CJIS Compliance Levels: Training, Agreements & Policy Areas
The FBI Criminal Justice Information Services (CJIS) FBI CJIS Security Policy imposes obligations across three distinct layers, not a single set of "levels." Four security awareness training levels sort personnel by the extent of their access to criminal justice data, from a maintenance worker with building access to a systems administrator. Two organizational categories, criminal justice agencies and noncriminal justice agencies, determine which formal agreements bind an entity to the policy. A set of 13 policy areas defines the technical controls every covered system must implement.
Any vendor, contractor, or government office that touches criminal justice information inherits obligations at all three layers, which is why "CJIS compliant" means little until you know which layer someone is talking about.
Key Takeaways
- Layer one, personnel: Four cumulative training tiers sort staff by access, from Level 1 (unescorted access to secure locations) to Level 4 (IT administrators). All levels now refresh annually.
- Layer two, entities: Agency type sets the agreement. Criminal justice agencies are bound directly; noncriminal justice agencies through Management Control Agreements or the CJIS Security Addendum.
- Layer three, controls: Thirteen policy areas remain the audit floor. Version 5.9.5 is the FBI audit baseline through March 31, 2027, though state CSAs set their own version-adoption timelines. CJIS Security Policy v6.0 restructures them into 20 control families aligned with the National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53.
- Audits stay decentralized: No central certification exists. Compliance is validated through state-level audits by each CJIS Systems Agency (CSA) and executed agreements, agency by agency.
CJIS Governs Access to Sensitive Criminal Justice Data
The FBI's Criminal Justice Information Services (CJIS) Division is the central clearinghouse for law enforcement data in the United States. It collects, warehouses, and disseminates criminal justice data to qualified law enforcement, criminal justice, civilian, academic, employment, and licensing agencies, and it administers the National Crime Information Center (NCIC), the Interstate Identification Index, and the National Instant Criminal Background Check System, among other systems.
The CJIS Security Policy governs how that data is handled. Criminal Justice Information (CJI) is the umbrella term: the v6.0 CJI definition describes it as "all of the FBI CJIS provided data necessary for law enforcement and civil agencies to perform their missions including, but not limited to biometric, identity history, biographic, property, and case/incident history data."
Criminal History Record Information (CHRI) is a more sensitive subset that covers arrests, charges, and dispositions, and it carries additional access controls governing dissemination. NCIC Restricted Files, which include CHRI alongside gang files, known or appropriately suspected terrorist files, and the National Sex Offender Registry, receive similar heightened handling.
The policy binds law enforcement and every other entity that accesses, or operates systems that process, store, or transmit CJI. The current release is v6.1 (June 25, 2026); the FBI conducts CJIS audits against v5.9.5 through March 31, 2027. Individual state CJIS Systems Agencies set their own adoption timelines for newer versions, so covered organizations should confirm which version their CSA is auditing against. Every individual who touches those systems inherits obligations under the policy, starting with role-based training.
Four Training Levels Define Personnel Obligations
Policy Area 2 of the CJIS Security Policy assigns security awareness training by role, and the four levels are cumulative: each tier includes everything below it.
1. Basic Security Awareness Training
Applies to anyone meeting Level 1 access requirements: unescorted access to a physically secure location, including maintenance and cleaning staff who never handle CJI. It covers:
- individual responsibilities around CJI and terminals,
- the implications of noncompliance,
- incident-response points of contact,
- visitor control procedures.
2. Security Awareness Training
Applies to authorized personnel meeting Level 2 access requirements: physical access to CJI, such as staff who handle printed records or can open locked files containing CJI. It adds:
- media protection,
- proper handling and marking of CJI,
- threats and vulnerabilities associated with handling it,
- social engineering,
- dissemination and destruction procedures.
3. Additional Security Training
Applies to personnel with both physical and logical access to CJI; dispatchers and records clerks with terminal access are typical examples. It adds:
- password usage and management,
- protection from malicious code,
- proper email usage,
- mobile and laptop security,
- encryption of sensitive transmissions,
- least-privilege access control.
4. Advanced Security Training
Applies to IT personnel: system, security, and network administrators. It adds:
- malware scanning and definition updates,
- data backup and storage,
- timely patching under configuration management,
- access control measures,
- network infrastructure protection.
All four levels run on the same clock. Training is due shortly after initial assignment; the refresh cadence, biennial under older 5.x releases, moved to annual with v5.9.4, and v6.0 carries the annual, role-based approach forward. Individual training records must be documented and kept current, so the compliance artifact is the roster, one whose reach is defined by the agreements the agency has executed.
Agency Type Determines CJIS Agreements
The policy sorts covered organizations into two categories, and the agreement that binds an entity to CJIS depends on which category it falls into. Before CJI changes hands, formal information exchange agreements must specify security controls, and the instrument varies by entity type.
Criminal Justice Agencies
A Criminal Justice Agency (CJA) is a court, governmental agency, or subunit that administers criminal justice under statute or executive order and allocates a substantial part of its annual budget to that function. CJAs answer to the policy directly. Examples include courts, law enforcement at all levels, prosecutors' offices, public defenders' offices, probation and parole offices, correctional facilities, and state and federal Inspectors General's offices.
Government Noncriminal Justice Agencies
A government NCJA performs criminal justice functions for a CJA, such as a city IT department running a police department's servers. It signs a Management Control Agreement stipulating that control of the criminal justice function stays with the CJA. Government NCJA examples include city and central state IT organizations, 911 communications centers dispatching for a CJA, and county school boards using CHRI for hiring decisions.
Private Noncriminal Justice Agencies
Private contractors and cloud vendors sign the CJIS Security Addendum, an FBI-approved contract addendum obligating them to the same security program as the agencies they serve. Examples include cloud and SaaS vendors, IT managed service providers, contractors performing criminal justice functions, and banks accessing CHRI for hiring.
For a software vendor, the practical consequence is that the Security Addendum imports the full policy into the contract, including personnel screening, the training levels above, and the technical controls that define the compliance floor.
Thirteen Policy Areas Define the Technical Compliance Floor
Under the v5.x structure still in force for audits, sections 5.1 through 5.13 define 13 policy areas.
- Information Exchange Agreements. Formal agreements must precede any CJI exchange, whether by email, fax, hard copy, or system-to-system transfer, and must define roles and security safeguards.
- Security Awareness Training. The four role-based levels covered above, with documented completion records.
- Incident Response. Documented detection, reporting, mitigation, and recovery procedures; major incidents must be reported promptly, upon discovery, to the CSA and the FBI CJIS Division Information Security Officer (ISO).
- Auditing and Accountability. Centralized logging of authentication attempts, permission changes, and privileged account actions, with at least one year of log retention and weekly review of audit records.
- Access Control. Least-privilege access with per-account session limits, automatic inactivity lockouts, and rapid identification and disabling of high-risk accounts.
- Identification and Authentication. A unique identity for each user and multi-factor authentication (MFA) at Authenticator Assurance Level 2 for anyone accessing CJI.
- Configuration Management. Documented baseline configurations and change control protecting systems from unauthorized modification.
- Media Protection. Secure storage, transport, and destruction of physical and digital media containing CJI.
- Physical Protection. Controlled physical access points, maintained lists of authorized personnel, and verified access authorizations.
- Systems and Communications Protection and Information Integrity. Data integrity and controlled information movement between networks, plus encryption of CJI in transit and at rest using Federal Information Processing Standard (FIPS) 140-3-validated cryptography.
- Formal Audits. The FBI CJIS Audit Unit audits each state CSA on a recurring cycle, and CSAs audit the agencies and contractors in their jurisdictions.
- Personnel Security. Personnel security requirements include fingerprint-based background checks and screening, access controls during transfers and terminations, and formal sanctions for violations.
- Mobile Devices. Usage restrictions, Mobile Device Management (MDM) software, and secured wireless technologies. Per the FBI's mobile device control applicability, device category (laptop, tablet, smartphone) and connection method (cellular versus Wi-Fi only) determine which controls a device can actually satisfy.
The catalog behind these areas is NIST SP 800-53 Rev5 (September 2020): the CJIS Security Policy is aligned with it, and v6.0 (December 2024) restructured the 13 areas into 20 control families aligned to that catalog at the moderate baseline, with full enforcement of the remaining priority tiers due by September 30, 2027. The restructuring redistributed legacy requirements across the new control families.
Three CJIS Gaps Drive Audit Exposure
Personnel training, agency agreements, and 13 policy areas set the standard, but where do most audits actually fail? Three recurring gaps account for much of the audit exposure in CJIS compliance, and each traces back to how covered organizations manage the day-to-day mechanics of the policy.
- Scope mapping for cloud and decentralized access. Cloud-hosted systems and distributed access paths can extend the CJI boundary beyond production into backup, analytics, support, email, and ticket queues. Because each state CSA interprets the policy independently, an arrangement accepted in one state may not clear another.
- Audit readiness in documentation, logs, and access controls. Default retention on many platforms falls short of the one-year log floor, and MFA must cover identity from initial login through the CJI query rather than stopping at the VPN. Security Addendum documentation must also extend to every subcontractor in the chain.
- Continuous monitoring after initial compliance. CJIS requires weekly audit-record reviews, with more frequent monitoring when risk indicators appear, and v6.0 formalizes ongoing control assessment after authorization. Staff turnover keeps the training obligation perpetually open, since every new hire needs prompt initial training and an annual refresh.
Every vendor, contractor, and government office that touches CJI inherits the full stack of personnel, agreement, and control obligations. CJIS has no central certification body, so the burden of continuous proof falls on each entity individually. But what if the compliance burden could be reduced? That math shifts when a covered organization can inherit controls from an already-authorized platform rather than stand them up from scratch.
Cloud Vendors Need a Dual CJIS and FedRAMP Program
Cloud vendors serving criminal justice agencies need to pursue both CJIS and FedRAMP. Federal customers require FedRAMP authorization to buy the service, while state and local law enforcement customers require CJIS Security Addendum coverage to share CJI with it.
Both programs draw from the same NIST SP 800-53 catalog, so a single control map, evidence stream, and continuous monitoring program can satisfy both audit regimes if designed that way from the start. Unresolved scope on either side blocks access to NCIC and state criminal databases, exposes gaps in subcontractor coverage, and forces remediation mid-audit.
Knox Systems offers a pre-authorized government cloud platform that reduces the FedRAMP compliance burden by 90% in 90 days, combining automated control mapping, continuous monitoring, remediation, and compliance documentation to shorten the path to authorization and significantly reduce the CJIS compliance scope. The platform currently supports FedRAMP Moderate and High, and Defense Information Systems Agency (DISA) Impact Level 4 (IL-4), with IL-5 authorization in process and an estimated completion date of December 2026.
To define the compliance boundary and execution plan, book a meeting.
FAQs about CJIS Compliance
Can Cloud Vendors Use Datacenters Outside Approved Locations?
Under v6.1, cloud vendors may store CJI only in datacenters within the United States, US territories, Indian Tribes, and Canada. CJI outside physically secure locations must use FIPS 140-3 validated encryption, with the agency retaining control of the encryption keys.
What Audit Evidence Should a CJIS Vendor Maintain?
A vendor should maintain executed agreements, current training rosters, personnel screening records, evidence of access controls, one year of audit logs, and weekly review records. The evidence set should also include incident-response documentation and coverage for relevant subcontractors.
When Must a CHRI Contractor Receive Its First CJIS Audit?
A contractor receiving CHRI under an outsourcing agreement must be audited within one year of first receipt. The contractor must then remain prepared for recurring or unannounced security inspections.