What Is the CJIS Security Policy?

Also called: FBI CJIS Security Policy, Criminal Justice Information Services Security Policy

Related problems: A police department or court customer asks whether our service is CJIS compliant; Our cloud, phone or records system will hold criminal justice information; Not sure who decides whether a vendor meets CJIS requirements; Vendor staff need background checks before accessing an agency's data

The Criminal Justice Information Services (CJIS) Security Policy is the set of security requirements the FBI’s CJIS Division sets for anyone who accesses, stores, processes or transmits criminal justice information. That includes police departments, courts and corrections, some noncriminal justice agencies that use the data, and the vendors that serve them, such as cloud, dispatch, records management and IT service providers. For buyers, the key point is that there is no national vendor certification: each state’s CJIS Systems Agency oversees compliance, and agencies decide whether a vendor meets the policy. This entry is general information, not legal advice; confirm requirements with the agency and its CJIS Systems Agency.

At a glance

  • The policy is issued by the FBI’s CJIS Division and covers criminal justice information wherever it is handled.
  • Contractors are brought under it through a CJIS Security Addendum signed as part of their agreement with an agency.
  • Requirements include access control, multi-factor authentication, encryption, audit logging, incident response and personnel screening.
  • There is no official vendor certification; the state’s CJIS Systems Agency and the agency itself judge compliance.
  • The policy has been modernized to align more closely with NIST security controls and is updated periodically, so check the current version.

What problem it solves

Criminal history, fingerprints, warrants and case information are highly sensitive, and they flow between thousands of local, state, tribal and federal agencies. A breach can endanger investigations, victims and officers, and erode public trust.

The CJIS Security Policy sets a common minimum for protecting that information across the organizations that handle it. As agencies move records, dispatch, body-camera and phone systems to cloud and managed services, it also gives them a consistent way to hold vendors to the same standard as their own staff.

How it works

Policy and oversight. The FBI issues the policy. Each state has a CJIS Systems Agency that manages access to FBI systems in that state and audits agencies, and often their vendors.

Agreements. An agency that uses a private contractor signs an agreement incorporating the CJIS Security Addendum, and the contractor’s staff acknowledge it.

Security controls. The contractor and agency together meet requirements covering areas such as access control, identification and authentication, encryption, audit and accountability, incident response, configuration management, media protection and physical protection.

Personnel security. People with access to unencrypted criminal justice information go through screening and security awareness training set by the policy and the state.

Audits. The CJIS Systems Agency, and in some cases the FBI, audits agencies periodically, and vendor environments may be reviewed as part of that.

Roles and responsibilities

The CJIS Security Policy has no levels. Its structure is a set of roles, summarized below in general terms; state practice varies.

Role Who it is How compliance is overseen Typical evidence
FBI CJIS Division Issues the policy and operates national systems Federal audits of state programs Current policy and audit findings
CJIS Systems Agency State-level agency managing CJIS access in the state Audits agencies and sets state requirements State policies and audit reports
Criminal justice agency Police, courts, corrections and similar Audited by the CJIS Systems Agency Audit results, agreements with vendors
Noncriminal justice agency Agencies using the data for authorized purposes, such as licensing Audited under the policy and state rules Agreements and audit results
Contractor Cloud, software, dispatch, IT or other provider handling the data Signs the Security Addendum; agency and state review Signed addendum, control documentation, personnel screening records

When it matters for buyers

  • When you are a public-safety agency choosing cloud or managed services. Confirm the provider can meet the policy before data moves.
  • When you sell cloud, voice, contact center or records systems to law enforcement. Expect the addendum, controls review and staff screening.
  • When multi-factor authentication or encryption is missing. These are common gaps in audits.
  • When moving across states. Requirements and screening processes can differ by state.
  • When a provider claims “CJIS certified”. Ask what that means and which agencies have accepted it.

Our governance, risk and compliance overview covers advisors who help agencies and vendors map controls to the policy.

Questions to ask vendors

  • Will you sign the CJIS Security Addendum with our agency?
  • Which states’ CJIS Systems Agencies have reviewed or audited your service?
  • Where is criminal justice information stored, including backups, and who can access it unencrypted?
  • How do you screen and train staff who can access our data, and can you meet our state’s process?
  • How are encryption keys managed, and can your staff decrypt our data?
  • How do you implement multi-factor authentication and audit logging, and what will you provide during an audit?

How it differs from FedRAMP

FedRAMP is a federal program that assesses cloud services for use by federal agencies, and GovRAMP does similar work for state and local governments. The CJIS Security Policy is not a vendor assessment program; it is a set of requirements for anyone handling criminal justice information, enforced through agency agreements and state audits. A FedRAMP or GovRAMP status can show that a provider’s security program is mature, but it does not by itself establish CJIS compliance, which also depends on the addendum, personnel screening and agency acceptance. Specific controls, such as multi-factor authentication (MFA), often come up in a security questionnaire as part of broader data security compliance reviews.

Frequently Asked Questions

Is there an official CJIS certification for vendors?
No. The FBI does not certify vendors as CJIS compliant. Each state's CJIS Systems Agency oversees compliance in its state, and the agency you serve decides, under that oversight, whether your service and staff meet the policy. Ask providers for evidence, not a certificate.
What is criminal justice information?
Broadly, data provided by the FBI's CJIS systems and related records needed by agencies to do their work, such as criminal history, biometric, identity and case information. Whether particular data counts depends on its source and use, so confirm with the agency.
Do vendor employees need background checks?
Typically, personnel with access to unencrypted criminal justice information must pass screening set by the policy and the state, often including fingerprint-based checks. Requirements vary by state and role, so confirm with the agency and its CJIS Systems Agency.
Is CJIS only for police departments?
No. It applies to criminal justice agencies such as police, courts and corrections, to some noncriminal justice agencies that access the data, and to contractors that handle it for them, such as cloud, records, dispatch and IT service providers.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.