The FBI’s CJIS Security Policy has been through a significant period of change. Version 6.0, released on December 27, 2024, completed the policy modernization effort and moved CJIS toward a control-based structure closely aligned with NIST SP 800-53.
Version 6.1, published on June 25, 2026, further refines the modernized policy by addressing omissions, corrections and additions highlighted throughout 2025. For security teams already working toward the requirements introduced in v6.0, that means the overall direction has not changed.
However, there are still updates that warrant attention. And as crackdowns are becoming more common, organizations responsible for CJI should understand them to keep their security controls and compliance programs aligned with the latest standards.
What’s Changed Between CJIS v6.0 and v6.1?
One of the clearest technical changes concerns encryption. Under SC-13, which covers cryptographic protection for CJI in transit outside a physically secure location, v6.0 specified a symmetric cipher key of at least 128-bit strength. Version 6.1 raises that requirement to at least 256-bit strength.
SC-28, covering the protection of CJI at rest outside physically secure locations, has also been tightened, specifying encryption strength of at least 256-bit strength.
Another notable change is in vulnerability management. Under v6.0, CJIS required agencies to use vulnerability scanning tools at least quarterly to determine whether applicable security-related software and firmware updates had been installed, as well as following security incidents involving CJI.
Version 6.1 changes that frequency from quarterly to at least monthly.
Does CJIS v6.1 Change the Audit Requirements?
Version 6.1 is now the current CJIS Security Policy, but agencies shouldn’t assume that publication automatically means an immediate switch to a single new audit baseline.
... continue reading