Skip to main content
—
Framework library
Framework module · cjis-security-policy

CJIS Security Policy

The FBI's security requirements for any agency or vendor that touches criminal justice information — the gate for public-safety software.

6.1 · FBI Criminal Justice Information Services · published 2026-06-25

Standing today
Directory entry

00Answer

from the registry record
What is CJIS Security Policy?
The FBI's security requirements for any agency or vendor that touches criminal justice information — the gate for public-safety software.
Who does CJIS Security Policy apply to?
CJIS Security Policy applies to law enforcement, public safety, government, US, per FBI Criminal Justice Information Services.
What is the current version of CJIS Security Policy?
The current edition is 6.1, issued by FBI Criminal Justice Information Services and published 2026-06-25. Source: https://le.fbi.gov/file-repository/cjis_security_policy_v6-1_20260625.pdf/view.
What does an assessment under CJIS Security Policy require?
No control catalog has been ingested for CJIS Security Policy yet — the registry tracks it as planned (Tracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented), so an assessment under this framework currently requires the authority's own catalog rather than a ControlFrame-parsed one.

01Standing

Directory entry

Authority and version facts, with a parsed public catalog when available; no tenant blueprint or executable evidence method is activated.

CJIS Security Policy is tracked in the registry — authority, version ledger, verification — and nothing else is modelled for it yet. Import its catalog to begin.

le.fbi.gov returns 403 to automated fetch. v6.1 is evidenced by the FBI's own file-repository filename (cjis_security_policy_v6-1_20260625.pdf); read the cover page from a browser session before treating this as primary.

02Registry record

checked 2026-09-06
Registry status
Planned · namedTracked metadata: we name the regime and monitor its issuing authority. No control or requirement model is implemented.
Control units
Not on record — no catalog ingested and no authority-published count cited.
Control families
Policy areas 1-13 · Access control · Identification and authentication · Audit and accountability · Incident response
Applies to
law enforcement · public safety · government · US
Verification
Secondary — corroborated across independent sources; the authority blocks automated fetch or does not state it plainly. checked 2026-09-06
Pending change
The FBI frames the transition not by version number but by a zero-cycle running 2024-10-01 to 2027-09-30 for lower-priority modernized requirements (Priority 2 through 4): findings are recorded but not yet sanctionable. Priority 1 controls have been sanctionable since 2024-10-01. A state's own audit program may still cite an older baseline against its own timeline (for example, Texas DPS audits have historically referenced v5.9.5) — that is a state-sourced fact, not an FBI one, and should be verified per state before quoting an enforced version.Expected: 2027-09-30 (zero-cycle closes)

03Version ledger

3 editions
5.9.5Supersededdate not published
6.0Superseded · supersedes 5.9.52024-12-27
6.1Current edition · supersedes 6.02026-06-25

03aCoexisting versions

1 other version in force
  1. 6.1 — Priority 2 through 4 modernized requirements (zero-cycle)

    Applies to: Every agency and vendor covered by v6.1 — findings on these lower-priority requirements are recorded but not sanctioned during the zero-cycle

    Coexistence scheduled to end 2027-09-30

    Source (opens in a new tab)

05Change history

06Related frameworks

scored from registry facts
  1. ASD Essential EightMaturity Model (November 2023)

    Also applies to government · The Australian Signals Directorate's prioritized baseline of eight cyber mitigations, implemented through maturity levels zero to three. Independent assessment may be required by policy or contract, but the model is not a universal certification scheme.

  2. Also applies to government · The IRS's safeguard requirements for any agency, contractor, or state/local entity that receives federal tax information — relevant to any government contractor or CMS-adjacent SaaS vendor handling federal tax data.

  3. NERC CIPCIP-002 through CIP-015 (per-standard versions)

    Commonly assessed together · The mandatory, auditable cybersecurity standards for the North American bulk electric system. NERC versions each CIP standard separately — there is no framework-wide version number.

  4. NYDFS 23 NYCRR 50023 NYCRR 500 (2023 amendments)

    Commonly assessed together · New York's cybersecurity regulation for banks, insurers, and other DFS-licensed entities — with a named CISO, board reporting, and 72-hour incident notice.

CJIS Security Policy | ControlFrame