Table of Contents

Free Active Directory Auditing Tool

Try it now
CJIS compliance risks

CJIS v6.1 Compliance Risks: Common Authentication Audit Findings

Table of Contents

For agencies handling Criminal Justice Information (CJI), compliance with the FBI’s Criminal Justice Information Services (CJIS) Security Policy is mandatory. And with state-level scrutiny increasing, understanding the standards for CJIS compliance can help agencies identify gaps before an audit does. After all, having security controls in place doesn’t necessarily mean they will meet CJIS requirements.

Washington State Patrol (WSP) discovered this when audited by the FBI against CJIS Security Policy v6.0 in June 2025. Among the findings, the FBI identified gaps in multi-factor authentication (MFA) for both privileged and non-privileged accounts, which is mandated in IA-2. WSP subsequently told agencies that it was preparing its response and developing a plan to resolve the findings.

WSP is far from the only agency grappling with CJIS requirements, particularly with the recent release of the latest edition, version 6.1. However, this is a maintenance release and not yet an audit baseline; it also largely retains the classifications established in the auditable v6.0.

To help agencies that handle CJI comply with the latest standards, this Specops guide will answer the following questions:

  • What should agencies be checking to meet the latest CJIS requirements?
  • Where are agencies getting caught out?

What Does CJIS Compliance Require Under v6.1?

CJIS Security Policy v6.1 sets the latest requirements for protecting CJI. Existing requirements and Priority 1 controls have been sanctionable since October 1, 2024. Priority 2, 3 and 4 controls remain in a zero-cycle until September 30, 2027, giving agencies time to implement and test them before they become sanctionable.

It’s worth noting that while CJIS sets the minimum standard, a state’s CJIS Systems Agency can impose additional or stricter requirements, and audit-transition schedules can vary. For example, Texas is continuing to audit against v5.9.5 through March 31, 2027 while agencies prepare for v6.1.

Five Focus Areas for CJIS Compliance

1. Multi-Factor Authentication

CJIS requires MFA for both privileged and non-privileged accounts under Priority 1 controls IA-2(1) and IA-2(2). Ensure your solution works across all accounts, workstations, mobile devices, remote access, legacy applications and third-party access. For instance, Maryland’s Department of Public Safety and Correctional Services approved the purchase of 18,000 YubiKey security tokens in 2025 specifically to ensure that coverage and meet CJIS MFA requirements.

2. Passwords

CJIS v6.1 requires agencies to maintain and regularly update a list of commonly used, expected or compromised passwords, check current passwords against it, and screen new passwords before they are accepted. Crucially, those standards should be applied consistently across the environment.

If you’re not sure how much visibility you have into your current password health, Specops Password Auditor provides a clear starting point. Its free, read-only Active Directory scan shows where your current password policies align with the CJIS Security Policy and flags password-related risks, including accounts using known compromised passwords. This gives teams a clearer view of where action may be needed to support CJIS compliance.

3. Account Management and Privileges

Accounts must be managed throughout their lifecycle, including when employees or contractors leave or change roles. CJIS also requires annual reviews of user privileges and logging of privileged functions, so identity management needs ongoing attention rather than a one-off configuration.

4. Logging

It isn’t enough to generate logs; agencies need the right audit information and processes to review it. WSP’s FBI audit, for example, identified audit-record and account-management logging issues alongside its MFA findings.

5. Audit Readiness

While agencies are audited at least once every three years, it’s expected that compliance will be maintained between audits. Keep policies, system inventories, MFA evidence, access reviews, logs, training records and vendor documentation current rather than pulling them together when an audit approaches.

Continuous Scan Password Policy icon
Continuously block 6 billion+ compromised passwords in your Active Directory

Where Agencies Find Gaps: Recent CJIS Compliance Case Studies

Platteville

The City of Platteville, Wisconsin, completed and submitted a CJIS audit in 2024 and made responding to the findings one of its IT goals for 2025. The city’s budget also recorded that MFA had been implemented across its departments except Police, although the public documents don’t establish that this was itself a CJIS audit finding.

Password policy, however, was directly tied to the audit. By May 2025, Platteville’s IT work plan included developing a city-wide password policy and addressing a CJIS audit finding in the same area.

Platteville highlights the continued importance of passwords, even where MFA is in use. Agencies and organizations working toward CJIS compliance need password policies that reflect the requirements in v6.1 and, just as importantly, are applied consistently wherever CJI is handled.

Michigan

At its October 2025 CJIS Board meeting, Michigan State Police (MSP) listed MFA among its top CJIS audit findings, alongside areas such as new policies, BYOD procedures, training, security agreements and event logging.

The same meeting outlined how MSP is changing how it assesses compliance. Its new phased approach focuses on continuous engagement rather than relying only on triennial audit visits. The model includes baseline security assessments, quarterly meetings, System Security Plans, secure submission of evidence, regular progress meetings and, eventually, continuous assessment. Identification and Authentication is among the control families scheduled for assessment during FY2027.

How Specops Helps You Comply with CJIS v6.1 Requirements

CJIS compliance is moving towards continuous verification of whether controls work. With MFA becoming a common appearance in findings, authentication is an area agencies should test continuously rather than waiting for the next audit.

Specops helps with those compliance efforts as a complete vendor to meet password and MFA requirements:

Specops Password Policy applies CJIS-aligned password rules directly in Active Directory, including length and complexity requirements, plus changes at expiration or when there is evidence of compromise. To reduce user friction, dynamic feedback at the password change screen helps users create strong, compliant passwords first time. The Breached Password Protection feature supports IA-5 blocklist requirements, checking passwords against a continuously updated database of more than 6 billion compromised credentials.

Specops Secure Access supports CJIS MFA requirements by adding a second authentication factor to Windows Logon, with coverage for RDP, RADIUS, offline and remote logons. This helps apply consistent MFA controls across your environment, with flexible factor options including authenticator apps and YubiKeys. Event API integrations with SOC, SIEM and analytics platforms provide evidence for compliance reporting, while SSO support centralizes authentication and helps reduce the identity attack surface.

If you’re interested in seeing how Specops can help your agency comply with the latest CJIS standards, contact us today or book a demo to see our solutions in action.

Common CJIS Compliance Questions

What is the latest CJIS Security Policy?

The latest version is CJIS Security Policy v6.1, published by the FBI on June 25, 2026. It follows v6.0, which introduced the modernized control structure and priority model now used across the policy.

Are all CJIS v6.1 requirements currently auditable and sanctionable?

No. Existing requirements and Priority 1 controls are sanctionable, while Priority 2, 3 and 4 modernized controls remain in a zero-cycle until September 30, 2027. State audit schedules can also vary, so agencies should check the requirements and timelines set by their CJIS Systems Agency.

What are the CJIS password requirements under v6.1?

CJIS takes a broader approach than traditional password-complexity rules. User-selected passwords must be at least eight characters long, and agencies must allow longer passwords and passphrases. They must also maintain a list of common and compromised passwords, compare existing passwords against it, and reject new passwords that appear on the list.

Who needs to comply with CJIS?

The policy applies to agencies and organizations that submit or receive information through FBI CJIS systems and the people supporting those services, including relevant contractors and private entities with access to CJI.

What happens if an agency fails a CJIS audit?

A finding does not automatically mean an agency loses CJIS access. Audit participants are expected to respond with corrective actions explaining how and when the issue will be addressed, and findings can remain under review until sufficient remediation has taken place. Continued failure to reach compliance can lead to further action or sanctions. Washington State Patrol, for example, was developing a remediation plan after its 2025 FBI audit identified several findings.

Can an agency be CJIS compliant if its vendor isn’t?

Agencies remain responsible for protecting CJI when third parties are involved, so vendor compliance needs to be part of the review. This includes changes that could affect a vendor’s risk profile, such as acquisitions or mergers with another entity.

Michigan provides a useful example: in 2025, the state reported that it had stopped using media-disposal provider Vital Records Control after an assessment found the vendor out of compliance.

Last updated on August 27, 2026

Written by

Daniel Imber

Daniel is a cybersecurity writer based in the UK, with more than four years' experience writing about B2B technology and cybersecurity.

Back to Blog

Related Articles

  • CJIS Password Policy Requirements

    The Criminal Justice Information Services Division (CJIS) is a division of the FBI that provides tools and services to law enforcement agencies around the country. Through systems like the National Crime Information Center (NCIC), Integrated Automated Fingerprint Identification System (IAFIS), and the National Instant Criminal Background Check System (NICS), CJIS helps agencies manage investigations, conduct…

    Read More
  • CJIS v6.1 Compliance: How to Meet Password and MFA Requirements

    If you’re responsible for password security at a law enforcement agency or organization that handles criminal justice data, CJIS compliance isn’t optional. It’s the baseline for protecting some of the most sensitive information in the country. The FBI’s Criminal Justice Information Services (CJIS) Security Policy sets strict standards for anyone accessing criminal justice information. Version…

    Read More
  • CJIS Security Policy v6.1: Everything You Need to Know

    Learn what the CJIS Security Policy requires, who it applies to, key controls, and how Specops supports compliance.

    Read More

Free Active Directory Auditing Tool!