Skip to main content
ComplianceData Protection

FBI Tightens CJIS Encryption, Vulnerability Rules

Secure briefing room with podium, chairs, and laptop displaying encryption graphics.

Version 6.1, published on June 25, 2026, further refines the modernized CJIS Security Policy and closes gaps identified during 2025.

How v6.1 builds on the December 27, 2024 modernization

Version 6.0, released on December 27, 2024, moved the FBI’s CJIS Security Policy to a control‑based structure closely aligned with NIST SP 800‑53. Version 6.1 does not change that overall direction; it “addresses omissions, corrections and additions highlighted throughout 2025,” according to the policy summary. For organizations that began work toward the v6.0 controls, the update is incremental—but meaningful in several technical areas that affect day‑to‑day compliance and control design.

Encryption requirements tightened: SC‑13 and SC‑28 now require 256‑bit strength

Two of the clearest technical changes are explicit increases in required cryptographic strength. Under SC‑13 (cryptographic protection for Criminal Justice Information, or CJI, in transit outside a physically secure location), v6.0 required a symmetric cipher key of at least 128‑bit strength; v6.1 raises that to at least 256‑bit strength. SC‑28, covering protection of CJI at rest outside physically secure locations, has been tightened in the same way to specify at least 256‑bit strength. These changes require organizations to review both transport and storage encryption configurations and, where necessary, upgrade cipher suites, key lengths or encryption tooling to meet the new baseline.

Vulnerability management frequency increases to monthly scans

Vulnerability management rules were also hardened. Where v6.0 required vulnerability scanning at least quarterly to determine whether applicable security‑related software and firmware updates had been installed (and to follow security incidents involving CJI), v6.1 changes that frequency to at least monthly. That shift from quarterly to monthly scanning shortens the window for detecting missing updates and forces teams to operationalize more frequent discovery, triage and remediation cycles.

Audit cadence and priority controls: staggered enforcement and state variation

Publication of v6.1 does not mean a single, immediate audit baseline. The modernized policy uses priority levels and phased audit and sanction dates: Priority 1 controls have been sanctionable since October 1, 2024; Priority 2, 3 and 4 controls are in “zero‑cycle” status until September 30, 2027. State CJIS Systems Agencies (CSAs) may issue their own implementation and assessment guidance. The bulletin cites Texas as continuing to audit against v5.9.5 through March 31, 2027 while agencies prepare for v6.1.

At its October 2025 meeting, the Michigan State Police (MSP) listed multi‑factor authentication (MFA) among top audit findings and described a move away from primarily triennial audit visits. MSP’s phased model includes baseline security assessments, quarterly meetings, System Security Plans, secure evidence submission and regular progress reviews, with continuous assessment planned later. Identification and Authentication is one of the control families scheduled for assessment during FY2027. A practical step the policy recommends: confirm current audit expectations with the relevant CSA rather than assuming a single federal baseline.

Identification and Authentication remains a central focus: MFA and password controls

The Identification and Authentication (IA) family retains sharp emphasis. IA‑2 requires organizational users to be uniquely identified and authenticated; Priority 1 enhancements require MFA for both privileged and non‑privileged accounts, regardless of whether access is local, network‑based or remote. Password controls under IA‑5 are explicit: agencies must maintain a list of commonly used, expected or compromised passwords, update that list at least quarterly and when passwords may have been compromised, and compare current memorized secrets against it quarterly. Prospective passwords must be checked against the list when users create or change them.

These requirements align with operational risk observations cited in the briefing: Verizon’s Data Breach Investigation Report found stolen credentials involved in 44.7% of breaches—an outcome the policy’s strengthened authentication and password controls are intended to reduce.

How Specops solutions are presented against IA requirements (vendor‑supplied mapping)

The source material includes vendor guidance from Specops Software mapping specific products to CJIS IA needs. Specops Password Auditor performs a read‑only Active Directory scan to identify password‑policy gaps and compromised passwords. Specops Password Policy enforces password length and organization‑defined rules, checks passwords against a continuously updated breached‑password database of more than six billion compromised passwords, and provides dynamic feedback at the password‑change screen. Specops Secure Access adds MFA to Windows authentication (Windows logon, RDP, RADIUS), supports offline and remote authentication for privileged and non‑privileged accounts, and exports authentication and security events via an Event API. The writeup also cites Specops Device Trust as a way to bind identities to approved hardware and assess device posture.

Readers should note the article is “Sponsored and written by Specops Software,” and the vendor mapping is presented as tools that can assist with meeting specific IA‑2 and IA‑5 obligations.

Conclusion: v6.1 is an incremental but concrete tightening of CJIS controls—stronger encryption, faster vulnerability scanning, and continued focus on MFA and password hygiene. Agencies and CSAs face a two‑track reality: Priority 1 controls are already sanctionable, while other controls remain in zero‑cycle until September 30, 2027. The immediate, practical actions the source recommends are straightforward and verifiable: inventory where CJI is stored and in transit, ensure encryption meets 256‑bit strength where required, shift vulnerability scanning toward monthly cadence, and confirm the active audit baseline with the relevant CSA.

Read the original report on BleepingComputer