The Criminal Justice Information Services (CJIS) Security Policy is the set of security requirements the FBI’s CJIS Division sets for anyone who accesses, stores, processes or transmits criminal justice information. That includes police departments, courts and corrections, some noncriminal justice agencies that use the data, and the vendors that serve them, such as cloud, dispatch, records management and IT service providers. For buyers, the key point is that there is no national vendor certification: each state’s CJIS Systems Agency oversees compliance, and agencies decide whether a vendor meets the policy. This entry is general information, not legal advice; confirm requirements with the agency and its CJIS Systems Agency.
At a glance
- The policy is issued by the FBI’s CJIS Division and covers criminal justice information wherever it is handled.
- Contractors are brought under it through a CJIS Security Addendum signed as part of their agreement with an agency.
- Requirements include access control, multi-factor authentication, encryption, audit logging, incident response and personnel screening.
- There is no official vendor certification; the state’s CJIS Systems Agency and the agency itself judge compliance.
- The policy has been modernized to align more closely with NIST security controls and is updated periodically, so check the current version.
What problem it solves
Criminal history, fingerprints, warrants and case information are highly sensitive, and they flow between thousands of local, state, tribal and federal agencies. A breach can endanger investigations, victims and officers, and erode public trust.
The CJIS Security Policy sets a common minimum for protecting that information across the organizations that handle it. As agencies move records, dispatch, body-camera and phone systems to cloud and managed services, it also gives them a consistent way to hold vendors to the same standard as their own staff.
How it works
Policy and oversight. The FBI issues the policy. Each state has a CJIS Systems Agency that manages access to FBI systems in that state and audits agencies, and often their vendors.
Agreements. An agency that uses a private contractor signs an agreement incorporating the CJIS Security Addendum, and the contractor’s staff acknowledge it.
Security controls. The contractor and agency together meet requirements covering areas such as access control, identification and authentication, encryption, audit and accountability, incident response, configuration management, media protection and physical protection.
Personnel security. People with access to unencrypted criminal justice information go through screening and security awareness training set by the policy and the state.
Audits. The CJIS Systems Agency, and in some cases the FBI, audits agencies periodically, and vendor environments may be reviewed as part of that.
Roles and responsibilities
The CJIS Security Policy has no levels. Its structure is a set of roles, summarized below in general terms; state practice varies.
| Role | Who it is | How compliance is overseen | Typical evidence |
|---|---|---|---|
| FBI CJIS Division | Issues the policy and operates national systems | Federal audits of state programs | Current policy and audit findings |
| CJIS Systems Agency | State-level agency managing CJIS access in the state | Audits agencies and sets state requirements | State policies and audit reports |
| Criminal justice agency | Police, courts, corrections and similar | Audited by the CJIS Systems Agency | Audit results, agreements with vendors |
| Noncriminal justice agency | Agencies using the data for authorized purposes, such as licensing | Audited under the policy and state rules | Agreements and audit results |
| Contractor | Cloud, software, dispatch, IT or other provider handling the data | Signs the Security Addendum; agency and state review | Signed addendum, control documentation, personnel screening records |
When it matters for buyers
- When you are a public-safety agency choosing cloud or managed services. Confirm the provider can meet the policy before data moves.
- When you sell cloud, voice, contact center or records systems to law enforcement. Expect the addendum, controls review and staff screening.
- When multi-factor authentication or encryption is missing. These are common gaps in audits.
- When moving across states. Requirements and screening processes can differ by state.
- When a provider claims “CJIS certified”. Ask what that means and which agencies have accepted it.
Our governance, risk and compliance overview covers advisors who help agencies and vendors map controls to the policy.
Questions to ask vendors
- Will you sign the CJIS Security Addendum with our agency?
- Which states’ CJIS Systems Agencies have reviewed or audited your service?
- Where is criminal justice information stored, including backups, and who can access it unencrypted?
- How do you screen and train staff who can access our data, and can you meet our state’s process?
- How are encryption keys managed, and can your staff decrypt our data?
- How do you implement multi-factor authentication and audit logging, and what will you provide during an audit?
How it differs from FedRAMP
FedRAMP is a federal program that assesses cloud services for use by federal agencies, and GovRAMP does similar work for state and local governments. The CJIS Security Policy is not a vendor assessment program; it is a set of requirements for anyone handling criminal justice information, enforced through agency agreements and state audits. A FedRAMP or GovRAMP status can show that a provider’s security program is mature, but it does not by itself establish CJIS compliance, which also depends on the addendum, personnel screening and agency acceptance. Specific controls, such as multi-factor authentication (MFA), often come up in a security questionnaire as part of broader data security compliance reviews.
