CJIS Security Policy v6.1: Key Changes, Audit Requirements, Password Rules, and MFA
The FBI’s Criminal Justice Information Services (CJIS) Security Policy is undergoing significant change. Version 6.0, released on December 27, 2024, completed the policy modernization effort and moved CJIS to a control-based structure closely aligned with NIST SP 800-53.
CJIS Security Policy v6.1 was published on June 25, 2026. It provides further refinements addressing omissions, amendments, and additions highlighted throughout 2025. For security teams already working toward the requirements introduced in v6.0, the overall direction remains unchanged.
However, organizations responsible for Criminal Justice Information (CJI) still have important updates to address. As enforcement becomes more common, agencies need to understand CJIS v6.1 and keep their security controls and compliance programs aligned with the latest requirements.
What changed between CJIS v6.0 and v6.1?
One of the most significant technical changes in CJIS v6.1 concerns encryption.
Encryption requirements increased to 256-bit strength
SC-13 covers cryptographic protection for CJI transmitted outside a physically secure location. In v6.0, the control specified symmetric encryption keys with at least 128-bit strength. Version 6.1 increases that requirement to at least 256-bit strength.
SC-28, which covers the protection of CJI stored outside a physically secure location, has also been strengthened to specify encryption with at least 256-bit strength.
Vulnerability scanning is now required at least monthly
CJIS v6.0 required government agencies to use vulnerability-scanning tools at least quarterly to determine whether applicable security-related software and firmware updates had been installed following a security incident involving CJIS.
Version 6.1 changes that frequency from quarterly to at least monthly. Agencies should review their vulnerability-management processes and ensure they can consistently document scans, findings, remediation, and follow-up activity.
Will CJIS v6.1 change audit requirements?
Although version 6.1 is the current CJIS Security Policy, agencies should not assume that its publication automatically creates a single, immediate audit baseline for every organization.
The updated policy uses priority levels and tiered audit and sanction dates. Priority 1 controls became subject to sanctions starting October 1, 2024. Priority 2, 3, and 4 management will remain in “zero cycle” status until September 30, 2027.
State CJIS Systems Agencies (CSAs) may also provide their own implementation and evaluation guidance. For example, the state of Texas continues its audit on v5.9.5 through March 31, 2027, while the agency prepares for v6.1.
A practical first step is to check with the relevant CSA about current audit expectations while working toward the new requirements.
Waiting until controls become sanctionable can create unnecessary work later, especially as CJIS audit programs move toward more continuous evaluation.
Verizon’s data breach investigation report found that 44.7% of breaches involved stolen credentials.
Easily protect your Active Directory with compliant password policies, block over 4 billion leaked passwords, improve security, and dramatically reduce support effort.
What do government agencies find during CJIS audits?
Findings from government agency audits show that identity and access controls remain a common challenge. At the October 2025 CJIS Board Meeting, the Michigan State Police (MSP) listed multi-factor authentication (MFA) among the requirements being addressed by police departments.
Other recurring audit issues included:
- New and updated policies
- Bring-your-own-device (BYOD) policies and procedures
- Security awareness training
- Security agreements
- Event logging
- Fingerprinting
The same meeting outlined a move away from relying primarily on audit visits every three years. MSP’s step-by-step model includes a baseline security assessment, quarterly meetings, system security planning, secure evidence submissions, and periodic progress reviews, with ongoing evaluations planned later in the process.
Identification and Authentication is one of the control families scheduled for evaluation during FY2027.
This is an important consideration for agencies planning CJIS initiatives. Compliance increasingly depends on the ability to establish controls and consistently demonstrate that those controls are operating effectively.
Are CJIS v6.1 password and MFA requirements different?
There are no major changes to the identification and authentication requirements between CJIS v6.0 and v6.1. However, the existing requirements remain important for agencies preparing for audits.
CJIS MFA requirements
IA-2 requires organizational users to be uniquely identified and authenticated. Priority 1 enhancements require MFA for both privileged and unprivileged accounts, regardless of whether access is local, network-based, or remote.
Agencies should verify that MFA coverage includes the accounts, systems, and access methods within the scope of their CJIS environment.
CJIS password requirements
IA-5 requires agencies to maintain a list of commonly used, expected, or compromised passwords. The list must be updated at least quarterly and whenever a password may have been compromised. Agencies must also compare currently memorized confidential information quarterly.
When users create or change passwords, the proposed passwords must also be checked against the list. These requirements make compromised-password detection and enforcement important parts of a CJIS compliance program.
How Specops supports CJIS identification and authentication
Specops supports CJIS password and MFA requirements through the following solutions:
Specops Password Auditor
Specops Password Auditor provides a starting point by performing a read-only scan of Active Directory. It identifies gaps in password policies and highlights compromised passwords already in use, helping security teams understand where remediation may be required before an assessment.
Specops Password Policy
Specops Password Policy enforces password length and detailed password rules defined by the organization while checking passwords against compromised credentials. Its Breached Password Protection feature uses a continuously updated database containing more than 6 billion breached passwords to help organizations address IA-5 requirements related to commonly used or compromised credentials.
Dynamic feedback on the password-change screen explains why a password was rejected, helping users choose an acceptable password without guesswork.
Specops Secure Access
Specops Secure Access adds MFA to Windows authentication, addressing a frequently encountered audit pain point. It supports Windows logon, RDP, and RADIUS, as well as offline and remote authentication for privileged and non-privileged accounts.
This makes the solution relevant to the IA-2(1) and IA-2(2) MFA requirements. It also supports single sign-on for SaaS applications and sends authentication and security events to SOCs, SIEMs, and analytics platforms through event APIs.
These capabilities help teams strengthen authentication while collecting clearer evidence of how their controls are operating.
Is CJIS moving toward zero trust?
CJIS v6.1 is not a zero trust standard, but many of its controls point in a similar direction.
The policy focuses on establishing user identity, authenticating privileged and non-privileged users, identifying managed devices, and enforcing least privilege. These controls emphasize validating who is requesting access and what they are requesting rather than treating network location alone as evidence of trust.
Specops Device Trust complements this policy direction by binding identities to authorized hardware and checking the security state of devices before access to sensitive systems is granted.
Future CJIS revisions may further develop this approach, but agencies do not need to wait. Strong identity controls, MFA, device assurance, and access restrictions can already help reduce CJI risks.
Prepare for CJIS Security Policy v6.1
CJIS v6.1 may be an incremental update, but it reinforces broader changes in compliance: stronger technical controls, more frequent verification, and greater evidence that controls continue to work.
For organizations that are unsure where they stand, reviewing password exposure and MFA coverage is a practical starting point. Agencies should also confirm encryption strength, vulnerability-scanning frequency, audit expectations, and evidence-collection processes with their relevant CSAs.
To see how Specops can help you, book a demo and see the solution in action.
Sponsored and written by Specops Software.
Source: www.bleepingcomputer.com


