← All stories
● Covered by 1 source · 1 reportMedium impact1 neutral

FBI Releases CJIS Security Policy v6.1 with Stricter Encryption and Vulnerability Scanning

🔄 Updated 2d ago
New to BrevFeed? We gather this story from every outlet covering it into one summary — ranked by real-world impact, not just the latest headline — so you never miss what matters. What is BrevFeed? →

Key points

  • CJIS Security Policy v6.1 released June 25, 2026.
  • Encryption strength for CJI in transit and at rest increased to 256-bit.
  • Vulnerability scanning frequency changed from quarterly to monthly.
  • Audit requirements vary by State CJIS Systems Agencies (CSAs).

CJIS Policy Modernization Continues

The FBI's Criminal Justice Information Services (CJIS) Security Policy version 6.1 was published on June 25, 2026. This release builds upon the modernization efforts initiated with version 6.0, which moved the policy towards a control-based structure aligned with NIST SP 800-53. Version 6.1 addresses omissions, corrections, and additions identified throughout 2025, maintaining the overall direction for security teams already implementing v6.0 requirements.

Key Technical Changes in v6.1

Version 6.1 introduces specific technical updates. Under SC-13, cryptographic protection for CJI in transit outside physically secure locations now requires a symmetric cipher key of at least 256-bit strength, an increase from the 128-bit requirement in v6.0. Similarly, SC-28, which covers CJI at rest outside physically secure locations, also mandates encryption strength of at least 256-bit.

Another significant change is in vulnerability management. While v6.0 required agencies to use vulnerability scanning tools at least quarterly, v6.1 mandates this frequency to be at least monthly. This change applies to determining whether security-related software and firmware updates have been installed and following security incidents involving CJI.

Audit and Compliance Considerations

Although v6.1 is the current CJIS Security Policy, agencies should not assume an immediate switch to a single new audit baseline. The modernized policy uses priority levels and phased audit and sanction dates. Priority 1 controls have been sanctionable since October 1, 2024, while Priority 2, 3, and 4 controls are in a “zero-cycle” status until September 30, 2027.

State CJIS Systems Agencies (CSAs) may provide their own implementation and assessment guidance. For example, Texas is auditing against v5.9.5 until March 31, 2027, allowing agencies time to prepare for v6.1. Organizations are advised to confirm current audit expectations with their relevant CSA while working towards the newer requirements.

✨ This summary was generated by AI from the outlets' reporting listed below. It is not independently verified and may contain errors — check the original sources. How BrevFeed works →

The daily brief

One email each morning: the day's tech stories, clustered across outlets and summarized. No account needed.

One email a day. Unsubscribe in one click, any time.

Today's brief

Spend a few minutes, get the whole day. Every topic's top stories in one hands-free rundown — listen, watch, or read the transcript.

~26 min · 21 stories · Sep 23

▶ Play today's brief Listen on Spotify

New every morning, and the back catalogue is archived by date.

Reporting from

The FBI released version 6.1 of its CJIS Security Policy on June 25, 2026, updating encryption requirements and increasing the frequency of vulnerability scanning. This update refines the control-based structure introduced in v6.0, impacting security teams responsible for Criminal Justice Information (CJI) compliance.