The FBI’s release record establishes the version and date. Texas Department of Public Safety describes v6.1 as incorporating corrections and additions approved through the 2025 Advisory Policy Board process, following the modernized v6.0 policy issued in December 2024.
For Windows and enterprise administrators supporting criminal justice systems, the immediate task is to identify which controls need adjustment—and which existing controls need better evidence of operation.
What security teams should review
Texas DPS identifies four areas for agencies to examine: privileged-account management and session locking, multifactor authentication across CJI access points, incident-reporting timelines and escalation procedures, and guidance for FedRAMP-authorized cloud environments. It explicitly advises agencies to begin gap assessments.
Those priorities reach beyond a password-policy change. They involve the accounts that administer systems, the routes people use to reach sensitive information, the procedures followed during an incident, and the responsibilities attached to hosted services.
A useful assessment should connect each applicable requirement to an actual system and an accountable owner. For an environment using Active Directory, Windows servers or cloud identity services, the following questions provide a practical starting point:
- Which privileged accounts can administer systems that handle CJI, and who owns the process for reviewing those accounts?
- Which authentication paths provide access to CJI, and what evidence demonstrates the protection applied to each path?
- Who receives an incident report, who escalates it, and do the written procedures reflect the applicable reporting requirements?
- Which CJI workloads use cloud services, and which controls remain the agency’s responsibility?
These are assessment questions, not a substitute for the policy’s individual controls. They help turn a broad compliance review into a list of systems, responsibilities and evidence that administrators can act on.
Keep technical changes tied to the control text
An important limitation remains in the publicly summarized guidance: Texas’s announcement identifies review areas but does not reproduce the detailed encryption, scanning or authentication requirements.
Consequently, it does not establish the precise before-and-after wording for cipher strength, vulnerability-scanning frequency or password checks. Those distinctions materially affect configuration decisions. Teams should avoid treating a general description of “stronger encryption” or “more frequent scanning” as an implementation specification.
For each proposed configuration change, record the applicable v6.1 control identifier, its requirement, the systems within scope and the current configuration. That comparison separates a newly introduced obligation from an existing requirement that was previously overlooked. It also avoids applying a narrowly scoped requirement indiscriminately across an entire Windows environment.
Confirm the audit baseline separately
Knox Systems’ August 2026 explanation reports that state CJIS Systems Agencies set their own timelines for adopting a new version for audit purposes. Its guidance is to confirm the applicable baseline with the state contact before assuming that v6.1 publication immediately replaces the version used in an assessment.
That creates two parallel workstreams:
- Establish the policy version, implementation guidance and deadlines governing the agency’s next assessment.
- Compare the environment with v6.1 and plan the work needed to address applicable differences.
An audit conducted against an earlier version does not make preparation for v6.1 wasted effort. Conversely, preparing for v6.1 does not eliminate obligations under the current assessment process.
The most useful outcome is a version-specific gap register: each entry should identify the control, affected system, responsible owner, required change and evidence needed to demonstrate completion. That gives security teams a defensible implementation plan without confusing a policy announcement, a product purchase and a completed compliance assessment.