What is CJIS 6.0?
CJIS Security Policy 6.0 is the latest major revision of the FBI's framework, aligning with NIST and Zero Trust. Here is what changed and who it applies to.

If your organization works with criminal justice data, you have likely heard about CJIS 6.0, the latest update to the FBI's Criminal Justice Information Services Security Policy. But what exactly is CJIS 6.0, and what does it mean for your agency or business?
This post breaks down what changed, who is affected, and how to make sure your organization stays compliant.
What is the CJIS Security Policy?
The CJIS Security Policy is a set of security standards established by the FBI to protect sensitive criminal justice information. It applies to any agency, organization, or vendor that accesses, stores, transmits, or processes CJI, including law enforcement agencies, courts, corrections facilities, and their technology partners.
The policy has been regularly updated over the years to keep pace with evolving cybersecurity threats and technology.
What is CJIS 6.0?
Version 6.0 is the most recent major revision of the framework. It introduces updated requirements across several key security domains to strengthen the protection of criminal justice information in an increasingly complex threat landscape.
It aligns more closely with modern cybersecurity frameworks, including the NIST Cybersecurity Framework and Zero Trust Architecture principles.
What are the key changes in CJIS 6.0?
Enhanced multi-factor authentication. The policy expands and clarifies MFA requirements, making it mandatory for a broader range of access scenarios including remote access, cloud environments, and privileged accounts. All users accessing CJI must be authenticated using two or more factors.
Alignment with Zero Trust. The updated policy reflects a shift toward Zero Trust Architecture, which operates on the principle of never trust, always verify. Organizations must continuously validate users and devices rather than relying solely on perimeter-based controls.
Cloud computing guidance. As more agencies move to cloud-based solutions, 6.0 provides clearer guidance on how cloud services can be used to store and process CJI, including requirements for cloud service providers.
Updated encryption standards. Encryption requirements now reflect current NIST standards, ensuring data at rest and in transit is protected using modern, approved cryptographic algorithms.
Incident response and reporting. The policy strengthens requirements around incident response planning, including clearer timelines for reporting breaches and security incidents involving CJI.
Mobile device management. With the widespread use of mobile devices in law enforcement, 6.0 places greater emphasis on mobile device security, including device encryption, remote wipe, and application management.
Who does CJIS 6.0 apply to?
It applies to any entity that accesses or handles criminal justice information. That includes local, state, and federal law enforcement agencies; courts and prosecutors' offices; corrections and detention facilities; criminal justice IT vendors and managed service providers; cloud service providers hosting CJI; and third-party contractors with access to CJI systems.
If your organization falls into any of these categories, compliance is not optional. It is a legal and contractual requirement.
Why does it matter?
The stakes for non-compliance are high. Organizations that fail to meet CJIS requirements risk losing access to FBI criminal justice databases, legal and financial penalties, reputational damage, and increased vulnerability to cyberattacks and data breaches.
Beyond the consequences of non-compliance, the policy exists to protect sensitive information. Fingerprints, criminal histories, biometric data, and other records that, if compromised, can have serious consequences for individuals and for public safety.
How do you achieve compliance?
Getting compliant requires a structured approach.
Start with a gap analysis, comparing your current security controls against the 6.0 requirements to identify what needs to improve. Update your security policies and procedures so internal documentation reflects the new requirements. Implement MFA and Zero Trust controls by upgrading authentication systems and reviewing access control policies. Train your staff, since the policy requires security awareness training for everyone with access to CJI. Assess your vendors and partners to make sure any third party handling CJI is also compliant. And document everything, maintaining thorough records of your compliance efforts for audits.
Final thoughts
CJIS 6.0 represents a significant step forward in protecting criminal justice information against modern cyber threats. Whether you are a law enforcement agency, a managed service provider, or a technology vendor, understanding and implementing these requirements is essential.
Staying compliant does not just protect your organization. It protects the integrity of the criminal justice system and the privacy of the individuals whose data it holds.
See where your compliance actually stands
Twenty minutes with our team — your program, mapped onto the platform all 50 states already trust.
Book a demo