Security1 publisher2 min readPublished
CJIS v6.1 doubles the key strength required for criminal justice data outside secure locations
The FBI published version 6.1 on June 25, 2026, keeping v6.0's NIST-aligned structure while lifting SC-13 and SC-28 to a 256-bit minimum and tripling how often agencies must run vulnerability scans.
The Watch · Security desk
What happened
- The FBI published CJIS Security Policy v6.1 on June 25, 2026, correcting and extending the modernized v6.0 without changing its overall direction.
- SC-13, covering CJI in transit outside a physically secure location, now requires a symmetric cipher key of at least 256-bit strength; v6.0 set that minimum at 128-bit.
- Priority 2, 3 and 4 controls stay in zero-cycle status until September 30, 2027, so much of the modernized policy is not yet sanctionable.
- Texas is still auditing agencies against CJIS v5.9.5 until March 31, 2027 while they prepare for v6.1.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- constraint Any endpoint, tunnel or appliance that can only negotiate a 128-bit symmetric cipher now sits under the floor, and reconfiguration will not rescue hardware that cannot do 256-bit.
- cost Monthly scanning is a standing operational load on every organization holding CJI, and each cycle has to produce evidence for an assessor that it ran and that findings were handled.
- decision Agencies have to build toward v6.1 while being audited against whatever baseline their state CJIS Systems Agency still uses, and those two targets can be nearly two policy versions apart.
- exposure SC-28 puts the same 256-bit minimum on CJI at rest outside a physically secure location, so stored data written under the old floor is in scope alongside live traffic.
Doubling a minimum key length is one line in a policy table and a long list of things to check. The keyspace goes up by a factor of 2^128 [2]. The work is finding every place CJI leaves a physically secure location and reading what the cipher actually negotiates there, because a link or a volume that settles on a 128-bit symmetric cipher passed under v6.0 and now sits under the minimum [3][4][5].
At least monthly instead of at least quarterly takes an agency from four scan cycles a year to twelve [1]. The scanning change recurs. Version 6.0 already required a scan after any security incident involving CJI, and that requirement stayed [6].
Priority 1 controls have been sanctionable since October 1, 2024 [8]. Everything in Priority 2, 3 and 4 holds zero-cycle status for roughly 15 more months from v6.1's publication [3]. So the sanction dates decide what gets done first. BleepingComputer's account of the new version does not state which priority tier SC-13 and SC-28 fall into [19], so the sanction date for the 256-bit floor has to come from the state CJIS Systems Agency, and CSAs issue their own implementation and assessment guidance [11].
In Texas the gap opens wide: an agency there is audited against v5.9.5 until March 31, 2027. That leaves six months before zero-cycle status ends for the lower-priority controls [4].
Michigan State Police listed MFA among its top audit findings at the October 2025 CJIS Board meeting, alongside new policies, BYOD procedures, training, security agreements, event logging and fingerprinting [12][13]. Those findings all predate v6.1. IA-2's Priority 1 enhancements require MFA for privileged and non-privileged accounts whether the access is local, network-based or remote [16], and Identification and Authentication did not materially change between v6.0 and v6.1 [17]. Those MFA gaps have been sanctionable since October 1, 2024 [5]. IA-5, in the same family, requires a list of commonly used, expected or compromised passwords, updated at least quarterly and whenever a password may have been compromised [18].
Michigan State Police is also moving off triennial audit visits, to baseline security assessments, quarterly meetings, System Security Plans, secure evidence submission and regular progress reviews, with continuous assessment planned later in the process [14]. Identification and Authentication is one of the control families scheduled for assessment during FY2027 [15].
What to watch
- Whether CSAs beyond Texas publish transition dates that keep agencies on pre-v6.1 audit baselines into 2027.
- Whether Priority 2, 3 and 4 controls actually leave zero-cycle status on September 30, 2027 or get an extension.
- Whether FY2027 Identification and Authentication assessments turn the recurring MFA findings into sanctions.