FBI’s CJIS v6.1: What Security Teams Need to Know.

The FBI’s CJIS Security Policy has undergone significant changes with the release of version 6.1, building on the modernized policy introduced in version 6.0 last year. The latest update refines the security standards for handling and protecting Criminal Justice Information (CJI) by addressing omissions, corrections, and additions highlighted throughout 2025.

For organizations responsible for CJI, understanding these updates is crucial to maintaining alignment with the latest security standards and avoiding compliance issues. As law enforcement agencies continue to crack down on non-compliance, it’s essential that security teams familiarize themselves with the changes introduced in CJIS v6.1.

One of the notable technical changes concerns encryption requirements. The new policy raises the minimum symmetric cipher key strength for encrypting CJI in transit from 128-bit to at least 256-bit, while also increasing the encryption strength for protecting CJI at rest from outside physically secure locations. These updates reflect the FBI’s commitment to staying ahead of emerging threats and maintaining the highest security standards.

Another significant change is in vulnerability management. Under CJIS v6.0, agencies were required to use vulnerability scanning tools quarterly to identify unpatched software and firmware vulnerabilities. The new policy increases this frequency to at least monthly, emphasizing the importance of proactive vulnerability management in preventing security incidents.

The update also clarifies audit requirements for CJIS v6.1. While version 6.1 is now the current policy, agencies should not assume that publication means an immediate switch to a single new audit baseline. The modernized policy uses priority levels and phased audit dates, with Priority 1 controls sanctionable since October 2024. State CJIS Systems Agencies (CSAs) may also provide their own implementation guidance, so it’s essential for organizations to confirm current audit expectations with the relevant CSA.

A recurring theme in CJIS audits is the importance of demonstrating consistent compliance, not just having controls in place. As highlighted by Michigan State Police at their October 2025 CJIS Board meeting, multi-factor authentication (MFA) was among the top findings, along with issues related to new policies, BYOD policies, training, and security agreements.

The shift towards continuous assessment is evident, with MSP’s phased model showcasing a move away from traditional triennial audit visits. This approach emphasizes the need for organizations to regularly review and update their security controls, rather than relying on periodic audits.

In terms of password and MFA requirements, CJIS v6.1 maintains the same standards as v6.0, emphasizing the importance of organizational users being uniquely identified and authenticated. Priority 1 enhancements require MFA for both privileged and non-privileged accounts, regardless of access method.

To stay ahead of these changes, security teams should focus on implementing robust password controls, conducting regular vulnerability assessments, and maintaining consistent compliance with CJIS v6.1 requirements. By doing so, organizations can ensure they are adequately protecting CJI and meeting the FBI’s evolving security standards.


Source: Bleeping Computer — 2026-09-21