation and assessment guidance. For example, Texas continues to audit against v5.9.5 through March 31, 2027, allowing agencies time to prepare for v6.1.
A practical approach is to confirm current audit expectations with the relevant **CSA** while proactively working towards the newer requirements. Delaying action on controls until they become sanctionable can create substantial remediation work, especially as audit programs move towards continuous assessment models.
## What Are Agencies Finding in Audits?
At its October 2025 **CJIS Board** meeting, the **Michigan State Police (MSP)** identified **multi-factor authentication (MFA)** as one of its top audit findings. Other recurring issues included deficiencies in new policies, **BYOD** policies and procedures, training, security agreements, event logging, and fingerprinting.
The **MSP** meeting also highlighted a shift away from relying solely on triennial audit visits. Their phased model now incorporates baseline security assessments, quarterly meetings, System Security Plans, secure evidence submission, and regular progress reviews, with continuous assessment planned for later stages. **Identification and Authentication** is one of the control families slated for assessment during FY2027.
This underscores a crucial point for agencies: compliance increasingly depends not just on having a control in place, but on consistently demonstrating its effective operation.
## Are CJIS v6.1 Password and MFA Requirements the Same?
The **Identification and Authentication** requirements have not materially changed between v6.0 and v6.1.
**IA-2** requires unique identification and authentication for organizational users. Its **Priority 1** enhancements mandate **MFA** for both privileged and non-privileged accounts, regardless of whether access is local, network-based, or remote.
**Password controls** under **IA-5** are similarly explicit. Agencies must maintain a list of commonly used, expected, or compromised passwords, updating it at least quarterly and whenever passwords may have been compromised. Prospective passwords must be checked against this list during creation or modification, and current memorized secrets must be compared against it quarterly.
## How Specops Helps with CJIS Identification and Authentication
**Specops** offers solutions to support **CJIS** password and **MFA** requirements:
* **Specops Password Auditor** provides a starting point by performing a read-only scan of **Active Directory** to identify password-policy gaps and compromised passwords, offering visibility for pre-assessment remediation.
* **Specops Password Policy** enforces granular password rules and checks against compromised credentials. Its **Breached Password Protection** uses a continuously updated database of over six billion compromised passwords, addressing the **IA-5** requirement to block common or breached credentials. Dynamic feedback informs users why a password is rejected.
* **Specops Secure Access** addresses a frequent audit pain point by adding **MFA** to **Windows** authentication. It supports **Windows** logon, **RDP**, and **RADIUS**, as well as offline and remote authentication for both privileged and non-privileged accounts, directly supporting **IA-2(1)** and **IA-2(2)** requirements. It also offers **SSO** for **SaaS** applications and integrates with **SOC**, **SIEM**, and analytics platforms via its **Event API**, providing stronger authentication and clear evidence of control operation.
## Is CJIS Moving Toward Zero Trust?
While **CJIS v6.1** is not a **Zero Trust** standard, many of its controls align with **Zero Trust** principles. The policy emphasizes establishing user identity, authenticating both privileged and non-privileged users, identifying managed devices, and applying the principle of least privilege.
Instead of solely trusting network location, these controls prioritize verifying who and what is requesting access. Technologies like **Specops Device Trust**, which binds identities to approved hardware and checks device security posture, naturally complement this direction by adding another layer of assurance for sensitive system access.
Future **CJIS** revisions may further develop this approach, but agencies don't need to wait. Strong identity management, **MFA**, device assurance, and restricted access are already effective strategies for reducing risk around **CJI**.
## Prepare for CJIS v6.1 by Closing Identity Gaps
**CJIS v6.1** may be an incremental update, but it reinforces a broader shift towards more rigorous and continuous compliance. Agencies must proactively address identity gaps and strengthen authentication mechanisms to meet these evolving standards and protect sensitive criminal justice information.