CJIS Security Policy
The FBI's security requirements for any agency or vendor that touches criminal justice information — the gate for public-safety software.
6.1 · FBI Criminal Justice Information Services · published 2026-06-25
00Answer
01Standing
Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.
CJIS Security Policy is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.
le.fbi.gov returns 403 to automated fetch. v6.1 is evidenced by the FBI's own file-repository filename (cjis_security_policy_v6-1_20260625.pdf); read the cover page from a browser session before treating this as primary.
02Registry record
- Registry status
- Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
- Control units
- Not on record — no catalog ingested and no authority-published count cited.
- Control families
- Policy areas 1-13 · Access control · Identification and authentication · Audit and accountability · Incident response
- Applies to
- law enforcement · public safety · government · US
- Verification
- Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
- Pending change
- The FBI frames the transition not by version number but by a zero-cycle running 2024-10-01 to 2027-09-30 for lower-priority modernized requirements (Priority 2 through 4): findings are recorded but not yet sanctionable. Priority 1 controls have been sanctionable since 2024-10-01. A state's own audit program may still cite an older baseline against its own timeline (for example, Texas DPS audits have historically referenced v5.9.5) — that is a state-sourced fact, not an FBI one, and should be verified per state before quoting an enforced version.Expected: 2027-09-30 (zero-cycle closes)
03Version ledger
| 5.9.5 | Superseded | date not published |
| 6.0 | Superseded · supersedes 5.9.5 | 2024-12-27 |
| 6.1 | Current edition · supersedes 6.0 | 2026-06-25 |
03aCoexisting versions
- 6.1 — Priority 2 through 4 modernized requirements (zero-cycle)
Applies to: Every agency and vendor covered by v6.1 — findings on these lower-priority requirements are recorded but not sanctioned during the zero-cycle
Coexistence scheduled to end 2027-09-30
Source (opens in a new tab)
05Change history
- 2027-09-30CJIS Security Policy: the coexistence window for 6.1 — Priority 2 through 4 modernized requirements (zero-cycle) (applying to Every agency and vendor covered by v6.1 — findings on these lower-priority requirements are recorded but not sanctioned during the zero-cycle) is scheduled to close.
- 2027-09-30CJIS Security Policy: The FBI frames the transition not by version number but by a zero-cycle running 2024-10-01 to 2027-09-30 for lower-priority modernized requirements (Priority 2 through 4): findings are recorded but not yet sanctionable. Priority 1 controls have been sanctionable since 2024-10-01. A state's own audit program may still cite an older baseline against its own timeline (for example, Texas DPS audits have historically referenced v5.9.5) — that is a state-sourced fact, not an FBI one, and should be verified per state before quoting an enforced version.
- 2026-06-25CJIS Security Policy 6.1 supersedes 6.0 and is the current edition.
- 2024-12-27CJIS Security Policy 6.0 supersedes 5.9.5.
06Related frameworks
- ASD Essential EightMaturity Model (November 2023)
Also applies to government · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.
- IRS Publication 1075Rev. 11-2021
Also applies to government · The IRS's safeguard requirements for any agency, contractor, or state/local entity that receives federal tax information — relevant to any government contractor or CMS-adjacent SaaS vendor handling federal tax data.
- NERC CIPCIP-002 through CIP-015 (per-standard versions)
Commonly assessed together · The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number.
- NYDFS 23 NYCRR 50023 NYCRR 500 (2023 amendments)
Commonly assessed together · New York's cybersecurity regulation for banks, insurers, and other DFS-licensed entities — with a named CISO, board reporting, and 72-hour incident notice.