RackTop Systems
Federal & Defense

CJIS Security Changes for 2026 and 2027: What State and Local Agencies Need to Know

Two dates now shape CJIS planning for state and local agencies: the FIPS 140-2 sunset on September 21, 2026, and the end of the zero-cycle period on September 30, 2027. Here is what each one actually requires, and why so much of the work lands on storage.

RackTop SystemsAugust 21, 202611 min read

Key takeaways

  • CJIS Security Policy v6.1 was published June 25, 2026 and took effect June 26, 2026. It is a corrections release on top of v6.0, which restructured the policy onto NIST SP 800-53 control families in December 2024.
  • September 21, 2026 is the last day a FIPS 140-2 validation is active. The following day every FIPS 140-2 certificate moves to the NIST CMVP Historical List, which removes it as justification for new procurement.
  • Priority 2 through Priority 4 modernized requirements sit in a zero cycle that ends September 30, 2027. Plan for normal audit and sanction treatment from October 1, 2027 unless the FBI changes the schedule.
  • Existing and Priority 1 requirements, including multi-factor authentication, have been sanctionable since October 1, 2024. Nothing about 2027 defers those.
  • The FBI does not offer certification of vendor compliance with CJIS. Contractors sign the CJIS Security Addendum and providers hold agreements with state CJIS Systems Agencies, so "CJIS certified" is not a credential any vendor can hold. Ask for control-level evidence instead.

Agencies that access, process, store, or transmit Criminal Justice Information are working against two dates that fall thirteen months apart. September 21, 2026 ends the useful life of FIPS 140-2 validations. September 30, 2027 ends the zero-cycle period the FBI granted for most of the modernized CJIS requirements, which puts them into normal audit and enforcement treatment on October 1, 2027.

Neither date is a general cybersecurity mandate for every state or municipal system. Both apply to the agencies and service providers that handle CJI or run the systems supporting it. States can and do impose requirements stricter than the federal baseline, so the CJIS Systems Agency in your state has the final word on how these dates land locally.

What version 6.1 changed, and what version 6.0 already had

The FBI published CJIS Security Policy version 6.1 on June 25, 2026, effective the next day, incorporating changes approved by the CJIS Advisory Policy Board during calendar year 2025. Version 6.1 is a corrections release. The structural work happened in version 6.0, published December 27, 2024, which completed the policy modernization effort.

That modernization is the part worth understanding. The old thirteen-policy-area structure that most CJIS explainers still describe is gone. The policy now runs to twenty policy areas, eighteen of which are NIST SP 800-53 control families taken in order, from Access Control through System and Information Integrity. Policy Area 1 (Information Exchange Agreements) and Policy Area 20 (Mobile Devices) keep the older framing because they have no direct NIST equivalent.

For an agency, the practical consequence is that CJIS now reads like a control catalog rather than a set of narrative policy areas. Subjects that used to occupy a paragraph, including contingency planning, audit and accountability, and supply chain risk management, are now full control families with individual requirements, assigned priorities, and defined sanction dates. An auditor can ask which policy version introduced a given requirement, what priority it carries, and what your remediation plan is if it is still open.

CJIS Security Policy modernization timeline, 2024 to 2027A vertical timeline of CJIS Security Policy milestones. December 27, 2024: version 6.0 completes the modernization, restructuring the policy into twenty policy areas built on NIST SP 800-53 control families. October 1, 2024: Existing and Priority 1 requirements, including multi-factor authentication, become sanctionable at audit. October 1, 2024 through September 30, 2027: the zero cycle, during which Priority 2 through Priority 4 requirements are part of the policy and reviewed at audit but not sanctioned. June 25, 2026: version 6.1 is published as a corrections release incorporating Advisory Policy Board changes approved during 2025. September 21, 2026, highlighted: the last active day for a FIPS 140-2 validation, after which all remaining certificates move to the NIST CMVP Historical List, affecting controls SC-13 and SC-28. September 30, 2027, highlighted: the zero cycle closes and Priority 2 through Priority 4 requirements enter normal audit and sanction treatment from October 1, 2027. The timeline closes with a reminder that 2027 is not a grace period for the controls already in force.Two dates, not one deadlineThe CJIS modernization timeline, 2024–2027Policy publishedIn effectDeadline aheadDEC 27, 2024CJIS Security Policy v6.0Modernization complete: 20 policy areas,restructured onto NIST SP 800-53 familiesOCT 1, 2024Priority 1 becomes sanctionableExisting and Priority 1 requirements, includingmulti-factor authentication, auditable nowOCT 1, 2024 – SEP 30, 2027Zero cycle opensPriority 2 through 4 requirements are in policyand reviewed at audit, but not yet sanctionedJUN 25, 2026CJIS Security Policy v6.1Corrections release folding in the AdvisoryPolicy Board changes approved during 2025SEP 21, 2026 · PLAN BACKWARD FROM HEREFIPS 140-2 validations go HistoricalLast active day for a 140-2 certificate. ControlsSC-13 and SC-28 need validated cryptography.SEP 30, 2027 · PLAN BACKWARD FROM HEREZero cycle closesPriority 2 through 4 enter normal audit andsanction treatment from October 1, 2027WHAT 2027 DOES NOT DEFERAlready auditableMFA, account management, remote accessboundary protection, vulnerability scanningconfiguration baselines, flaw remediation
The CJIS modernization timeline. Priority 1 requirements have been sanctionable since October 2024; the two dates ahead are the FIPS 140-2 sunset and the end of the zero cycle.

September 21, 2026: the FIPS 140-2 sunset

This deadline originates at NIST rather than at the FBI, but it lands on CJIS through control SC-13, which requires cryptographic protection using validated modules, and control SC-28, which covers CJI at rest, particularly outside a physically secure location.

The NIST Cryptographic Module Validation Program stopped accepting FIPS 140-2 submissions for new validation certificates on April 1, 2022. Under the transition schedule, FIPS 140-2 modules stay active for five years after validation or until September 21, 2026, whichever comes first, and on September 22, 2026 all remaining FIPS 140-2 certificates are placed on the Historical List.

Historical status does not switch anything off. CMVP is explicit that it supports the purchase and use of those modules for existing systems, and a validated module that worked on September 21 still works on September 22. What changes is the paperwork underneath it. A Historical certificate no longer supports a new procurement decision or a control-satisfaction argument that depends on active validation, which is exactly the argument an agency makes when it maps a storage platform to SC-13 and SC-28.

The work between now and then is an inventory, not a rip and replace. Every technology that encrypts CJI belongs on the list: NAS and file servers, backup and disaster recovery platforms, cloud storage, VPN gateways and TLS terminators, mobile devices, CAD and RMS platforms, evidence repositories, managed file transfer, databases, and key management systems.

Ask vendors for the certificate, not the adjective

A vendor statement that a product is "FIPS compliant" carries no weight in an audit. FIPS compliance is not a status a company confers on itself, and the phrase is frequently used to describe a product that calls a validated library without the deployed configuration falling inside the validation boundary.

The evidence an agency should collect for each system is specific enough to check against the public CMVP database:

What to ask forWhy it matters
Cryptographic module name and CMVP certificate numberLets you confirm active vs. Historical status yourself instead of taking the claim on faith.
Exact software or firmware version the certificate coversValidations attach to a specific build. The version you run may sit outside the one that was validated.
Validation standard and level (140-2 vs. 140-3, Level 1 through 4)Determines whether the certificate survives September 21, 2026 and whether the level suits the deployment.
Approved algorithms and required operating modeA module often has to be placed in an approved mode to be operating as validated. Default configuration is frequently not that mode.
Whether hardware and software encryption are covered separatelySelf-encrypting drives and a software cryptographic module are distinct validations. One does not imply the other.
The vendor migration plan and its datesIf a product is still on a 140-2 certificate, you need the 140-3 timeline before your own remediation register can be credible.

The zero cycle ends September 30, 2027

When the FBI modernized the policy, it tagged each requirement with a priority and gave the lower priorities room to land. Requirements marked Existing or Priority 1 have been sanctionable since October 1, 2024. Requirements marked Priority 2 through Priority 4 were placed in a zero cycle running from October 1, 2024 through September 30, 2027.

A zero cycle is one full audit cycle of review and education without sanction, which is three years because CJIS Systems Agencies are audited triennially. During that window the requirements are fully part of the policy and agencies are expected to work toward them, but a gap generally does not produce a sanction. The National Association of Counties has told its members to be ready by October 1, 2027.

Requirement setStatus todayWhen it bites
Existing and Priority 1 (includes multi-factor authentication)SanctionableSince October 1, 2024
Priority 2 through Priority 4 modernized requirementsZero cycle: reviewed and educated, not sanctionedZero cycle ends September 30, 2027
Cryptographic modules under SC-13 and SC-28FIPS 140-2 validations still activeHistorical List from September 22, 2026

What the 2027 requirements cover

The requirements approaching the end of the zero cycle reach well past encryption. Governance and documentation obligations run across access control, audit and accountability, configuration management, contingency planning, incident response, risk assessment, system acquisition, physical and personnel security, and supply chain risk management, with periodic review and update expected for most of them.

Logging and monitoring requirements ask whether audit records exist at sufficient capacity, whether they are protected from tampering, whether anyone reviews and correlates them, and whether personally identifiable information is being written into logs unnecessarily. CJIS has long expected audit records to be retained and reviewed rather than merely generated.

Resilience requirements cover contingency planning, backup protection and testing, alternate storage and processing, telecommunications resilience, and recovery to a known trusted state. For ransomware readiness the operative question is not whether backups exist. It is whether the backups and the recovery path can survive an attacker who already holds privileged credentials.

Supply chain requirements now include a documented supply chain risk management plan that is reviewed annually, vendor vetting before onboarding, inspection of systems and components before deployment, and notification agreements obliging vendors to report breaches affecting government systems. That pulls procurement and legal into a program that used to sit entirely inside IT.

2027 is not a grace period for the controls already in force

The most common planning error is treating September 2027 as a single deadline for all CJIS security work. Multi-factor authentication, which the policy calls advanced authentication, has been sanctionable at audit since October 1, 2024. So have account management, identification and authentication, remote access, boundary protection, vulnerability scanning, configuration baselines, flaw remediation, malicious code protection, system monitoring, and software integrity.

The right unit of analysis is the requirement, not the domain. The FBI publishes a Requirements Companion Document alongside the policy precisely so that agencies can work control by control, checking the priority and sanction date on each one rather than assuming an entire security area is deferred.

Nobody is CJIS certified

Worth stating plainly because the market muddies it: the FBI does not offer certification of vendor compliance with CJIS requirements. Large cloud providers document this on their own CJIS pages. What exists instead is a chain of agreements and audits. Private contractors that process CJI sign the CJIS Security Addendum, a uniform agreement approved by the U.S. Attorney General that binds them to the policy. Providers enter information agreements with individual state CJIS Systems Agencies. The agency itself is then audited by its CSA.

Several states also run their own vendor compliance or vendor management programs, and those are real and worth using. What none of them produce is a national credential. When a storage, cloud, or software vendor markets itself as "CJIS certified," the accurate reading is that the vendor has described a certificate nobody issues. Ask instead which specific controls the product supports, what evidence it produces for an auditor, and which controls remain the agency's responsibility.

Cloud and managed services do not absorb the obligation

Moving CJI into a cloud or managed service redistributes the work without transferring accountability. CJIS establishes shared responsibilities across IaaS, PaaS, and SaaS models, and the agency remains answerable for protecting CJI in all of them.

Contracts covering CJI should therefore be specific about encryption requirements and key custody, security logging and the agency's access to it, incident notification timelines, vulnerability management, data location, personnel screening, subcontractors, audit cooperation, data return and destruction, and recovery commitments. The question to answer before signing is simple to state and frequently unanswered in practice: for each applicable control, who performs it, and what evidence will exist when an auditor asks.

Why so much of this lands on storage

CJI is unstructured data. Case files, investigative documents, evidence exports, body-worn and interview video, court filings, and RMS and CAD extracts all end up as files on a share. Security architectures tend to treat that share as passive infrastructure and concentrate on the perimeter, identity, endpoints, and backup. The CJIS control families that come due in 2027 do not accept that division.

Read them against the storage layer and the mapping is direct. Audit and Accountability asks for a record of who touched which file, when, and from where, protected against the administrator who might want it edited. Access Control and Identification and Authentication ask whether one compromised credential can traverse every share, or whether authorization is evaluated per file and per operation. System and Communications Protection asks for validated encryption of CJI at rest. Contingency Planning asks whether recovery reaches a known trusted state and whether the recovery copies themselves survive a privileged compromise. System and Information Integrity asks whether anything is watching the data for behavior that indicates an attack in progress.

This is the argument for putting security controls in the storage data path rather than around it. A platform that evaluates attribute-based policy on every SMB, NFS, S3, and Web Drive operation, writes an immutable per-operation audit record, holds immutable copies that survive administrative compromise, and detects the bulk-read and mass-change behavior that signals exfiltration or encryption is answering several CJIS control families at one place in the architecture, with evidence an assessor can read.

That is what BrickStor SP was built to do. Systems shipped since 2022 with FIPS drives use FIPS 140-3 Level 2 validated self-encrypting drives, and BrickStor SP 23.8 and later uses a FIPS 140-3 Level 1 validated software cryptographic module, which is the side of the September 2026 date agencies need their storage on. Active Defense inspects file operations inline and can terminate a malicious session in under a second. ImmutaVault holds immutable, isolated copies inside the platform. Intelligent Bulk Remediation restores exactly the files an attack touched, which is how recovery to a known trusted state stops being a plan and becomes an operation with a duration. None of that makes an agency compliant on its own. It changes what the agency can prove.

Where to start

Build the cryptography inventory first, because September 2026 arrives first and the answer for each system is either a certificate number or a gap. Then extract every zero-cycle requirement into a remediation register with an owner, a current status, the evidence an audit will require, a budget line, and any vendor dependency.

Sequence the register by lead time rather than by priority number. Storage modernization, cyber recovery, log management, data center physical controls, retiring unsupported systems, cloud contract renegotiation, and alternate facilities are the items that cannot be closed in a quarter, and they are the ones most likely to still be open in September 2027 if they start last. Review vendor and cloud contracts against that register, and confirm the whole plan with your CJIS Systems Agency, CJIS Systems Officer, and state Information Security Officer, since state requirements can exceed the federal baseline.

The point of the exercise is not the audit. It is that criminal justice data stays confidential, available, trustworthy, and recoverable while systems are under attack, which is the condition the policy exists to produce.

Frequently asked questions

September 21, 2026 is the last day FIPS 140-2 cryptographic module validations remain active. On September 22, 2026 the NIST Cryptographic Module Validation Program places all remaining FIPS 140-2 certificates on the Historical List. Modules keep working and CMVP supports their continued use in existing systems, but a Historical certificate no longer supports new procurement or a control-satisfaction argument under CJIS controls SC-13 and SC-28, which require validated cryptography for CJI.
The zero cycle is a single audit cycle of review and education without sanction that the FBI granted for modernized requirements marked Priority 2 through Priority 4. It runs from October 1, 2024 through September 30, 2027, three years because CJIS Systems Agencies are audited triennially. Those requirements are already part of the policy and agencies are expected to work toward them during the window. Plan for normal audit and enforcement treatment from October 1, 2027.
No. Requirements marked Existing or Priority 1 have been sanctionable since October 1, 2024, including multi-factor authentication, account management, remote access, boundary protection, vulnerability scanning, configuration baselines, flaw remediation, malicious code protection, and system monitoring. Work the FBI Requirements Companion Document control by control and check the priority and sanction date on each requirement rather than assuming a whole security domain is deferred.
No. The FBI does not offer certification of vendor compliance with CJIS requirements, and there is no national CJIS certification for technology. What exists is a chain of agreements and audits: contractors that process CJI sign the CJIS Security Addendum, providers enter information agreements with individual state CJIS Systems Agencies, and the agency is audited by its CSA. Some states also run their own vendor compliance programs, but those are state programs, not a federal credential. Evaluate a product on the specific controls it supports and the evidence it can produce for an auditor.How BrickStor SP supports government agencies
It redistributes the work but not the accountability. CJIS defines shared responsibilities across IaaS, PaaS, and SaaS, and the agency remains answerable for protecting CJI. Contracts should specify encryption and key custody, security logging and agency access to it, incident notification timelines, data location, personnel screening, subcontractors, audit cooperation, data return and destruction, and recovery commitments, with a clear control-by-control split of who performs what.
Access Control and Identification and Authentication govern who can reach which files and under what conditions. Audit and Accountability governs the record of file access and its protection from tampering. System and Communications Protection covers validated encryption of CJI at rest, including SC-13 and SC-28. Contingency Planning covers backup protection and testing, alternate storage, and recovery to a known trusted state. System and Information Integrity covers monitoring for the behavior that indicates an attack in progress.

See data-layer defense in action

A 30-minute demo shows Active Defense stopping an attack inline, immutable recovery, and surgical rollback — mapped to your environment.

CJIS Security Policy Changes for 2026 and 2027 | RackTop