CJIS Compliance Explained: Requirements and Scope

Written by: 
Team Knox
Published on: 
August 3, 2026

The FBI, through its Criminal Justice Information Services (CJIS) Security Policy framework, sets the minimum security requirements for any system that touches Criminal Justice Information (CJI). It reaches law enforcement agencies and vendors whose software stores, processes, or transmits that data on their behalf.

CJIS compliance is established state by state through signed agreements and recurring audits, rather than through a federal certification body, accredited assessor pool, or marketplace listing a vendor can point to.

That state-by-state model reshapes how a SaaS compliance program must be built before the first contract closes. For SaaS providers, it affects data classification, contracting, control mapping, cloud architecture, and federal authorization strategy.

Key Takeaways

  • CJI scope is broad. The policy protects biometric CJI data, identity history, biographic data, property data tied to personally identifiable information, and case/incident history, with stricter controls on Criminal History Record Information.  
  • Scope extends broadly. Courts and corrections agencies, authorized noncriminal justice agencies, CJIS cloud providers, information technology (IT) vendors, and even physical contractors near CJI transmission areas all carry obligations.  
  • The policy baseline is now Version 6.1. The Federal Bureau of Investigation released Version 6.1 in June 2026, succeeding the Version 6.0 reorganization that aligned controls with the National Institute of Standards and Technology (NIST) SP 800-53 Revision 5 catalog, the same catalog Federal Risk and Authorization Management Program (FedRAMP) baselines draw from.  
  • Architecture does not matter. On-premises, cloud, and hybrid deployments carry identical obligations because the requirements follow the data, not the infrastructure.

CJIS Compliance Protects Criminal Justice Information Across Any Environment

The CJIS Security Policy is the FBI's minimum-security framework for CJI: the data law enforcement and civil agencies draw from FBI systems such as the National Crime Information Center (NCIC) and the Next Generation Identification (NGI) biometric repository.

Policy v5.9.5 defines CJI to include:

  • Biometric data, including fingerprints, iris scans, DNA profiles, and other biometric identifiers.  
  • Identity history.  
  • Biographic data.  
  • Property data when accompanied by personally identifiable information.  
  • Case/incident history.

That scope is broad, and Criminal History Record Information (CHRI) is a subset that carries additional access and dissemination controls because of its sensitivity.

The policy does not distinguish between hosting models: a county's on-premises records system, a cloud-hosted digital evidence platform, and a hybrid deployment all carry the same obligations, since coverage follows the data across whatever infrastructure holds it. That data-first orientation is also what determines who falls under the policy in the first place.

CJIS Compliance Applies to a Wider Group Than Sworn Law Enforcement

The policy covers every individual who accesses or operates in support of criminal justice services and information. In practice, the covered groups include:

  • Criminal justice agencies: police departments, sheriffs, prosecutors, courts, corrections, and probation at the federal, state, tribal, and local levels.  
  • Non-criminal justice agencies with authorized access: organizations granted CJI access for a specific purpose, such as school boards, banks, medical boards, and social services agencies running fingerprint-based background checks.  
  • Technology vendors: cloud service providers and IT vendors that store, process, transmit, or support CJI.  
  • Physical contractors and private contractors: personnel who need unescorted access to areas where unencrypted CJI is stored, processed, or transmitted. Private contractors performing criminal justice functions must meet the same training and screening standards as the agencies they serve and remain subject to the same audits.

Vendor and contractor obligations sit inside a broader control structure, and that structure is the same one the policy itself was recently reorganized around.

The CJIS Security Policy Maps Its Requirements to NIST 800-53

The NIST SP 800-53 Rev5 (September 2020) control catalog is the reference framework behind the CJIS Security Policy, and it is the same catalog the current FedRAMP Rev5 baselines, approved May 30, 2023, are built from. That shared ancestry matters for any vendor planning to satisfy both.

Version 6.1 Is Now The Current Policy Baseline

The FBI's Security Policy Modernization Task Force released CJIS Security Policy Version 6.0 on December 27, 2024, reorganizing the policy from 13 policy areas into control families aligned with NIST 800-53 Revision 5 at the moderate baseline, and tagging every control with a priority tier from 1 to 4, including multi-factor authentication (MFA) for CJI access outside physically secure locations as a Priority 1 control.

The FBI published Version 6.1 on June 25, 2026, superseding 6.0 as the current baseline. As with any policy update, individual state CJIS Systems Agencies set their own timelines for when a new version governs audits, so vendors and agencies operating under 6.0 should confirm with their state contact whether 6.1 has been adopted for audit purposes in that jurisdiction before treating it as authoritative for compliance work.

Each Policy Area Maps to Specific NIST Controls

The FBI's CJIS Information Security Officer publishes a companion document mapping the policy to many mapped "best fit" NIST 800-53 controls. The common mappings fall into several control families:

  • Access control requirements correspond to the AC family.  
  • Incident response requirements correspond to the IR family.  
  • Personnel security requirements correspond to the PS family.  
  • Encryption requirements correspond to SC controls such as SC-13.

The mapping document is explicit that the correspondence between CJIS controls and federal controls may not always be exact, and that agencies must still meet CJIS Security Policy requirements directly during audits. For cloud service providers (CSPs), Version 6.0 direction is similarly direct: a CSP must employ appropriately tailored security controls from the moderate baseline defined in the policy. That mapping gives cloud and SaaS providers a legible starting point, but it doesn't replace the separate contractual and audit obligations a provider has to satisfy on its own, which is where the compliance work actually begins.

Cloud Providers Must Take Specific Steps to Support CJIS Compliance

A cloud or SaaS provider handling CJI has four core obligations:

  1. Sign the CJIS Security Addendum. This uniform contract, approved by the U.S. Attorney General, authorizes access to CHRI, limits use to the purpose it was provided for, and provides for sanctions. It is executed through applicable state or agency agreements; no central FBI-CJIS authorization body exists.  
  2. Implement the required technical controls. Encryption of CJI must use Federal Information Processing Standards (FIPS) 140-3 validated cryptography. The FIPS 140-3 requirements draw on the same NIST 800-53 basis FedRAMP uses, alongside MFA and documented access management.  
  3. Support personnel screening. State and national fingerprint-based background checks are required before anyone gets unescorted access to unencrypted CJI. Personnel without completed checks must be escorted by authorized staff at all times.  
  4. Undergo ongoing audits. State CJIS Systems Agencies audit contractors at least triennially, on the same terms as local user agencies, and the FBI may conduct unannounced inspections of contractor facilities.

Meeting these four obligations gets a provider into the compliance conversation, but it doesn't make that posture portable. A vendor's standing with one agency doesn't automatically carry over to the next.

A Cloud Platform's Compliance Does Not Automatically Cover Its Customers

CJIS compliance runs through state and agency processes, and the FBI offers no marketplace-style endorsement that a vendor can use across all states. Any vendor marketing itself as "CJIS certified" at the federal level is overstating what that decentralized model provides.

Shared Responsibility Still Applies

Agencies should not assume a FedRAMP-authorized or State Risk and Authorization Management Program (StateRAMP)-authorized product necessarily puts them in compliance with the security policy. Shared responsibility divides obligations across:

  • Agencies: configuration, access control, data classification, and vendor oversight.  
  • Vendors: personnel policies and application-level controls, with training records to support review.

Colorado's Bureau of Investigation notes that the same vendor may run a compliant configuration for one client and a non-compliant one for another. That variability is a direct consequence of how the policy treats infrastructure: it doesn't set architectural requirements; it sets data requirements, which is worth examining directly.

CJIS Is Architecture Independent

Section 2.2 of the policy states that it looks at the data, services, and protection controls that apply regardless of implementation architecture. Appendix G.3 applies that principle to the cloud directly, noting that device and architecture independence permits the use of cloud computing without changing the underlying security requirements.

Two cloud-specific constraints still apply:

  • Storage location: CJI may only be stored within Advisory Policy Board (APB) member country boundaries, regardless of which cloud provider or region a vendor uses.  
  • Encryption key control: anyone with access to the encryption keys can decrypt stored files, and therefore counts as having unescorted access to unencrypted CJI. Key management is the main architectural lever in CJIS system design.

CJIS shares technical lineage with federal cloud authorization and operates through different legal and audit mechanics. That distinction matters most when vendors try to use one authorization posture to support another market.

CJIS and FedRAMP Share a Foundation but Serve Different Missions

The FedRAMP authorization program governs cloud services holding federal data through a Rev5 centralized authorization model. An accredited Third-Party Assessment Organization (3PAO) validates the system, and the package is listed on the FedRAMP Marketplace. Each agency issues its own Authority to Operate (ATO).

That assessment structure matters for vendors that use an outside platform. FedRAMP LI-SaaS and Low each require 156 controls under Rev5, FedRAMP Moderate requires 323 controls, and FedRAMP High requires 410 controls. CJIS runs the opposite way. Each state or territory has exactly one CJIS Systems Agency (CSA); compliance is established through signed addenda rather than a marketplace listing, and CSAs audit their agencies and vendors at least every 3 years. CJIS also adds CJIS-specific requirements for encryption and audit-log retention, with fingerprint-based screening handled through personnel controls.

The overlap helps vendors reuse evidence across federal, state, and local justice markets, though each reviewing authority still requires its own agreement and audit package. That reuse potential becomes most visible when a vendor is trying to sell into both markets at once.

SaaS Vendors Serving Justice and Public Safety Agencies Face a Compliance Layering Problem

For a SaaS vendor selling into justice and public safety, CJIS is rarely the whole compliance bill. Federal buyers require FedRAMP; state and local agencies expect CJIS obligations met in each jurisdiction where they operate. The layers stack:

  • The federal authorization itself. The traditional path takes 12 to 36 months, and costs reach upwards of $3.5 million once assessment and remediation are counted alongside diverted engineering time.  
  • Per-state agreements. A growth-stage vendor faces a state-by-state motion with a fraction of the staff.  
  • Per-state personnel vetting and training, each on the local CSA's cadence and paperwork.  
  • Parallel audit calendars: triennial CSA audits in every covered state on top of FedRAMP continuous monitoring.

Every layer draws on the same NIST 800-53 catalog, yet each is evidenced, signed, and audited separately. What if the largest single layer, the federal authorization, were already built?

Meeting CJIS Requirements Starts With a Strong Federal Authorization Foundation

Because CJIS and FedRAMP both draw on the NIST 800-53 catalog, a vendor that builds its FedRAMP posture first arrives at every state CSA conversation with the evidence base those reviews rely on. The CJIS-specific remainder, state addenda plus fingerprinting and training cadence, becomes an incremental exercise instead of a second full compliance program.

Knox Systems is built for that sequence. Vendors deploy into Knox's pre-authorized FedRAMP boundary and inherit up to 80% of the NIST 800-53 control evidence CJIS reviews draw on. Knox supports FedRAMP Moderate, FedRAMP High, and DISA IL-4, with IL-5 targeted for December 2026, across AWS, Azure, and Google Cloud Platform.

To scope the fastest path to signed addenda and a federal authorization in hand, book a meeting with Knox.

FAQs about CJIS compliance

What penalties apply for CJIS non-compliance?

Sanctions include termination of CJIS service, and violations of the criminal history record regulations in Title 28 of the Code of Federal Regulations (CFR), Title 28 Part 20 regulations, carry civil penalties of up to $11,000 per violation. States may add sanctions up to criminal prosecution for misuse.

What is a Management Control Agreement?

A Management Control Agreement (MCA) is required when a noncriminal justice government entity, such as city or county IT, supports criminal justice functions. It gives the criminal justice agency authority to set and enforce priorities, personnel standards, and policy for every system component touching CJI.

How often is CJIS security awareness training required?

Role-based training is required within six months of assignment, with annual refreshers; contractors meet the same criteria as government personnel.

Does CJIS Require An Independent Assessor Like FedRAMP's 3PAO?

No. Unlike FedRAMP, which mandates an accredited Third-Party Assessment Organization to validate a system before authorization, CJIS compliance is audited directly by the state CJIS Systems Agency on a triennial cycle, with no equivalent accredited third-party assessor market. That's one of the structural differences that makes CJIS a state-audit model rather than a centralized authorization model like FedRAMP.