UK’s trusted IT infrastructure partner since 2003
Servnet
FinanceToolsConfiguratorGet in Touch
Cyber security

FBI CJIS v6.1 2026 Compliance: What It Means for UK Suppliers

London · Servnet News Desk · IT infrastructure analysis5 min read
Share

The FBI has published CJIS v6.1, raising the minimum encryption strength for criminal justice information to 256-bit and doubling vulnerability scanning frequency to monthly. For UK suppliers and IT teams handling US law enforcement data, the phased audit timeline running to 2027 means compliance planning — including how organisations understand broader IT compliance requirements — needs to start now.

Vulnerability scanning mandate: minimum scans per year
20scans/yr15scans/yr10scans/yr5scans/yr0scans/yr4scans/yrCJIS v6.012scans/yrCJIS v6.1Minimum scans required
View the data behind this chart
Vulnerability scanning mandate: minimum scans per year
CJIS v6.0CJIS v6.1
Minimum scans requiredscans/yr4scans/yr12

What actually changed in CJIS v6.1

CJIS v6.0, released on 27 December 2024, completed the FBI's move to a control-based policy structure aligned with NIST SP 800-53. Version 6.1, published on 25 June 2026, is a refinement rather than a rewrite, but two changes matter operationally. Under SC-13, the minimum symmetric cipher strength for CJI in transit outside a physically secure location rises from at least 128-bit to at least 256-bit. SC-28, covering CJI at rest outside physically secure locations, is likewise tightened to at least 256-bit.

The other significant change sits in vulnerability management. Under v6.0, agencies had to run vulnerability scans at least quarterly to check whether security-related software and firmware updates had been applied, plus scans after any incident involving CJI. v6.1 moves that baseline to at least monthly. For teams that haven't already moved past quarterly cycles, this is a good moment to strengthen their vulnerability scanning capabilities before it becomes an audit finding.

Who in the UK actually needs to act

CJIS is a US federal policy, but it reaches well beyond US borders through the supply chain. UK-based cloud providers, MSPs and software vendors that contract to host, process or transmit criminal justice information for US law enforcement agencies may need to meet CJIS requirements if their services fall within its scope, including the increased encryption and scanning thresholds. It's a useful moment for these firms to understand broader IT compliance requirements that CJIS obligations sit alongside.

There's also a domestic angle. UK forces and their suppliers are navigating their own version of this scrutiny. Computer Weekly has reported ongoing questions over whether cloud vendors can guarantee sovereignty for UK policing data, and the Information Commissioner's Office has said it has not yet given formal regulatory approval for the cloud arrangements used by some UK law enforcement bodies. Suppliers straddling both jurisdictions face two live compliance conversations at once, not one.

The audit timeline isn't a single deadline

v6.1 is now the current CJIS Security Policy, but publication doesn't switch every agency to a single new audit standard overnight. The modernised policy uses priority levels with phased sanction dates: Priority 1 controls have been sanctionable since 1 October 2024, while Priority 2, 3 and 4 controls remain in "zero-cycle" status until 30 September 2027. State CJIS Systems Agencies can also set their own pace — Texas, for example, is continuing to audit against v5.9.5 through to 31 March 2027 while agencies prepare for v6.1.

At its October 2025 board meeting, Michigan State Police flagged multi-factor authentication as a top audit finding, alongside gaps in BYOD policy, training, security agreements, event logging and fingerprinting. MSP also outlined a shift away from relying mainly on triennial audit visits, toward baseline assessments, quarterly meetings and continuous assessment — with Identification and Authentication scheduled for review during FY2027. The practical lesson for buyers: confirm current expectations with the relevant CSA rather than waiting for a control to become sanctionable, and plan for evidence of ongoing operation, not just a point-in-time tick.

Illustration: FBI CJIS v6.1 2026 Compliance: What It Means for UK Suppliers

Encryption, network segmentation and identity controls to verify

The direction of travel on encryption is clear: FIPS-validated cryptography, TLS 1.2 or higher for data in flight, and AES-256 for data at rest, with CJIS environments segmented from the wider corporate network using firewalls, VLANs or air-gapped enclaves. Buyers reviewing legacy estates against these requirements may also want to explore advanced cryptographic protection strategies given how far minimum key strengths have already moved in one policy cycle.

Identity requirements haven't changed materially between v6.0 and v6.1, but they remain a recurring audit weak spot. IA-2 requires unique identification and authentication for all organisational users, with MFA mandated for privileged and non-privileged accounts regardless of whether access is local, network-based or remote. IA-5 requires agencies to maintain a list of commonly used, expected or compromised passwords, refreshed at least quarterly, and to check both existing and prospective passwords against it. None of this is framed as Zero Trust, but the emphasis on verifying identity and device posture rather than trusting network location alone points firmly in that direction — which is why it's worth having teams review their overall cybersecurity posture alongside CJIS remediation.

Why the wider UK policing data debate raises the stakes

CJIS tightening its rules doesn't happen in isolation from the UK's own reckoning with law enforcement data handling. Computer Weekly has reported that Police Scotland uses cloud infrastructure for biometric data despite acknowledged risks, that Microsoft has admitted it cannot guarantee sovereignty for UK policing data hosted on its platforms, and that the company has refused to disclose data flows related to Police Scotland systems. Separately, the National Police Chiefs' Council-backed National Data Integration and Exploitation Service is working to let local forces share intelligence and digital forensics data nationally.

None of this changes what CJIS v6.1 requires, but it changes the context UK infrastructure buyers are operating in. Suppliers already under pressure to demonstrate sovereignty and encryption assurances to UK regulators will find CJIS's tightened SC-13/SC-28 thresholds and monthly scanning mandate arriving on top of an already scrutinised environment, not into a clean slate.

CJIS audit and sanction phasing to 2027
W0W26W52W78W104W130W156Priority 1 sanctionable40wv6.1 published8wTexas v5.9.5 ends6wZero-cycle ends5wTotal: 156 weeks end-to-end
View the data behind this chart
CJIS audit and sanction phasing to 2027
PhaseStarts (week)Duration (weeks)
Priority 1 sanctionable040
v6.1 published908
Texas v5.9.5 ends1306
Zero-cycle ends1515

A practical remediation checklist

None of the individual v6.1 changes are exotic, but taken together they demand a structured response rather than a last-minute scramble before an audit cycle lands.

Teams working through this should also consider how CJIS controls line up against frameworks they already report on — many organisations find it efficient to map CJIS controls to other security standards like ISO 27001 rather than running parallel compliance programmes, and to route the resulting telemetry into existing managed detection & response capability so continuous assessment evidence is generated automatically rather than assembled retrospectively.

  • Confirm your relevant CSA's current audit baseline (v6.0, v6.1 or a state-specific version such as Texas's v5.9.5) before assuming a single national deadline applies
  • Audit encryption configurations against the 256-bit minimum for both CJI in transit (SC-13) and at rest (SC-28)
  • Move vulnerability scanning cadence from quarterly to monthly and ensure scans also trigger after any CJI-related incident
  • Validate MFA coverage for privileged and non-privileged accounts under IA-2, including remote and offline authentication paths
  • Check that compromised-password lists are refreshed and compared against live credentials at least quarterly under IA-5
Sources
  1. 01BleepingComputer — FBI's CJIS v6.1: What Security Teams Need to Know · 21 September 2026
  2. 02BleepingComputer — FBI's CJIS Demystified: Best Practices for Passwords, MFA and Access Control · 21 September 2026
  3. 03Computer Weekly — Reassessing UK law enforcement data adequacy · 21 September 2026
  4. 04Computer Weekly — Police Scotland use cloud for biometric data despite clear risks · 21 September 2026
  5. 05Computer Weekly — Microsoft admits no guarantee of sovereignty for UK policing data · 21 September 2026
  6. 06Computer Weekly — Microsoft refuses to divulge data flows to Police Scotland · 21 September 2026
  7. 07Computer Weekly — Inside police plans to share intelligence and crime data across the UK · 21 September 2026
  8. 08Computer Weekly — ICO police cloud guidance released under FOI · 21 September 2026
Share
Key takeaways
  • CJIS v6.1 raises SC-13 and SC-28 encryption minimums to at least 256-bit, up from 128-bit under v6.0.
  • Vulnerability scanning frequency moves from at least quarterly to at least monthly under v6.1.
  • Priority 2-4 controls remain in "zero-cycle" status until 30 September 2027; states such as Texas run separate audit baselines (v5.9.5 to 31 March 2027).
  • UK suppliers and MSPs handling CJI should confirm current CSA audit expectations now rather than waiting for controls to become sanctionable.
Frequently asked

FAQs — FBI CJIS v6.1 2026 Compliance

What is CJIS v6.1 and when did it take effect?

CJIS v6.1 was published on 25 June 2026 as a refinement of v6.0, which was released on 27 December 2024 and moved the policy to a control-based structure aligned with NIST SP 800-53. v6.1 is now the current CJIS Security Policy.

Does CJIS v6.1 apply to UK organisations?

It applies directly to UK-based suppliers, cloud providers and MSPs that handle criminal justice information for US law enforcement agencies. UK-only public sector bodies should still understand broader IT compliance requirements given parallel scrutiny of UK policing data handling.

Is there a single CJIS v6.1 compliance deadline?

No. The policy uses phased priority levels: Priority 1 controls have been sanctionable since 1 October 2024, while Priority 2, 3 and 4 controls remain in zero-cycle status until 30 September 2027. State CJIS Systems Agencies can set their own timelines on top of this.

Have password and MFA requirements changed under v6.1?

No material change. IA-2 still requires MFA for privileged and non-privileged accounts across local, network and remote access, and IA-5 still requires compromised-password lists to be checked at least quarterly.

Related

Turning this into a buying decision?

One conversation with an engineer who's specced this before. No sales script.

Talk to Servnet →

Talk to a UK specialist

Get expert advice or a no-obligation quote — servers, storage, networking, maintenance, finance and cloud. We reply the same working day.

or call 0800 987 4111