WATCHUR6 // CJIS SECURITY POLICY // AUDIT READINESS

CJIS doesn't care about your title.
It cares about access.

The FBI's CJIS Security Policy applies to anyone who touches criminal justice information — agencies, courts, and the vendors and IT staff behind them. And with version 6.0, it's shifting from a checklist to continuous, audit-ready accountability. We map your scope, close the gaps, and get you ready for the audit.

Book a CJIS Strategy Call
CJIS SECURITY POLICY MFA MANDATORY v6.0 BY OCT 2027 VETERAN-LED

// WHY CJIS, WHY NOW

The policy just modernized. The checklist era is ending.

ACCESS

Not your job title

CJIS applies to every entity that creates, stores, accesses, or transmits CJI — including non-justice agencies, vendors, MSPs, and IT admins. It's enforced individually, too.

MFA

No longer optional

Every account that touches criminal justice information must use multi-factor authentication — with the policy pointing to NIST 800-63 for phishing-resistant methods.

v6.0

Continuous, by Oct 2027

Version 6.0 shifts agencies from point-in-time checklists to continuous governance and audit-ready accountability, with full expected compliance by October 1, 2027.

// "WE'RE JUST THE VENDOR" ISN'T A SHIELD

We just provide IT support, CJIS is the agency's problem.
If you can reach CJI, CJIS applies to you — individually and as an organization.

CJIS is access-based: it doesn't care whether you're a police department or a contractor's after-hours admin — if you can create, store, access, or transmit criminal justice information, you're in scope. That means background screening, security awareness training, and MFA for the actual people with access, not just a policy on the agency's shelf. Vendors and MSPs who assume CJIS is "the agency's problem" become the finding in the agency's audit — and lose the contract. We make sure your access is defensible before the auditor maps it.

// WHAT v6.0 ACTUALLY CHANGES

Same data to protect. A whole new way to prove it.

The controls aren't being thrown out — they're being held to a higher standard. The shift to continuous, audit-ready accountability is the heart of version 6.0, and it changes how every control area below is judged.

Continuous Accountability The v6.0 shift · from checklist to always-audit-ready

The defining change in version 6.0: CJIS moves from point-in-time checklist compliance to continuous governance, risk management, and audit-ready accountability, with full expected compliance by October 1, 2027. You're no longer proving you were compliant on audit day — you're proving you stay compliant. The three control areas below are the substance; this is the standard they're now held to.

// IDENTITY & ACCESS

MFA & Authentication

Mandatory MFA on every account reaching CJI, identity proofing, and NIST 800-63 phishing-resistant methods.

// THE CONTROL SET

Policy Areas

Access control, incident response, monitoring, supply-chain risk, and system controls across the CJI lifecycle.

// PEOPLE & AUDIT

Personnel & Audit

Background screening, security awareness training, and the recurring CSA audit you're measured against.

Architecture-independent — the policy applies on-prem, cloud, or hybrid alike.

v5.9.5 · CURRENT AUDIT POLICY v6.0 · MODERNIZED · ~50% NEW Continuous Accountability · BY OCT 1, 2027

// THE PATH

From "who touches CJI?" to a clean audit.

How agencies and vendors build a defensible CJIS posture. The amber stages are the oversight-facing moments — the CSA audit, and the continuous accountability v6.0 now expects between them.

Scope

Map CJI & Access

WK 1–3

Assess

Gap vs 5.9.5 & 6.0

WK 3–6

Identity

MFA & Access Control

MO 1–3

Implement

Controls & Personnel

MO 3–6

Audit

CSA / FBI Review

ON CYCLE

Sustain

Continuous Accountability

ONGOING

Amber stages are the oversight-facing moments — the recurring audit your CJIS Systems Agency and the FBI conduct, and the continuous accountability version 6.0 expects you to sustain between audits. Everything before is the work that makes the review routine.

// IS THIS YOU?

Three signs CJIS is on you.

// 01 // JUSTICE AGENCY

You're an agency or court

You're law enforcement, a court, or a government body handling CJI, and the v6.0 modernization is reshaping what your next audit will expect.

// 02 // SUPPORTING VENDOR

You serve a justice agency

You're a vendor, MSP, or contractor whose people can reach CJI. You're in scope — and the agency's audit can turn on your controls.

// 03 // CHECKLIST MINDSET

You treat CJIS as a binder

Your compliance is a document you dust off before audits. Version 6.0's continuous accountability won't accept that posture much longer.

// WHAT WE DO

The scope, the controls, and the audit.

// Phase 01 · Scope

CJI Mapping & Gap Assessment

We map where CJI lives and who can reach it, then assess your posture against the current 5.9.5 policy and the modernized 6.0 — so you know exactly what today's audit and tomorrow's expect.

  • CJI data and access mapping
  • Gap assessment vs. 5.9.5 and 6.0
  • Vendor and third-party scope analysis

// Phase 02 · Implement

Identity, Controls & People

We implement mandatory MFA and access controls, build the personnel-security and training program, and put the policy-area controls in place across on-prem, cloud, and hybrid systems.

  • MFA and identity, aligned to NIST 800-63
  • Access control and policy-area controls
  • Personnel security, screening, and training

// Phase 03 · Sustain

Audit Prep & Continuous Compliance

We prepare you for the CSA audit and stand up the continuous monitoring and documentation that version 6.0 expects — so accountability is ongoing, not a pre-audit scramble.

  • CSA / FBI audit preparation
  • Continuous monitoring and documentation
  • Version-update tracking (6.1 and beyond)

// THE BINDER ERA IS ENDING

By October 2027, "compliant on audit day" won't be the standard. "Compliant every day" will.

Book a CJIS Strategy Call

// FREQUENTLY ASKED

The CJIS questions agencies and vendors keep asking.

Does CJIS apply to us if we're not a police department?

Quite possibly, because CJIS is access-based, not title-based. The policy doesn't care about your job title or department name; it cares about whether you create, store, access, or transmit Criminal Justice Information. That sweeps in far more than police and courts: non-justice government agencies, IT administrators, managed service providers, cloud and software vendors, and even on-call support staff who can reach systems holding CJI.

CJI itself is broad — criminal history records, arrest and warrant data, fingerprints and mugshots, jail and inmate records, dispatch logs, and court records tied to criminal cases. Compliance is enforced at the individual level, not just organizationally, so the people with access must meet requirements like background screening, security awareness training, and strong authentication. If you support law enforcement in any way through technology, records, or infrastructure, assume CJIS likely applies and confirm it deliberately.

What's the difference between CJIS version 5.9.5 and version 6.0?

They represent the current state and near future, and you need both. Version 5.9.5 (July 2024) is the policy that audits are currently conducted against, so it's your primary reference today. Version 6.0 (December 2024) is a major modernization — roughly half new content — that shifts CJIS away from point-in-time, checklist compliance toward continuous governance, risk management, and audit-ready accountability, revising areas like assessment and authorization, continuous monitoring, personnel security, and supply chain risk.

Agencies are expected to meet the modernized requirements by October 1, 2027, with enforcement milestones phasing in before then, so the right posture is to keep meeting 5.9.5 while running gap assessments against 6.0. CJIS is also moving to a faster rhythm — version 6.1 is expected in 2026, with updates roughly every six to twelve months — which is itself a reason to treat compliance as an ongoing program, not a periodic project.

Is multi-factor authentication actually required for CJIS now?

Yes. MFA is no longer optional: every account that accesses Criminal Justice Information must use it, so a stolen or guessed password alone cannot grant access to CJI. The policy doesn't lock you into a single product, but it points to NIST SP 800-63 Digital Identity Guidelines, which describe phishing-resistant authentication — an important nuance, because not all MFA is equally strong against modern credential-phishing.

Alongside MFA, the modernized policy tightens authenticator hygiene, including a banned or commonly-compromised password list and rules on how often certain authenticators must change. For most agencies and vendors, the challenge isn't understanding that MFA is required — it's implementing it consistently across every system and account that can reach CJI, including service accounts, admin access, and third-party connections, without breaking the workflows officers and staff depend on. That complete coverage is what an auditor looks for.

Is CJIS a certification, and who audits us?

CJIS is not a certification you earn once; it's a security policy you're audited against on a recurring basis. Oversight is tiered: the FBI's CJIS Division sets the national policy, and within each state a CJIS Systems Agency (CSA) administers access to FBI criminal justice information and ensures the agencies and vendors under it comply. Audits are typically conducted on a recurring cycle — commonly every three years — by the FBI and the state CSA, assessing whether your technical, administrative, and physical controls actually meet the policy in practice.

Because version 6.0 emphasizes continuous accountability rather than a point-in-time snapshot, the expectation is increasingly that you can demonstrate compliance at any time, not just the week before an audit. That's why the durable approach is to build CJIS into ongoing operations — identity, monitoring, personnel security, and documentation maintained continuously — so an audit becomes a confirmation of what you already do. We help agencies and vendors reach that state and prepare for the CSA audit itself.

// THE NEXT MOVE

Find out who touches CJI before the auditor does.

Book a 30-minute CJIS strategy call with a WatchUr6 advisor. Bring whether you're an agency or a vendor, where criminal justice information lives in your environment, and when your next CSA audit falls. You'll walk away knowing your scope, your gaps against 5.9.5 and 6.0, and a path to continuous compliance — whether you hire us or not.

Book a CJIS Strategy Call

SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED