The One-Hour Reporting Requirement

IR-6(a) is unambiguous: personnel must report suspected security incidents to the organizational incident response capability immediately, but not to exceed one hour after discovery.

Two words in that sentence deserve attention before anything else: suspected and discovery.

The clock starts at discovery. Not at confirmation, not at investigation, not at escalation. The moment someone becomes aware of something that might be an incident, the one-hour window opens.

The reporting obligation applies to suspected incidents. An agency that waits for confirmation before reporting has already exceeded what the control requires. The policy does not give personnel latitude to investigate first and report after. The report goes in when discovery happens.

Who gets notified

IR-6(b) defines the reporting chain. The report goes to organizational personnel with incident handling responsibilities, and to the CSO, SIB Chief or Interface Agency Official, and FBI CJIS ISO.

That is not an internal notification. The FBI CJIS Division ISO is on the list. An agency whose incident response process routes discovery to an internal help desk for triage before any external notification has a process that does not satisfy IR-6(b) for incidents involving CJI.

Most agencies are not thinking about the FBI CJIS ISO as an immediate notification target when a patrol officer reports something unusual on their workstation. That gap between what the policy requires and what the operational process does is where IR-6 findings originate.

IR-6(1) — the automated reporting enhancement

IR-6 carries an enhancement marked Existing and Priority 2: automated reporting mechanisms. The control lists examples: email, posting on websites with automatic updates, automated incident response tools.

The automated reporting requirement is not a recommendation. Existing status means it has applied since before v6.1. An agency handling IR-6 reporting through entirely manual processes has a gap against IR-6(1) in addition to the base control.

The operational question the policy creates

Most agencies have incident response plans. Those plans typically establish investigation procedures, escalation paths, and notification requirements. The question IR-6 creates is whether the one-hour clock appears anywhere in those plans — and whether it is tied to discovery rather than to confirmation or escalation.

A plan that requires notification within one hour of a confirmed incident does not satisfy IR-6. A plan that starts the clock at the help desk ticket rather than at the moment a user reported something does not satisfy IR-6. A plan that routes CJI incidents through an IT triage process before the CSO is notified does not satisfy IR-6(b).

The enforcement date question is relevant here. IR-6 is Priority 2 and marked Existing, which means it falls outside the Priority 1 sanction set that has been enforceable since October 1, 2024. Priority 2 sits in the zero cycle ending September 30, 2027. That said, §1.4 makes existing requirements sanctionable regardless of the zero cycle — and IR-6 is an existing requirement. The interaction between the existing marking and the priority tier is worth confirming with your CSA, since different CSAs may be applying the enforcement boundary differently.

What is not in question is that IR-6 will be fully auditable when the zero cycle closes. An agency whose incident response process has never been tested against the one-hour clock, the specific notification chain, or the automated reporting requirement has work to do before that date.

What adequate evidence looks like

An auditor reviewing IR-6 compliance is looking for: a documented incident response policy and procedure that reflects the one-hour discovery-to-report requirement; evidence that personnel have been trained on it; a reporting mechanism that reaches the IR-6(b) notification chain including the FBI CJIS ISO; automated notification capability; and records of any incidents or tests of the procedure.

A plan that describes incident response generally, without addressing the CJIS-specific notification chain and timing, is a plan. It is not evidence the control operates.

Read next
Why Attestation Is Not Assurance
An incident response plan is documented evidence. Whether IR-6 is satisfied depends on what the plan contains and whether it has been tested.

Sources: CJIS Security Policy v6.1, 06/25/2026 — IR-6 Incident Reporting; IR-6(1) Automated Reporting; §1.4 Terminology Used in This Document. Requirement Companion Document v6.1.

Questions about how this applies to your agency: agency@cjis360.com

Back to the Knowledge Center