📋 GRC compliance for CMMC 2.0, CPCSC, CPA Canada, IIROC…SaaS discovery for data governanceFree enriched web chat widget🚀 Enriched remote support without your laptop

Governance, risk & compliance

FBI CJIS Security Policy 6.1

Current version 6.1, published June 25, 2026 · pre-modernization release 5.9.5 still applies

The CJIS Security Policy sets the security requirements attached to criminal justice information (CJI). Version 6.1 is current, published June 25, 2026. Two rulebooks are sanctionable at the same time: since October 1, 2024 the sanctionable set has been the pre-modernization version 5.9 requirements plus everything marked Priority 1 in the modernized policy. Priority 2 through 4 are assessed but not sanctioned until October 1, 2027, when the whole policy becomes sanctionable.

Assess against CJISCJIS 5.9.5 →

What is sanctionable today?

Today the sanctionable set is the pre-modernization 5.9 requirements plus every Priority 1 requirement in the modernized policy, both at once. An agency audited now is measured against the old rulebook and the new Priority 1 set together. Anyone who read "modernization deadline 2027" as permission to defer has a problem today, not in three years.

Priority 2, 3, and 4 sit in zero-cycle status from October 1, 2024 through September 30, 2027: assessed and reported during an audit, but not sanctioned. On October 1, 2027 the full policy becomes sanctionable. The dates below are the whole story, so read them as a table, not a headline.

GateWhat it coversStatus nowSanctionable
Gate 1Legacy version 5.9 requirementsSanctionableSince Oct 1, 2024
Gate 2Priority 1 (modernized)SanctionableSince Oct 1, 2024
Gate 3Priority 2Zero-cycle: assessed, not sanctionedOct 1, 2027
Gate 4Priority 3Zero-cycle: assessed, not sanctionedOct 1, 2027
Gate 5Priority 4Zero-cycle: assessed, not sanctionedOct 1, 2027
Gate 6Full policy, all prioritiesNot yet sanctionableOct 1, 2027

What Lavawall ships for CJIS

Six assessments, all live in the product, so you assess the version and the gate you are actually on rather than a generic checklist.

AssessmentQuestionsWhat it is for
CJIS 6.1 — Priority 1 (sanctionable now)24The set an audit measures today
CJIS 6.1 — Full Policy (P1 through P4)55All twenty control families, including Mobile Devices
CJIS 5.9.5 — Thirteen Policy Areas49The legacy requirements that are still sanctionable
CJIS 5.9.4 → 5.9.5 Delta Review22For a program never updated past 5.9.4
CJIS 5.9.5 → 6.1 Migration Gap32Planning the move off the pre-modernization policy
CJIS 6.0 → 6.1 Change Review26Run once per release

Six sanction-gate tiers sit behind these, so a gap shows which clock it is behind: Gate 1 the legacy 5.9 set, Gate 2 Priority 1, Gates 3 to 5 the zero-cycle priorities, and Gate 6 the October 1, 2027 full-policy gate.

Every one of these writes to the same shared control library. An agency running 5.9.5 and 6.1 side by side answers each underlying control once; the second assessment is mostly already answered. That is why carrying two rulebooks does not cost twice the work, and it is the actual reason to assess both instead of guessing which one your auditor will open.

What changed between 6.0 and 6.1?

The published Summary of Changes names three Advisory Policy Board packages rather than itemizing control-level changes. That is precisely why a structured review beats reading a diff: there is no clean line-by-line changelog to read.

Lavawall ships a 6.0 to 6.1 change review (26 questions) to walk the packages against your current state. We would rather tell you the diff is not itemized than claim a completeness nobody can verify against the source.

Can a compliance tool live inside our CJI security boundary?

Yes, when it is deployed for it. This is the objection that actually stops these deals, so here is the honest version rather than the brochure one.

Lavawall tenants for US public-safety customers can be provisioned in a Government Community Cloud environment built for ITAR and CJIS requirements, so Lavawall operates within a CJI security boundary rather than beside it. Every vendor says "government cloud," so the specifics are what matter: US-only data residency, US-person support and administration, personnel screening, and contract terms that survive a CJIS audit.

Concretely, Lavawall will execute a CJIS Security Addendum, and personnel who could reach agency data are fingerprint-screened. The Security Addendum is the specific artifact a Local Agency Security Officer has to be able to hand their auditor, so it is the thing to ask for by name.

Be clear about the responsibility split. The modernized policy assigns each requirement across IaaS, PaaS, and SaaS. Lavawall covers its share and hands you a documented view of yours. We do not claim the product makes your agency compliant; it shows you where you stand and keeps the evidence. That is the true statement, and it is the stronger one to anyone who has been pitched by a vendor that overclaimed.

We do not claim a FedRAMP authorization. FedRAMP authorizes cloud providers to sell to federal agencies, it is checkable in a public database in under a minute, and it is the wrong program for a criminal-justice buyer anyway. If a status matters to your procurement, ask us and we will point you at the accurate answer.

Is StateRAMP the same thing as GovRAMP?

Yes. GovRAMP (formerly StateRAMP) is the same program under a new name: it rebranded during 2025, and statuses, requirements, pricing, and existing authorizations all carried over unchanged.

If your procurement asks for a cloud-vendor assurance status, see GovRAMP. CJIS itself is a policy your agency is assessed against; GovRAMP is a status a product you buy may hold.

How Lavawall® helps you evidence CJIS

Most of CJIS comes down to technical controls you have to run and prove: access control, auditing and accountability, configuration management, incident response, encryption, and keeping evidence that all of it actually happened. Lavawall runs those controls across Windows, macOS, Linux, and Microsoft 365 / Google Workspace from one console, maps them to both the 5.9 requirements and the modernized priorities, and tracks your posture continuously instead of the week before an audit.

  • Assess against 6.1 (Priority 1 or full policy) and 5.9.5 in the Lavawall GRC module, from the same shared control library.
  • Remediate the gaps with the same platform — patching, configuration hardening, breach detection, backups, and access review — not a separate project.
  • Evidence everything with timestamped, exportable records a CJIS auditor accepts.

Related

Primary source: the FBI’s CJIS Security Policy Resource Center. Last verified August 27, 2026.

Frequently asked questions

What version of the CJIS Security Policy is current?

Version 6.1, published June 25, 2026. It succeeded 6.0, the first modernized release. The last pre-modernization release was 5.9.5, published July 9, 2024, and parts of the 5.9 requirements are still sanctionable, so it has not gone away.

What is sanctionable today?

Since October 1, 2024 the sanctionable set is the pre-modernization version 5.9 requirements plus every requirement identified as Priority 1 in the modernized policy. Two rulebooks, both live. An agency audited today is measured against both at once.

What is zero-cycle status?

Priority 2, 3, and 4 requirements are in zero-cycle status from October 1, 2024 through September 30, 2027: they are assessed and reported during an audit, but not sanctioned. On October 1, 2027 the whole policy becomes sanctionable.

Is CJIS 5.9.5 still required?

Yes. The 5.9 requirements remain part of the sanctionable set until October 1, 2027, so an agency still has to meet and evidence them. That is why Lavawall keeps a separate CJIS 5.9.5 assessment alongside the 6.1 one.

What changed between 5.9.4 and 5.9.5?

5.9.5 (July 9, 2024) introduced the priority levels and their implementation dates, expanded Access Control, Auditing and Accountability, Configuration Management, Incident Response, Physical and Environmental Protection, and Systems and Communications Protection ahead of the rest of the policy, and added Maintenance, Planning, Contingency Planning, and Risk Assessment as new areas.

What changed between 6.0 and 6.1?

The published Summary of Changes names three Advisory Policy Board packages rather than an itemized, control-level diff, which is exactly why a structured 6.0-to-6.1 review beats trying to read a changelog. Lavawall ships a 6.0 to 6.1 change review for that reason.

Can a cloud tool be used inside a CJI security boundary?

It can, if it is deployed in an environment built for CJIS and covered by a signed CJIS Security Addendum, with US-only data residency and screened US-person administration. The modernized policy assigns each requirement across IaaS, PaaS, and SaaS, so the agency and the provider each own a documented share.

Is StateRAMP the same thing as GovRAMP?

Yes. StateRAMP rebranded to GovRAMP during 2025. Statuses, requirements, pricing, and existing authorizations all carried over unchanged, so a product listed under the old name is the same product.