What is the CJIS Security Policy?
The CJIS Security Policy (CJISSECPOL) is the FBI’s minimum security standard for protecting Criminal Justice Information (CJI) throughout its lifecycle, from creation to destruction. The current version is v6.0, released on December 27, 2024, and it’s the most significant update to the policy since it was first introduced in 1992.
Published by the FBI’s Criminal Justice Information Services Division, v6.0 aligns closely with NIST SP 800-53 Rev. 5 and organises requirements across 20 policy areas covering administrative, technical, and physical controls. Agencies have until October 1, 2027 to fully implement the modernised requirements, though Priority 1 (P1) controls are already sanctionable.
Who does the CJIS Security Policy apply to?
Anyone who creates, views, stores, transmits, or accesses Criminal Justice Information must comply with the CJIS Security Policy. Compliance is not limited to sworn law enforcement. It covers:
- State, local, Tribal, territorial (SLTT), and federal law enforcement agencies
- Courts, corrections, and other justice-adjacent agencies
- Noncriminal justice agencies that perform fingerprint-based background checks
- Contractors, private entities, and cloud service providers that touch CJI in any way
- Individual employees, contractors, and integrators with access to CJI systems
If CJI flows through your hands, the CJISSECPOL applies to you, regardless of job title or employer.
What is Criminal Justice Information (CJI)?
Criminal Justice Information is the full set of FBI CJIS-provided data that law enforcement and civil agencies need to do their jobs, from enforcing laws to making hiring decisions on justice-related roles. CJI covers far more than criminal history records.
The FBI groups CJI into five main categories:
- Biometric data: fingerprints, iris scans, facial recognition data
- Identity history data: arrests, dispositions, and related criminal history
- Person and organisation data: identifying information on individuals and entities linked to investigations
- Property data: vehicles, weapons, or other items, when tied to personally identifiable information (PII)
- Case and incident history data: reports, investigative records, and related documentation
Transaction Control Numbers (TCNs) are exempt from CJI protection only when they reveal neither CJI nor PII.
What are the CJIS encryption requirements?
CJI must be encrypted whenever it sits outside a physically secure location, whether at rest or in transit. Agencies need cryptographic modules that are either FIPS 140-3 certified or FIPS 197 (AES) validated.
Minimum key strengths:
- Data in transit: symmetric cipher key of at least 128-bit strength
- Data at rest with FIPS 140-3: symmetric cipher key of at least 128-bit strength
- Data at rest with FIPS 197: symmetric cipher key of at least 256-bit strength
These are floors, not ceilings. Agencies handling high-risk workloads typically exceed the minimum, especially as post-quantum cryptography guidance matures and FIPS 140-2 certifications continue to be phased out.
What’s new in CJIS Security Policy v6.0?
Version 6.0 is the most significant CJIS rewrite in over a decade. It moves agencies away from checklist compliance and toward continuous, risk-based governance modelled on NIST SP 800-53 Rev. 5.
The headline changes:
- Full alignment with NIST SP 800-53 Rev. 5, making cross-mapping to FedRAMP, GovRAMP, CMMC, and IRS 1075 far simpler
- Stronger identity controls, including clearer MFA requirements, banned password lists, and account lifecycle management
- Formalised governance, with defined security roles, documented responsibilities, and executive-level oversight of CJIS security
- Expanded configuration management, continuous monitoring, and supply chain requirements
- Priority 1 (P1) controls flagged as immediately sanctionable, while full compliance is expected by October 1, 2027
Version 6.1 is slated for spring 2026, with roughly 6 to 12 month update cycles going forward. That pace means your compliance posture should be treated as an ongoing programme, not a one-off audit preparation sprint.