Federal & defense · FBI CJIS Division
FBI CJIS Security Policy 6.0
Anyone handling criminal justice information, including contractors, with full compliance expected by October 1, 2027.
Who it applies to
The businesses that carry CJIS 6.0, and the pages written for them.
Each industry page names the regulation, the obligation and the clock, tells the story of an owner in that trade, and shows what we protect for them.
Which packages satisfy it
Cyber and Data Protection Assessment
Any business of 10 to 500 people that has never had a real assessment, or has not had one in a year
CMMC Level 2 Gap Readiness Package
Defense manufacturers, engineering and design firms, and IT and service suppliers of 10 to 300 people handling CUI
CMMC Self-Assessment and SPRS Score Calculation
Suppliers who need a current, defensible SPRS score now and a clear path toward Level 2 later
What it asks for
In plain English, what CJIS 6.0 expects you to have in place.
- A defined boundaryWhere controlled information lives, moves and is stored, and which systems and people can reach it.
- The control set, implementedEvery applicable requirement met or on a plan, with the objective-level evidence that proves it.
- A System Security PlanThe document that describes your environment and how each requirement is satisfied.
- A Plan of Action and MilestonesOpen items, owners and dates, limited to what the rule allows to remain open.
- Incident reportingA rehearsed procedure that meets the reporting clock in your contract.
- Flow-downThe same obligations passed to the subcontractors and cloud providers that handle the data.
A note on authority: the regulator, auditor or certifying body has the final say on whether you comply. We help interpret the requirements, scope what applies, gap-assess against what is published today, and keep you compliance-ready and secure as the guidance evolves. We hold no regulatory authority and do not certify.
Questions we get about CJIS 6.0
Do you certify CJIS 6.0 compliance?
Where do we start with CJIS 6.0?
We also need other frameworks. Do we do CJIS 6.0 separately?
Also in federal & defense: CMMC 2.0 · NIST 800-171 · every framework by industry
Next step
Thirty minutes, an engineer, a written scope for CJIS 6.0.
Book the demo and see how one control set carries CJIS 6.0 and everything else you owe. Or leave your details and an engineer replies within one business day.