Skip to content
Tech News
← Back to articles

FBI's CJIS v6.1: What Security Teams Need to Know.

read original get YubiKey 5 Series Security Key → more articles
Why This Matters

CJIS v6.1 tightens encryption and vulnerability scanning requirements for organizations handling criminal justice information, raising the stakes for compliance teams already adapting to the v6.0 modernization. As enforcement and audits increase, security teams need to understand these incremental but consequential changes to avoid falling out of compliance.

Key Takeaways
Worth a Look

YubiKey 5 Series Security Key — As CJIS v6.1 pushes stronger encryption and access controls for CJI, hardware security keys like the YubiKey 5 make multi-factor authentication enforcement straightforward for security teams. It's a practical way to harden identity verification in line with tightened compliance standards. A simple, durable tool that supports the kind of access control rigor CJIS now demands.

See YubiKey 5 Series Security Key on Amazon → Affiliate link — we may earn a commission on purchases, at no extra cost to you. Product picked by AI based on this article; it is not a tested recommendation.

The FBI’s CJIS Security Policy has been through a significant period of change. Version 6.0, released on December 27, 2024, completed the policy modernization effort and moved CJIS toward a control-based structure closely aligned with NIST SP 800-53.

Version 6.1, published on June 25, 2026, further refines the modernized policy by addressing omissions, corrections and additions highlighted throughout 2025. For security teams already working toward the requirements introduced in v6.0, that means the overall direction has not changed.

However, there are still updates that warrant attention. And as crackdowns are becoming more common, organizations responsible for CJI should understand them to keep their security controls and compliance programs aligned with the latest standards.

What’s Changed Between CJIS v6.0 and v6.1?

One of the clearest technical changes concerns encryption. Under SC-13, which covers cryptographic protection for CJI in transit outside a physically secure location, v6.0 specified a symmetric cipher key of at least 128-bit strength. Version 6.1 raises that requirement to at least 256-bit strength.

SC-28, covering the protection of CJI at rest outside physically secure locations, has also been tightened, specifying encryption strength of at least 256-bit strength.

Another notable change is in vulnerability management. Under v6.0, CJIS required agencies to use vulnerability scanning tools at least quarterly to determine whether applicable security-related software and firmware updates had been installed, as well as following security incidents involving CJI.

Version 6.1 changes that frequency from quarterly to at least monthly.

Does CJIS v6.1 Change the Audit Requirements?

Version 6.1 is now the current CJIS Security Policy, but agencies shouldn’t assume that publication automatically means an immediate switch to a single new audit baseline.

... continue reading