Back to Feed
PolicySep 21, 2026

FBI's CJIS v6.1: What Security Teams Need to Know.

FBI's CJIS Security Policy v6.1 strengthens encryption and vulnerability scanning requirements.

Summary

The FBI's CJIS Security Policy v6.1 has been released, refining version 6.0 with updated requirements for encryption strength (256-bit for data in transit and at rest) and increasing vulnerability scanning frequency to monthly. Agencies are advised to align with these changes, as audit requirements are shifting towards continuous assessment, with some controls already sanctionable and others phased in until late 2027.

Full text

FBI's CJIS v6.1: What Security Teams Need to Know. Sponsored by Specops Software September 21, 2026 10:02 AM 0 The FBI’s CJIS Security Policy has been through a significant period of change. Version 6.0, released on December 27, 2024, completed the policy modernization effort and moved CJIS toward a control-based structure closely aligned with NIST SP 800-53. Version 6.1, published on June 25, 2026, further refines the modernized policy by addressing omissions, corrections and additions highlighted throughout 2025. For security teams already working toward the requirements introduced in v6.0, that means the overall direction has not changed. However, there are still updates that warrant attention. And as crackdowns are becoming more common, organizations responsible for CJI should understand them to keep their security controls and compliance programs aligned with the latest standards. What’s Changed Between CJIS v6.0 and v6.1? One of the clearest technical changes concerns encryption. Under SC-13, which covers cryptographic protection for CJI in transit outside a physically secure location, v6.0 specified a symmetric cipher key of at least 128-bit strength. Version 6.1 raises that requirement to at least 256-bit strength. SC-28, covering the protection of CJI at rest outside physically secure locations, has also been tightened, specifying encryption strength of at least 256-bit strength. Another notable change is in vulnerability management. Under v6.0, CJIS required agencies to use vulnerability scanning tools at least quarterly to determine whether applicable security-related software and firmware updates had been installed, as well as following security incidents involving CJI. Version 6.1 changes that frequency from quarterly to at least monthly. Does CJIS v6.1 Change the Audit Requirements? Version 6.1 is now the current CJIS Security Policy, but agencies shouldn’t assume that publication automatically means an immediate switch to a single new audit baseline. The modernized policy uses priority levels and phased audit and sanction dates, with Priority 1 controls sanctionable since October 1, 2024. Priority 2,3, and 4 controls are in “zero-cycle” status until September 30, 2027. State CJIS Systems Agencies (CSAs) may also provide their own implementation and assessment guidance. For instance, Texas is continuing to audit against v5.9.5 through to March 31, 2027, while agencies prepare for v6.1. A practical step is to confirm the current audit expectations with the relevant CSA while working toward the newer requirements. Waiting for a control to become sanctionable before addressing it can create unnecessary work later, particularly when audit programs themselves are moving toward more continuous assessment. Secure your Active Directory passwords with Specops Password Policy Verizon’s Data Breach Investigation Report found stolen credentials are involved in 44.7% of breaches. Effortlessly secure Active Directory with compliant password policies, blocking 4+ billion compromised passwords, boosting security, and slashing support hassles! Try it for free What are Agencies Finding in Audits? At its October 2025 CJIS Board meeting, Michigan State Police (MSP) listed multi-factor authentication (MFA) among its top audit findings. Other recurring issues included new policies, BYOD policies and procedures, training, security agreements, event logging and fingerprinting. The same meeting outlined a move away from relying primarily on triennial audit visits. MSP’s phased model includes baseline security assessments, quarterly meetings, System Security Plans, secure evidence submission and regular progress reviews, with continuous assessment planned later in the process. Identification and Authentication is one of the control families scheduled for assessment during FY2027. That is an important point for agencies planning their CJIS work: compliance increasingly depends not only on having a control, but on being able to demonstrate consistently that it is working. Are CJIS v6.1 Password and MFA Requirements the Same? The Identification and Authentication requirements themselves have not materially changed between v6.0 and v6.1. IA-2 requires organizational users to be uniquely identified and authenticated. Its Priority 1 enhancements require MFA for both privileged and non-privileged accounts, regardless of whether access is local, network-based or remote. Password controls are similarly explicit. Under IA-5, agencies must maintain a list of commonly used, expected or compromised passwords, update that list at least quarterly and when passwords may have been compromised, and compare current memorized secrets against it quarterly. Prospective passwords must also be checked against the list when users create or change them. How Specops Helps with CJIS Identification and Authentication Specops provides full support for password and MFA requirements through the following solutions: Specops Password Auditor gives organizations a good starting point by performing a read-only scan of Active Directory to identify password-policy gaps and highlight compromised passwords already in use. That gives security teams visibility into areas that may need remediation before an assessment. Specops Password Policy then enforces password length and granular organization-defined password rules while checking passwords against compromised credentials. Its Breached Password Protection capability uses a continuously updated database containing more than six billion compromised passwords, helping organizations address the IA-5 requirement to block commonly used or compromised credentials. Dynamic feedback at the password-change screen also tells users why a password has been rejected rather than leaving them to guess. Specops Secure Access addresses another frequent audit pain point by adding MFA to Windows authentication. It supports Windows logon, RDP and RADIUS, as well as offline and remote authentication for privileged and non-privileged accounts. That makes it particularly relevant to the IA-2(1) and IA-2(2) requirements for MFA. It also supports SSO for SaaS applications and sends authentication and security events into SOC, SIEM and analytics platforms through its Event API, which is useful where teams need both stronger authentication and clearer evidence of how those controls are operating. Is CJIS Moving Toward Zero Trust? CJIS v6.1 is not a Zero Trust standard, but many of its controls point in a similar direction. The policy places greater emphasis on establishing user identity, authenticating both privileged and non-privileged users, identifying managed devices and applying least privilege. Rather than treating network location alone as proof of trust, these controls focus on verifying who, and increasingly what, is requesting access. That makes technologies such as Specops Device Trust a natural complement to the direction of the policy. Binding identities to approved hardware and checking device security posture can add another layer of assurance around access to sensitive systems. Future CJIS revisions may develop this approach further, but agencies do not need to wait for that to happen. Strong identity, MFA, device assurance and restricted access are already useful ways to reduce risk around CJI. Prepare for CJIS v6.1 by Closing Identity Gaps CJIS v6.1 may be an incremental update, but it reinforces a broader change in how compliance is being approached: stronger technical controls, more frequent verification and more evidence that those controls continue to work. For organizations unsure where they stand, reviewing password exposure and MFA coverage is a practical place to start. To see how Specops can help, book a demo and see our solutions in action. Sponsored and written by Specops Software.

Entities

NIST SP 800-53 (technology)Specops Password Policy (product)Specops Software (vendor)