The Complete CJIS Compliance Checklist for Agencies and Vendors
The FBI's Criminal Justice Information Services (CJIS) Security Policy binds organizations that handle Criminal Justice Information (CJI), including police departments and county IT departments, as well as the vendors that sell software to both.
Version 5.9.5 remains the policy for which FBI audits are conducted through March 31, 2027. The modernized policy line, version 6.0 (updated to version 6.1 in June 2026), is not yet the audit baseline, but its Priority 1 controls are already sanctionable, with the remaining tiers due September 30, 2027.
Local Agency Security Officers (LASOs) who answer to auditors and SaaS vendors selling into their agencies can use the policy areas below to prepare audit evidence.
Key Takeaways
- Multifactor authentication (MFA) gaps matter. Priority 1 controls carry sanctions now; the remaining tiers come due September 30, 2027.
- Two versions are in play. Version 5.9.5 is the audit baseline through March 31, 2027, while version 6.0 (updated to 6.1) is being phased in and mapped to the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 Rev5.
- Vendors sign Addenda. Contractor screening and audit requirements include fingerprint-based checks and agency-equivalent audits.
- Compliance runs continuously. Agencies review CJI activity logs on a weekly cadence and renew required security training on an annual cadence; the FBI can also conduct unannounced inspections of contractor facilities.
CJIS Compliance Protects Sensitive Criminal Justice Information Nationwide
The CJIS Security Policy is the overarching document governing every system that touches CJI, and compliance is required for any entity with access. The FBI CJIS Division administers the systems that hold CJI.
CJIS compliance is defined by the security policy in terms of who must comply and what the controls protect:
- Covered entities include criminal justice agencies and noncriminal justice agencies with CJI access, as well as private-sector vendors and cloud providers under contract.
- The scope of protected CJI includes biometric, identity history, biographic, property, and case or incident data from FBI systems.
The CJIS Advisory Policy Board (APB) sanctions process requires approval from the FBI Director and can result in termination of an agency's CJIS services. Noncompliance can also lead to tighter audit cycles or loss of access to FBI systems. Individuals who misuse CJIS face penalties ranging from administrative penalties to state and federal prosecutions.
Those consequences make the policy's control structure the starting point for compliance work.
Every Organization Subject to CJIS Must Meet These 13 Policy Areas
Version 6.0 organizes the policy into 20 areas mapped to NIST SP 800-53 Rev5, and related requirements fit into 13 operational groupings. Priority 1 controls, including MFA, have been sanctionable since October 1, 2024; the remaining tiers come due September 30, 2027.
- Information Exchange Agreements put CJI sharing in writing first.
- Access Control limits CJI to need-to-know users.
- Awareness and Training covers every CJI user.
- Audit and Accountability retains activity logs for at least one year.
- Assessment, Authorization, and Monitoring confirms controls still work.
- Configuration Management tracks changes and inventory.
- Contingency Planning covers outages of CJI systems.
- Identification and Authentication requires unique IDs and MFA.
- Incident Response documents procedures and CJIS Systems Agency (CSA) notification.
- Maintenance governs how CJI systems are serviced.
- Media Protection governs storage, transport, and destruction.
- Physical and Environmental Protection covers facilities and equipment, including mobile device controls.
- Personnel Security requires fingerprint screening before unescorted access.
The Priority 1 set concentrates on identity, access, and system integrity, adding modernized enhancements across six NIST control families: Access Control (7), Configuration Management (5), Identification and Authentication (2), Risk Assessment (1), System and Communications Protection (1), and System and Information Integrity (5). These 21 enhancements are now auditable, in addition to the existing v5.9 controls, which also remain sanctionable.
The CJIS Compliance Checklist Is Organized by Policy Area
The checklist below walks the policy areas in the order agencies typically encounter them, beginning with the written agreements that authorize CJI sharing and ending with the personnel screening that gates individual access.
The requirements interlock at the record level: the identifiers issued under access control drive the audit log, the training files document who may hold those identifiers, and the screening records establish who qualifies for the training in the first place. Reading the areas in sequence shows how a single CJI transaction is governed from authorization through deprovisioning, and each control produces dated evidence that an auditor can test against its specific policy area.
Information Exchange Agreements Define Every Authorized CJI Sharing Relationship
Written agreements establish the permitted scope of each CJI exchange.
- Execute a written security-controls agreement before exchanging CJI by email, web service, fax, or paper.
- Confirm every agreement is signed and current; outdated, unsigned, or incomplete agreements are among the most common CJIS audit findings.
Once an agreement is in force, the parties know which users and roles fall inside its scope.
Access Control Restricts CJI to the Minimum Necessary Users and Roles
Access controls define who can reach CJI and how that access is protected.
- Grant access on a least-privilege, need-to-know basis, commonly through role-based access control (RBAC).
- Lock inactive devices after 30 minutes.
- Encrypt CJI leaving the secure boundary according to CJIS cryptographic requirements using Federal Information Processing Standards (FIPS) 140-3 validated modules, with Transport Layer Security (TLS) 1.2 or higher required in transit at symmetric key strength of 128 bits or better.
Every account created under those rules belongs to a person who must understand the responsibilities attached to the credential before it is issued.
Awareness Training Is Mandatory Before Access and Renewed Regularly
Training records show that personnel understand their responsibilities before receiving access.
- Deliver pre-access security awareness training and renew it on an annual cadence under version 5.9.4 and later; earlier policy versions allowed a six-month period from assignment with a biennial refresh cadence.
- Designate a LASO and ensure the officer completes required initial and recurring training.
Trained users then generate the day-to-day activity that the audit log has to capture.
Audit Logs Must Capture Every CJI Access, Change, and Logoff Event
Audit logging creates the activity record needed to reconstruct CJI system events.
- Log authentication attempts, permission changes, privileged actions, and configuration changes with date, time, component, event type, user identity, and outcome.
- Retain logs for at least one year, review them on a weekly cadence, and protect them from modification.
The same log data feeds the periodic checks that confirm each control still works as designed.
Ongoing Assessment and Authorization Verifies Controls Remain Effective Over Time
Periodic assessment identifies gaps between formal audits and tracks their remediation.
- Run an internal self-audit at least annually between periodic audits; some v6.0 controls require independent assessment.
- Log each gap the self-audit finds in a Plan of Action and Milestones (POA\&M), the instrument agencies use to schedule remediation after an audit.
Assessment results also identify the baseline and inventory changes configuration management must control.
Configuration Management Locks Down Approved Baselines for All CJI Systems
Configuration management establishes the systems and network boundaries subject to control.
- Inventory all CJI systems that store, process, or transmit CJI.
- Segment CJI systems from general-purpose networks.
A controlled inventory supplies the system scope for contingency planning.
Contingency Planning Ensures CJI Operations Survive Disruptions and Disasters
Contingency planning assigns recovery responsibilities and protects CJI during disruptions.
- Maintain a contingency plan for each system in the CJI inventory and name the recovery roles; version 6.0 lists Contingency Planning among its policy areas.
- As a practical extension of the at-rest rule, encrypt backup copies held outside a physically secure location to the same standard.
Whether a user is signing in during normal operations or a recovery scenario, the authentication requirements stay the same.
Identification and Authentication Demands MFA for Every CJI System Entry
Identification and authentication controls tie each CJI system entry to a verified individual.
- Assign unique CJI user identifiers to every person with CJI access; shared accounts fail audit.
- Set the password minimum to 8 characters, or use a 20-character minimum under the Advanced Password Standard, which drops additional complexity rules.
- Enforce MFA at Authenticator Assurance Level 2 (AAL2) or higher. Qualifying methods include hardware tokens, authenticator apps and smart cards. Short Message Service (SMS) authentication no longer qualifies.
Verified identities make incident attribution and escalation reliable.
Incident Response Plans Must Be Documented, Tested, and Ready to Activate
Incident response documentation defines how personnel classify and escalate a breach.
- Document CSA notification procedures and breach classification criteria.
- Run tabletop exercises on at least an annual cadence and keep the records.
Tested escalation procedures also define how servicing-related events are handled.
Maintenance Procedures Prevent Unauthorized Access During System Servicing
Maintenance controls address personnel who need temporary access to CJI processing areas.
- Under the personnel-security escort exception, escort maintenance, support, and custodial staff in any area where CJI is processed.
- Require a fingerprint check for unescorted access.
Servicing frequently brings technicians within reach of the storage media that hold CJI in usable form.
Media Protection Governs CJI Storage Media
Media protection applies while CJI is stored or transported and when media is finally disposed of.
- Encrypt CJI at rest using FIPS 140-3 validated cryptographic modules, consistent with FIPS cryptography requirements, outside a physically secure location.
- Sanitize media using approved methods, such as overwriting at least 3 times or degaussing.
The same protection extends to the physical space where the media and endpoints operate.
Physical and Environmental Security Isolates Facilities While Controlling Mobile Devices
Physical and device controls restrict the environments in which CJI can be processed.
- Restrict access to server rooms and CJI processing areas via card-key access and visitor logs, with cameras monitoring the facilities.
- Mobile device management requirements include enrolling every device that touches CJI in Mobile Device Management (MDM), with remote lock, wipe, jailbreak detection, and encryption.
Doors, cameras, and MDM enrollment ultimately depend on the trustworthiness of the individuals who use them.
Personnel Security Requires Background Checks Before Unescorted CJI Access
Personnel controls connect access decisions to screening and employment status.
- Complete fingerprint-based screening before granting unescorted access to unencrypted CJI.
- Terminate separated personnel access immediately when an employee or contractor separates.
Completed screening and prompt deprovisioning close the policy-area checklist.
CJIS Audits Review Documentation, Access Logs, and Physical Controls
Each CSA follows agency audit cycle requirements at least every three years, and the FBI's CJIS Audit Unit (CAU) audits each CSA on the same triennial cycle. Noncompliance draws more frequent audits, and the FBI can inspect contractor facilities unannounced.
On-site, auditors follow audit site-review procedures. They interview staff, review data quality, tour facilities, and check vendor compliance. Auditors then assess each policy area and document any items requiring corrective action, tracking them to resolution. Audit review traces MFA from login to the CJI query and checks that documentation is current.
File your evidence package by policy area so you can answer auditors' questions control by control:
- Written policies per area, signed agreements, and Addendum acknowledgments.
- Dated security training records with content and refresh cadence.
- Fingerprint screening records for every employee and contractor with access.
- CJI system network documentation, naming each system and detailing its encryption and logging.
- Incident response plan with CSA notification steps and a logged tabletop exercise.
- Practice-audit results using the CJIS Requirements Companion.
Keeping this package current lets agencies answer control-by-control questions from existing records. When vendors handle CJI, the same evidence expectations extend through the contracting relationship.
Third-Party Vendors and Cloud Providers Have Distinct CJIS Obligations
CJIS has no certification, no central authorization body, and no accredited assessor pool; each state's CJIS Systems Officer (CSO) enforces the policy. The CJIS Security Addendum, approved by the US Attorney General, binds private contractors to agency-equivalent training criteria and audit scope and must be signed before any CJI access. A government noncriminal justice agency must also execute a Management Control Agreement (MCA) that keeps management control of the criminal justice function with the criminal justice agency.
The process runs through the contracting agency. Vendor personnel submit to fingerprint-based screening through that agency; breaches affecting government systems trigger a Supply Chain Risk Management notification; and any facility storing or processing CJI accepts the same audit scope as a local user agency.
Can an inherited cloud boundary carry that weight? A pre-authorized Federal Risk and Authorization Management Program (FedRAMP), State Risk and Authorization Management Program (StateRAMP), or System and Organization Controls (SOC) Type 2 environment can substantially reduce the CJIS scope a vendor has to demonstrate on its own, since encryption, logging, and infrastructure controls are already assessed and inherited. The contracting agency retains oversight, and CJIS-specific evidence (Addendum, screening, training) remains the vendor's responsibility, but the underlying platform work does not need to be rebuilt.
CJIS Compliance Depends on Evidence Generated Continuously
For SaaS vendors, CJIS obligations stack on top of broader federal requirements. Continuous evidence changes audit readiness from a periodic project into an operating discipline: when access changes, training renewals, log reviews, and remediation records are captured as work occurs, the audit package becomes an output of the control environment rather than a reconstruction effort. That posture is what lets a vendor answer control-by-control questions from either an agency CSO or a federal auditor without assembling records after the fact.
Knox Systems is built for FedRAMP authorization, and the same pre-authorized boundary significantly reduces CJIS compliance scope. Vendors inherit up to 80% of federal controls and cut FedRAMP timelines to approximately 90 days, building on infrastructure that currently supports FedRAMP Moderate, FedRAMP High, and Defense Information Systems Agency (DISA) Impact Level 4 (IL-4), with IL-5 authorization in process and estimated for completion in December 2026.
Book a meeting to map the authorization layer for your federal path.
FAQs About CJIS Compliance
How Should Agencies Assign Evidence Ownership Across Vendor Controls?
Map each control to an agency or vendor owner in the evidence package. The agency retains CJIS oversight, while the vendor keeps its operating evidence available throughout the contracting relationship. For shared controls, retain both the agency approval record and the vendor evidence showing how the control operates.
How Should Inherited Cloud Controls Be Documented for CJIS Review?
Treat FedRAMP, StateRAMP, and SOC Type 2 materials as supporting assurance rather than substitutes for CJIS evidence. Pair inherited-control documentation with the applicable Addendum, screening, training, encryption, logging, and access-control records required by the state CSO.
What Evidence Should Follow a Change to a CJI System?
Update the system inventory and network documentation, then retain the audit record for the configuration change. If the assessment identifies a control gap, add it to the POA\&M with its remediation schedule and evidence of reassessment.