Start with Identity
🇺🇸 United States · Information security

CJIS Security Policy

FBI Criminal Justice Information Services (CJIS) Security Policy

The CJIS Security Policy sets the minimum security requirements for anyone who accesses, processes, stores or transmits criminal justice information (CJI) from FBI CJIS systems. Its modernized control set, aligned with NIST SP 800-53 and the authenticator requirements of NIST SP 800-63B, requires multi-factor authentication for every user account. Version 6.1, effective June 26, 2026, is a corrections release that clarifies authentication cross-references, requires immediate incident reporting, and raises encryption and scanning requirements.

Jurisdiction:🇺🇸 United States
Type:Information security
In effect:Version 6.1, effective June 26, 2026
Authority:FBI Criminal Justice Information Services (CJIS) Division, with changes approved through the CJIS Advisory Policy Board

Who it applies to

Every individual, contractor, private entity, noncriminal justice agency representative, or member of a criminal justice entity with access to, or who operates in support of, criminal justice services and CJI, including cloud and technology vendors serving law enforcement.

Identity requirements

How it impacts identity systems

Identity areaImpact
Authentication & MFAMFA is required for all privileged and non-privileged accounts with access to CJI, and authenticators must meet AAL2 criteria, which rules out single-factor password access to criminal justice systems.
Identity governance (IGA)Account management controls require disabling expired, inactive, or anomalous accounts and periodic review of assigned privileges for everyone with CJI access, including contractors.
Privileged access (PAM)Privileged users have their own role-based security training requirements (AT-3), and least privilege (AC-6) applies to every account with access to CJI.
Audit, logging & accountabilityAudit record review (AU-6) and immediate incident reporting under v6.1's IR-6 make identity events part of the evidence agencies must be able to produce.

Penalties

Compliance is audited by state CJIS Systems Agencies and the FBI CJIS Division. Requirements that pre-date the policy's modernization and those marked Priority 1, including the MFA requirements, are auditable and sanctionable now; Priority 2 to 4 requirements are in a zero-cycle, auditable but not sanctionable, that ends September 30, 2027.

CJIS Security Policy: frequently asked questions

Does the CJIS Security Policy require MFA?
Yes. Controls IA-2(1) and IA-2(2) require multi-factor authentication for access to both privileged and non-privileged accounts, and both are Priority 1 requirements, meaning they are sanctionable in audits now rather than in the zero-cycle that runs to September 30, 2027.
What changed in CJIS Security Policy v6.1?
Version 6.1, effective June 26, 2026, is mainly a corrections release. For identity teams, it fixes authentication cross-references (including treating a phone-number change for out-of-band verification as binding a new authenticator), limits two FIPS 140 validation requirements at AAL2 to federal agencies, and requires immediate incident reporting. It also raises symmetric encryption to 256-bit for CJI in transit and at rest outside secure locations, and moves vulnerability-based update checks from quarterly to monthly.
Does CJIS apply to private companies?
Yes, if they access CJI or operate systems in support of criminal justice services. Cloud providers, software vendors, and contractors serving law enforcement agencies must meet the policy's requirements for the systems and people involved.
Educational summary, not legal advice. Confirm current requirements with the relevant authority or counsel. See all United States regulations or the full country index.
Last reviewed Suggest a correctionHow we research