CJIS Security Policy
FBI Criminal Justice Information Services (CJIS) Security Policy
The CJIS Security Policy sets the minimum security requirements for anyone who accesses, processes, stores or transmits criminal justice information (CJI) from FBI CJIS systems. Its modernized control set, aligned with NIST SP 800-53 and the authenticator requirements of NIST SP 800-63B, requires multi-factor authentication for every user account. Version 6.1, effective June 26, 2026, is a corrections release that clarifies authentication cross-references, requires immediate incident reporting, and raises encryption and scanning requirements.
Who it applies to
Every individual, contractor, private entity, noncriminal justice agency representative, or member of a criminal justice entity with access to, or who operates in support of, criminal justice services and CJI, including cloud and technology vendors serving law enforcement.
Identity requirements
- Implement multi-factor authentication for access to both privileged and non-privileged accounts (IA-2(1) and IA-2(2), Priority 1), regardless of local, network, or remote access
- Meet AAL2 criteria where CJI is accessed: a multi-factor authenticator or two single-factor authenticators, approved cryptography, and at least one replay-resistant authenticator
- Maintain a list of commonly used, expected, or compromised passwords, update it quarterly, and compare current passwords against it quarterly
- Require user-chosen passwords of at least 8 characters, allow long passphrases, never truncate secrets, and force a new password after account recovery
- Treat changing a pre-registered phone number used for out-of-band verification as binding a new authenticator, and time out session-binding secrets according to the assurance level (clarified in v6.1)
- Report incidents and suspected incidents immediately to the CJIS Systems Officer or equivalent and the FBI CJIS Information Security Officer, not only after confirmation (v6.1)
How it impacts identity systems
| Identity area | Impact |
|---|---|
| Authentication & MFA | MFA is required for all privileged and non-privileged accounts with access to CJI, and authenticators must meet AAL2 criteria, which rules out single-factor password access to criminal justice systems. |
| Identity governance (IGA) | Account management controls require disabling expired, inactive, or anomalous accounts and periodic review of assigned privileges for everyone with CJI access, including contractors. |
| Privileged access (PAM) | Privileged users have their own role-based security training requirements (AT-3), and least privilege (AC-6) applies to every account with access to CJI. |
| Audit, logging & accountability | Audit record review (AU-6) and immediate incident reporting under v6.1's IR-6 make identity events part of the evidence agencies must be able to produce. |
Penalties
Compliance is audited by state CJIS Systems Agencies and the FBI CJIS Division. Requirements that pre-date the policy's modernization and those marked Priority 1, including the MFA requirements, are auditable and sanctionable now; Priority 2 to 4 requirements are in a zero-cycle, auditable but not sanctionable, that ends September 30, 2027.
CJIS Security Policy: frequently asked questions
- Does the CJIS Security Policy require MFA?
- Yes. Controls IA-2(1) and IA-2(2) require multi-factor authentication for access to both privileged and non-privileged accounts, and both are Priority 1 requirements, meaning they are sanctionable in audits now rather than in the zero-cycle that runs to September 30, 2027.
- What changed in CJIS Security Policy v6.1?
- Version 6.1, effective June 26, 2026, is mainly a corrections release. For identity teams, it fixes authentication cross-references (including treating a phone-number change for out-of-band verification as binding a new authenticator), limits two FIPS 140 validation requirements at AAL2 to federal agencies, and requires immediate incident reporting. It also raises symmetric encryption to 256-bit for CJI in transit and at rest outside secure locations, and moves vulnerability-based update checks from quarterly to monthly.
- Does CJIS apply to private companies?
- Yes, if they access CJI or operate systems in support of criminal justice services. Cloud providers, software vendors, and contractors serving law enforcement agencies must meet the policy's requirements for the systems and people involved.