Governance, risk & compliance
FBI CJIS Security Policy 5.9.5
The last pre-modernization release, published July 9, 2024 · still sanctionable today
CJIS 5.9.5 is the final release of the pre-modernization policy, organized as thirteen numbered policy areas. It is not an archive entry: since October 1, 2024 the sanctionable set has been the version 5.9 requirements plus the modernized Priority 1 requirements, so an agency audited today is measured against 5.9.5 and the current 6.1 policy at the same time.
Why 5.9.5 is still live
Because the 5.9 requirements remain part of the sanctionable set until October 1, 2027, an agency still has to meet them and evidence them, not just the modernized policy. Treat 5.9.5 as a current obligation, not history.
5.9.5 is also the release that introduced the priority levels and their implementation dates, expanded several policy areas (Access Control, Auditing and Accountability, Configuration Management, Incident Response, Physical and Environmental Protection, and Systems and Communications Protection) ahead of the rest of the policy, and added Maintenance, Planning, Contingency Planning, and Risk Assessment as new areas.
Assess 5.9.5 alongside 6.1, not instead of it
Assess this at the Priority 1 gate together with the modernized policy. Both write to the same shared control library, so the overlap costs nothing and the second assessment is mostly already answered.
Lavawall ships a 5.9.5 thirteen-policy-area assessment (49 questions), a 5.9.4 to 5.9.5 delta review (22 questions) for a program never updated past 5.9.4, and a 5.9.5 to 6.1 migration gap (32 questions) for planning the move. See the full set on the CJIS 6.1 page.
Primary source: the FBI’s CJIS Security Policy Resource Center. Last verified August 27, 2026.
Frequently asked questions
Is CJIS 5.9.5 still required in 2026?
Yes. Since October 1, 2024 the sanctionable set has been the version 5.9 requirements plus the modernized Priority 1 requirements, so an agency audited today is measured against 5.9.5 as well as the current 6.1 policy. It is not an archive release.
When was CJIS 5.9.5 published?
July 9, 2024. It is the last release of the pre-modernization CJIS Security Policy, organized as thirteen numbered policy areas rather than the NIST SP 800-53 control families used from 6.0 onward.
What changed between 5.9.4 and 5.9.5?
5.9.5 introduced the priority levels (P1 through P4) and their implementation dates, expanded Access Control, Auditing and Accountability, Configuration Management, Incident Response, Physical and Environmental Protection, and Systems and Communications Protection ahead of the rest of the policy, and added Maintenance, Planning, Contingency Planning, and Risk Assessment as new areas.
Do I assess 5.9.5 instead of 6.1?
Alongside it, not instead. Assess 5.9.5 at the Priority 1 gate together with the modernized policy. Both write to the same shared control library, so the overlap costs nothing and the second assessment is mostly already answered.