Last Updated on September 10, 2026 by Satyendra
CJIS Security Policy v6.1 is an update, rather than another major policy overhaul. On June 25, 2026, the FBI released v6.1, updating the v6.0 baseline that has been in place since December 27, 2024. v6.0 represented a major stage in the modernization of the CJIS Security Policy, while v6.1 incorporates calendar-year 2025 changes, including omissions, corrections, additions approved through the APB process, and administrative changes.
Agencies do not need to treat v6.1 as a complete reset of their CJIS compliance programs. Instead, they should identify which policy requirements have changed and determine whether their existing controls still meet the applicable requirements.
This blog works through two questions: What changed in v6.1, and what should agencies do about it now?
CJIS Security Policy v6.1 at a Glance
A few facts about CJIS Security Policy v6.1 are as follows:
| Item | Details |
|---|---|
| Release Date | June 25, 2026 |
| Previous Version | v6.0, released December 27, 2024 |
| Purpose of v6.1 | The intent of v6.1 is to include the latest APB-approved changes from 2025, like corrections, additions, omissions, and administrative updates rather than a substantial modernization effort. |
| Who Should Review It | Criminal Justice Agencies (CJAs), Noncriminal Justice Agencies (NCJAs), CJIS Systems Agencies (CSAs), contractors, service providers, and any organization that processes, stores, or transmits Criminal Justice Information (CJI). |
v6.1 builds on the control structure established in v6.0, including its security-control organization and related NIST SP 800-53 mappings. Rather than restructuring it, this version is refined through corrections, new requirements approved in 2025, and administrative changes such as updated references, reformatting, and technology-related updates.
A Practical Takeaway: A full CJIS program rebuild is not required. Organizations should instead compare their existing v6.0 documentation and controls against the changes introduced in v6.1.
What Changed in CJIS Security Policy v6.1?
CJIS Security Policy v6.1 is not an additional restructuring of the policy but rather an incorporation of changes that occurred throughout 2025 following the modernization of the whole policy in v6.0.
According to the FBI’s Summary of Changes, these changes can be divided into two broad categories: APB- approved changes and administrative changes.
1. APB- Approved Omissions, Corrections, and Additions
The substantive changes in v6.1 result from the approval of three separate change sets within the Spring 2025 Advisory Policy Board (APB) cycle:
- Part 1 – APB#16, SA#1: Addressing omissions, corrections, and additions to the modernized CJIS Security Policy.
- Part 2 – APB#16, SA#2: Additional omissions, corrections, and additions identified following the modernization of the policy.
- Part 3 – APB#16, SA#3: Further updates to sections of the modernized CJIS Security Policy.
Together, these changes refine the framework established in v6.0 without replacing it. Agencies should determine which requirements are applicable to their environment and whether the changes affect existing controls, processes, configurations, or documentation.
2. Administrative Changes
v6.1 also incorporates administrative changes approved by the Security and Access Subcommittee on November 14, 2025. It is important to mention that the FBI considers the above-mentioned administrative updates to be separate from the updates made via the APB process. Therefore, agencies should not assume that every textual difference between v6.0 and v6.1 represents a new or modified security requirement.
What This Means for Agencies
The practical task is not to rebuild a CJIS compliance program around v6.1. Rather, agencies need to assess the requirements relevant to their environment against the new policy and categorize any differences according to their significance.
For each applicable change, determine whether it:
- Introduces or changes a security requirement.
- Requires a technical or configuration change.
- Affects an existing policy, procedure, or responsibility.
- Changes the evidence needed to demonstrate implementation.
- Is administrative and does not require a change to the underlying security control.
This differentiation is significant since an administrative correction might involve minimal effort at the operations level, while an addition or substantive fix would require modifications at the level of technology, processes, documentation, and control implementation.
Which v6.1 Changes Should Agencies Prioritize?
Not every change requires the same level of effort. Agencies should prioritize changes according to their impact on security controls and audit readiness.
Technical Action: Items that call for new configurations, changes in access control, adjustments to authentication, the introduction of new monitoring capabilities, or modifications to security tooling.
Process or Policy Updates: Items that touch upon access-review procedures, incident-response processes, account-management workflows, third-party oversight, or security documentation.
Documentation and Clarification Updates: Items where the control itself remains unchanged, but the policy language, control mapping, or audit evidence needs to be changed to match the latest version’s wording.
For every item, run it through a simple chain:
Requirement→ Current Control → Gap → Risk → Owner → Remediation Date.
This turns the review into a documented remediation plan that can support compliance and audit-readiness efforts.
What Agencies Need to Do to Prepare for v6.1
The most effective way for agencies to prepare for v6.1 is to perform a structured gap assessment and determine how the updated requirements affect existing controls, processes, systems, and documentation.

- Perform a v6.0-to-v6.1 Gap Assessment: Compare your current implementation against v6.1 and identify applicable omissions, corrections, additions, and administrative changes. Then determine which changes affect controls, configurations, processes, or documentation.
- Identify Affected Systems and CJI: With each change, figure out which application servers, identity systems, file systems, cloud platforms, endpoints, and third-party services come under the scope. For example, a change affecting privileged-account requirements may apply across systems and environments that privileged accounts can access when those systems contain or provide access to CJI.
- Review Identity and Access Controls: Validate user accounts, privileged accounts, group memberships, and effective permissions. Look specifically for dormant accounts, unused service accounts, and remote-access paths that may no longer match the current policy language.
- Validate Monitoring and Audit Coverage: Confirm that the security team has meaningful visibility into identity, access, administrative, and relevant CJI-related activity, not simply that logging is technically enabled.
- Update Policies and Procedures: Wherever v6.1 changes responsibilities, security processes, technical requirements, incident handling, or third-party oversight, update the corresponding internal documentation so it reflects the current policy, not v6.0.
- Remediate and Document Gaps: For every gap identified in the above steps, record the control affected, the remediation required, the responsible owner, the target completion date, and, once complete, evidence of completion. This record is what turns “we fixed it” into something an auditor can verify.
- Validate Before the Next Audit: Conduct an internal audit to verify two facts: first, that the control is in place, and second, that the agency can provide proof that the control is in place. Both are important when demonstrating compliance during an audit.
What v6.1 Means for Hybrid and Cloud Environments
Most agencies nowadays use a combination of on-premises infrastructure and cloud services, Active Directory with Microsoft Entra ID, internal file servers with Microsoft 365, and SaaS solutions with internally hosted systems. Agencies should assess how applicable CJIS security controls are implemented across their on-premises, cloud, and hybrid environments rather than limiting their review to a single environment.
Pay Attention to Shared Responsibility
Moving services to the cloud does not eliminate the agency’s responsibility for CJIS compliance. Agencies need to know which controls they are responsible for, which controls the cloud provider is responsible for, which controls they share together, and whether the cloud provider can offer sufficient proof that their responsibilities are fulfilled.
Look for Hybrid Control Gaps:
- Access policies are inconsistent between on-premises and cloud environments.
- Limited visibility into identities that operate across both environments.
- Privileged accounts accessing multiple environments.
- Monitoring that does not provide a unified view across environments.
- Access and permission assessments are conducted for one environment but not the other.
How to Demonstrate v6.1 Compliance During an Audit
Compliance is not only about implementing controls. Agencies should be ready to show proof of implementation, monitoring, and maintenance of CJIS v6.1 requirements rather than just documenting policies around them.
- Control Implementation: Demonstrate that relevant CJIS v6.1 security controls have been implemented and that they work as intended. This evidence includes configurations, procedures, technology controls, and control documentation.
- Access Governance: Who gets access to Criminal Justice Information (CJI), for what purpose, and how privileged access is controlled. Agencies should be prepared to demonstrate that applicable access reviews are performed periodically and that inappropriate access is addressed.
- Security Monitoring: Demonstrate that applicable audit and monitoring requirements are being met, including the collection, review, protection, and retention of relevant audit records where required by the CJIS Security Policy.
- Change Management: Provide records showing how changes to user accounts, permissions, security configurations, and policies are authorized, tracked, and reviewed. This helps demonstrate that security controls remain properly configured over time.
- Remediation Evidence: Demonstrate documented evidence that security gaps or audit findings were addressed and resolved. This can include remediation plans, corrective actions, approvals, and follow-up remediation activities.
- Policy Alignment: Ensure internal policies, procedures, and security documentation reflect the current CJIS v6.1 requirements and do not rely on outdated versions. This demonstrates that compliance processes are aligned with current expectations.
For a broader view of audit readiness beyond v6.1 specifically, see The Complete Guide to CJIS Compliance and Audit Readiness.
How Lepide Helps Agencies Adapt to CJIS v6.1
Adapting to a policy update like v6.1 is fundamentally a visibility problem. Agencies must be aware of who has access to CJI, whether the access is legitimate, and how changes in this regard are being monitored and evaluated. This is where Lepide comes into play in many ways:
- Understand Access to Sensitive Data: Through Lepide, agencies can link their sensitive information with identity and permissions context. This helps security teams understand not only where sensitive information exists, but also who can access it.
- Identity Access and Privileged Access: Lepide’s permission visibility feature allows agencies to detect unnecessary access
- Monitor Identity and Permission Changes: Lepide’s solution enables monitoring of changes in identity and permissions on the relevant platforms such as Active Directory, Microsoft Entra ID, file servers, and Microsoft 365.
- Detect Suspicious Activity: Using contextual monitoring and alerting, security teams can identify any suspicious activity from users and administrators, allowing organizations to investigate such activities.
- Strengthen Audit Evidence: Historical activity data and reporting can help provide evidence of access, permission, and related security monitoring.
- Improve Hybrid Visibility: For agencies operating on-premises and Microsoft cloud environments, bringing identity, permission, data, and activity context together can make it easier to identify control gaps.
The goal is not to position Lepide as a substitute for the CJIS Security Policy or an automatic compliance solution. Lepide helps agencies support, monitor, and demonstrate applicable CJIS controls by improving visibility into access, changes, permissions, and security activity.
If your agency needs help assessing access, monitoring changes, and improving visibility across on-premises and cloud environments for CJIS audit readiness, schedule a demo with Lepide to learn how our platform supports v6.1 preparation.
Conclusion
CJIS Security Policy v6.1 is an update to the existing CJIS security framework, not a complete replacement of v6.0. Agencies should approach the update systematically by identifying applicable changes, assessing their impact on existing controls, remediating gaps, documenting evidence, and continuing to monitor security activity.
Agencies that treat v6.1 as a one-time documentation exercise may face additional work when future policy updates are introduced. Building continuous visibility into access, identity, and change activity can help agencies maintain audit readiness as the policy evolves.
Frequently Asked Questions (FAQs)
CJIS v6.0 represented a major stage in the broader CJIS Security Policy modernization effort, whereas v6.1 incorporates approved calendar-year 2025 changes to that modernized framework, including omissions, corrections, additions, and administrative changes.
Yes, agencies should compare their existing controls, configurations, procedures, and documentation against v6.1 to determine whether any changes affect their implementation or evidence requirements.
Agencies should conduct a v6.0-to-v6.1 gap assessment, identify affected systems and CJI, review identity and access controls, validate monitoring coverage, update policies and procedures, remediate gaps, and collect evidence demonstrating that controls are implemented and operating effectively.