FBI Updates Criminal Justice Data Security Rules: Stronger Encryption and Monthly Scans Required

The FBI's CJIS Security Policy version 6.1, published in June 2026, raises encryption strength requirements for criminal justice information both in transit and at rest to at least 256-bit keys. It also increases the required frequency of vulnerability scanning from quarterly to monthly. Agencies should note that audit deadlines vary by state, with some still assessing against older versions until 2027.
The June 2026 update mandates 256-bit encryption for criminal justice information both during transmission and when stored outside secure perimeters, a notable jump from the prior 128-bit floor. Additionally, vulnerability scans must now occur monthly rather than quarterly, reflecting a faster pace for identifying unpatched software.
Implementation remains staggered. While v6.1 is the current standard, states like Texas continue assessing against v5.9.5 until spring 2027. Audit findings from Michigan highlight recurring issues such as multi-factor authentication gaps, and agencies are shifting toward continuous assessment models with quarterly reviews rather than relying solely on triennial visits.
The tightened encryption and scanning requirements could significantly raise the compliance burden for state and local agencies, particularly smaller departments with limited IT staff. However, this may also reduce the risk of data breaches involving sensitive criminal records. The phased audit deadlines could create confusion, but the trend toward continuous assessment may ultimately lead to more consistent security practices across jurisdictions.