Start with Identity
Compliance

CJIS Security Policy

The CJIS Security Policy is the FBI's set of minimum security requirements for anyone who accesses, processes, stores or transmits criminal justice information (CJI) from FBI Criminal Justice Information Services systems, including state and local agencies and the private companies that support them.

Its modernized control set follows the NIST SP 800-53 families and borrows its authenticator rules from NIST SP 800-63B. For identity teams, the headline requirement is multi-factor authentication for every privileged and non-privileged account with access to CJI, plus a compromised-password list checked quarterly and a minimum user-chosen password length of 8 characters. Version 6.1, effective June 26, 2026, is a corrections release that clarifies authentication cross-references, requires incidents to be reported immediately rather than after confirmation, and raises symmetric encryption for CJI to 256-bit. The MFA requirements are Priority 1 and sanctionable now; lower-priority requirements stay auditable but not sanctionable until September 30, 2027.

See also: CJIS Security Policy requirements, NIST SP 800-63, MFA, FedRAMP

Last reviewed By SWI Community TeamSuggest a correctionHow we research