Table of Contents

Free Active Directory Auditing Tool

Try it now
CJIS security policy

CJIS Security Policy: Everything You Need to Know

Table of Contents

Criminal Justice Information (CJI) is some of the most sensitive data in the US and must be secured wherever it is accessed, processed, stored or shared. The FBI Criminal Justice Information Services (CJIS) Security Policy sets the minimum security requirements for protecting that information throughout its lifecycle. It applies to criminal justice agencies, as well as non-criminal justice agencies, contractors, private organizations and other parties that access CJI or support criminal justice services.

The latest update is CJIS Security Policy version 6.1, released by the FBI on June 25, 2026. With crackdowns becoming more common, organizations responsible for CJI need to understand the CJIS Security Policy, know which requirements apply to them and keep their security controls and compliance programs aligned with the standards that govern their environment.

What’s new in CJIS Security Policy v6.1?

Version 6.1 of the CJIS Security Policy is a correction and omissions cleanup of version 6.0. It builds on the framework introduced in v6.0 rather than replacing it with another wholesale redesign.

CJIS Security Policy v6.0, released on December 27, 2024, marked the completion of the policy modernization effort. Version 6.1 followed on June 25, 2026, incorporating changes developed during calendar year 2025. The latest version can be found here, and specific edits to the policy are highlighted here. The updates include:

  • Minimum encryption strength for SC-13 and SC-28 have increased from 128-bit to 256-bit.
  • Agencies must confirm that applicable software or firmware updates are installed using vulnerability scanning tools at least monthly (rather than quarterly), or following any security incidents involving CJI.

CJIS v6.1 isn’t yet an audit baseline, and agencies are still assessed against v6.0. The update is currently better treated as the next iteration of the modernized policy, refining the requirements already in place.

desktop screen with warnings
How many of your end-users are using a compromised password in AD?

What are the CJIS Security Policy Requirements?

The CJIS Security Policy requirements are outlined in 20 policy areas, which include access controls and authentication, incident response, system security and supply chain risk management. Across the 20 policy areas, the main responsibilities include:

  • Controlling who can access CJI by managing accounts (including applying least privilege), and removing access when it is no longer required.
  • Identifying and authenticating users, including using multi-factor authentication (MFA) for both privileged and non-privileged accounts.
  • Managing personnel security and training, ensuring that users understand their responsibilities and providing role-based training.
  • Protecting CJI wherever it is handled, stored, accessed, and transmitted.
  • Securing and maintaining systems by using secure configurations, managing vulnerabilities, and carrying out maintenance securely.
  • Preparing for disruption with robust contingency and recovery plans, as well as reporting incidents correctly.
  • Managing third-party and supply chain risk with formal agreements and expectations in place for service providers and contactors.

How Specops Helps: Identification and Authentication (IA)

A key part of the CJIS Security Policy is ensuring that every user accessing CJI is uniquely identified and authenticated so that activity can be attributed to an individual. The identity requirements in v6.1 remain unchanged, with agencies still needing to maintain a banned password list and multi-factor MFA still mandatory.

Specops provides full support for password and MFA requirements through the following solutions:

Specops Password Auditor is a free tool that performs a read-only scan of your Active Directory, seeing if your existing password policies are compliant with the latest version of CJIS, as well as other major frameworks and regulations.  It also identifies any compromised passwords your organization is using, providing crucial visibility that aligns with CJIS IA requirements.

Specops Password Policy enforces CJIS-aligned password rules directly in Active Directory, including length and complexity requirements, and expiration or “change on evidence of compromise” logic. To help with the user experience, it provides dynamic feedback at the password change screen. It also aligns with IA-5 blocklist requirements with a continuously updated database of more than 6 billion compromised passwords through the Breached Password Protection feature.

Specops Secure Access supports CJIS IA-2(1) and 2(2) by adding MFA to Windows logon, helping protect an area that presents greater risk when access relies on passwords alone. It covers RDP, RADIUS, and both offline and remote logons for privileged and non-privileged accounts.  It also supports SSO for SaaS applications and integrates with SOC, SIEM, and analytics platforms through its Event API. This helps simplify administration while giving security teams clear visibility into authentication and security events.

For more information about how Specops helps you comply with the CJIS Security Policy, read our blogs on the password and MFA requirements.

Continuous Scan Password Policy icon
Continuously block 6 billion+ compromised passwords in your Active Directory

Is the CJIS Security Policy Implementing Zero Trust Controls?

CJIS v6.1 reflects a closer alignment with Zero Trust principles, with greater emphasis on verifying users and devices rather than relying primarily on perimeter-based security. Access is also becoming more restricted and segmented, helping limit how freely users can move between systems.

This approach supports the wider aim of the CJIS Security Policy: protecting sensitive law enforcement data by making sure access is granted only to trusted users and devices, and only where it is needed.

Solutions such as Specops Device Trust support this approach by binding identities to specific hardware and continually checking the security posture of those devices. If future CJIS updates continue in this direction, technologies that support Zero Trust principles are likely to become an increasingly important part of maintaining compliance.

Move Towards CJIS Compliance with Specops

Most law enforcement agencies are audited at least once every three years, with ongoing compliance expected between audits. Specops helps you meet CJIS authentication requirements with confidence by:

  • Helping you identify whether your current password policies are CJIS-compliant with Specops Password Auditor.
  • Enforcing CJIS-aligned password policies in Active Directory and blocking compromised passwords through Specops Password Policy with Breached Password Protection.
  • Adding MFA for privileged and non-privileged accounts for Windows Logon as well as SSO support with Specops Secure Access.

If you’re interested in seeing how Specops can help you comply with CJIS, book a demo to see our solutions in action.

Common CJIS Security Policy Questions

Who has to comply with CJIS?

CJIS requirements apply broadly to organizations and individuals that access CJI or operate systems and services that support it. This includes criminal justice agencies, authorized noncriminal justice agencies, contractors, private entities, and other service providers where their work brings them within the scope of the policy.

Does CJI have to be encrypted?

CJIS requires CJI to be encrypted when stored or transmitted outside a physically secure location, using approved cryptographic protections. Certain types of CJI, such as system backups, have additional encryption requirements even within secure environments.

Does CJIS require MFA?

Yes. CJIS Security Policy v6.1 requires multi-factor authentication for access to both privileged and non-privileged organizational user accounts. MFA means using two or more different authentication factors, such as something the user knows, possesses, or is.

The policy aligns its CJIS authentication risk profile with Authenticator Assurance Level 2 (AAL2), for which MFA is required.

Last updated on August 24, 2026

Written by

Daniel Imber

Daniel is a cybersecurity writer based in the UK, with more than four years' experience writing about B2B technology and cybersecurity.

Back to Blog

Related Articles

  • CJIS Password Policy Requirements

    The Criminal Justice Information Services Division (CJIS) is a division of the FBI that provides tools and services to law enforcement agencies around the country. Through systems like the National Crime Information Center (NCIC), Integrated Automated Fingerprint Identification System (IAFIS), and the National Instant Criminal Background Check System (NICS), CJIS helps agencies manage investigations, conduct…

    Read More
  • CJIS compliance: How to meet password and MFA requirements

    If you’re responsible for password security at a law enforcement agency or organization that handles criminal justice data, CJIS compliance isn’t optional. It’s the baseline for protecting some of the most sensitive information in the country. The FBI’s Criminal Justice Information Services (CJIS) Security Policy sets strict standards for anyone accessing criminal justice information. Version…

    Read More
  • Investigating CJIS? Lock down password compliance with Specops

    When we think about criminal justice and cybersecurity, the imagination isn’t immediately drawn to compliance. Meeting policy requirements isn’t as flashy or exciting as a hooded hacker using a laptop to defeat their foes.  The realm of cybercrime is known for tall tales, mysterious individuals, and underground digital spaces that both Blackhat and Whitehat hackers are…

    Read More

Free Active Directory Auditing Tool!