CJIS compliance means meeting the FBI's security standards for any system that stores, processes, or transmits criminal justice information, covering encryption, access control, authentication, auditing, and physical security.
This guide covers exactly what you need:
CJIS compliance is adherence to the FBI's Criminal Justice Information Services Security Policy a framework governing how criminal justice information (CJI) must be protected throughout its lifecycle.
CJI includes criminal history records, arrest records, biometric data, surveillance footage, and investigative case files. Any facility that stores, transmits, or provides access to criminal justice data falls within scope.
CJIS stands for Criminal Justice Information Services, a division of the FBI, headquartered in Clarksburg, West Virginia, which manages the policy on behalf of the Bureau and its intelligence community partners.
The CJIS Division also operates the national systems agencies depend on daily, including NCIC and the national fingerprint databases.
Non-compliance carries real operational consequences. Failing an audit can result in losing access to FBI systems such as NCIC, along with potential fines and other sanctions.
For software vendors, the stakes are commercial. An agency cannot deploy a tool that would put its own CJIS standing at risk, which means compliance capability is effectively a prerequisite for selling into the law enforcement market at all.
CJIS obligations extend to every entity that touches criminal justice information, municipal and county law enforcement, sheriff's offices, courts, corrections, prosecutors, dispatch centres, and civilian staff.
Private companies are included. Contractors performing criminal justice functions or data processing for an agency must operate under an agreement incorporating the Policy, sign the CJIS Security Addendum, and submit staff with access to unencrypted CJI to fingerprint-based background checks.
Beginning with version 6.0, the CJIS Security Policy is structured around the security control families defined in NIST SP 800-53 Revision 5, rather than the 13 policy areas used in version 5.x.
This was a substantial restructuring. Version 6.0, released December 27, 2024, was the largest policy update in over a decade, expanding the framework to more than 180 primary controls and 1,300 subcontrols.
Core CJIS data security requirements include:
A practical CJIS compliance checklist for agencies and vendors:
Vulnerability management sets a demanding pace. Under RA-5, systems must be scanned at least monthly, with critical findings remediated in 15 days, high in 30, medium in 60, and low in 90.
Cryptographic requirements also carry a near-term deadline — agencies and vendors need compliant cryptography in place before the September 21, 2026 cutoff.
Important clarification: the FBI does not certify products as CJIS compliant. Compliance is established through agreements and attestations between the vendor, the agency, and the state's CJIS authority, not a certificate issued by the Bureau.
When evaluating CJIS compliant software, look for FIPS-validated encryption, native MFA support, granular audit logging, role-based access controls, documented breach notification procedures, and a vendor willing to sign the CJIS Security Addendum.
Cloud deployment is permitted, but responsibility is shared. The provider secures the underlying infrastructure while the agency remains accountable for configuration, access management, and data handling.
Version 6.0 formalised evaluation of cloud services and third-party tools for CJIS compliance before deployment, making procurement-stage due diligence a documented requirement rather than an informal step.
Microsoft supports CJIS through agreements with state CJIS authorities. A Microsoft attestation is included in agreements between Microsoft and a state's CJIS authority, and between Microsoft and its customers, reflecting that no vendor holds a blanket FBI certification.
AWS follows a comparable model, offering CJIS-aligned regions and signing agreements with individual states. In both cases, using a compliant cloud platform does not make an agency compliant automatically, configuration and access controls remain the customer's responsibility.
Mobile access carries additional requirements. Every mobile device authorized to connect to CJI must be registered in an MDM solution supporting full-device encryption, remote wipe, and controls over installed applications.
Secure access from mobile endpoints requires device-level authentication in addition to user-level MFA. BYOD is permitted only when all required controls can be fully enforced on the personal device.
Communication tools handling CJI face the same standards as any other in-scope system. A CJIS compliant messaging app needs end-to-end or FIPS-validated encryption, MFA at login, comprehensive audit logging of message access, administrative controls over user permissions, and retention capabilities that support audit requirements.
Consumer messaging apps do not meet these criteria. Agencies evaluating CJIS compliant communication tools should also consider deployment model, on-premise or dedicated hosting gives agencies direct control over where CJI resides, which simplifies several control requirements compared with shared cloud environments.
Troop Messenger is one example of a platform built with this kind of flexibility, offering on-premise deployment alongside end-to-end encryption, role-based access controls, audit logging, and MFA at login. These map directly to the control categories auditors review, including the MFA gap that remains the most common audit failure.
As noted earlier, no product carries CJIS compliance on its own, that status comes from the Security Addendum and agreement with a state CJIS authority. What these features provide is the configuration groundwork an agency's IT team needs to support its own compliance posture.
For related context, see our guides on AI in law enforcement, secure messaging for government and defence, and data sovereignty.
Most law enforcement agencies are audited at least once every three years, with ongoing compliance expected between audits.
Auditors examine access logs, authentication configurations, encryption implementation, physical security at CJI locations, personnel background check records, and training completion. The most common failure point is an overlooked legacy application lacking MFA coverage, rarely email or VPN, which agencies typically address first.
Security awareness training is required for everyone with CJI access, including civilian staff, IT administrators, and contractors. Training covers proper CJI handling, incident recognition and reporting, password and authentication practices, and physical security responsibilities.
Training must be repeated on a recurring basis and documented, since completion records are reviewed during audits.
Vendors must sign the CJIS Security Addendum, ensure staff with CJI access complete fingerprint-based background checks, and notify agencies of any security incident or breach affecting government systems.
For vendors already holding NIST 800-171, CMMC, or FedRAMP compliance, the path to CJIS is significantly shorter, since control overlap allows meaningful reuse of existing work.
CJIS | HIPAA | |
Governs | Criminal justice information | Protected health information |
Authority | FBI CJIS Division | US Dept of Health & Human Services |
Structure | NIST SP 800-53 control families | Security, Privacy, and Breach Rules |
Breach reporting | Within one hour to FBI | Within 60 days |
Certification | No FBI certification exists | No federal certification exists |
Background checks | Fingerprint-based, mandatory | Not required |
The one-hour breach notification window is the sharpest practical difference, substantially tighter than almost any comparable framework.
CJIS is a US framework , but most regions with organised policing have a comparable standard governing how criminal justice data must be handled. Software vendors selling internationally typically need to satisfy more than one of these.
The EU Law Enforcement Directive (Directive 2016/680) governs how police and criminal justice authorities across EU member states process personal data, covering lawful processing, data subject rights, and strict conditions on transferring criminal justice data outside the EU. It sits alongside GDPR as part of the same 2018 EU data protection reform, but applies specifically to law enforcement processing rather than general commercial data.
The UK transposed the LED into domestic law through Part 3 of the Data Protection Act 2018, which applies the same core principles to policing and criminal justice processing carried out by UK authorities following Brexit.
In Australia, the Information Security Manual, maintained by the Australian Signals Directorate, sets the security control baseline for government and law enforcement systems, often paired with the Essential Eight mitigation strategies.
Vendors serving multiple regions commonly hold ISO 27001, SOC 2, or FedRAMP alongside CJIS, since control overlap across these frameworks, much like the NIST 800-171 and CMMC overlap mentioned earlier, significantly shortens the path to meeting each individual requirement.
The current standard is CJIS Security Policy version 6.1, dated June 25, 2026 — a 473-page document incorporating calendar year 2025 Advisory Policy Board and Compact Council changes. Version 6.1 is a corrections and omissions cleanup of version 6.0 rather than another wholesale redesign.
Key timeline points:
Of 178 controls, only 22 are Priority 1. The FBI has also moved to a faster release cadence, with updates now expected every 6 to 12 months rather than multi-year cycles.
Agencies that build continuous compliance programs adapt far more easily than those treating each policy version as a one-time project.
CJIS compliance has shifted from a periodic checklist exercise into an ongoing operational discipline, driven by a modernised policy structure and a faster update cadence.
Quick summary:
The agencies handling this well have stopped treating compliance as a project with an end date and started treating it as a standing operational requirement.
CJIS compliance means meeting the FBI Criminal Justice Information Services Security Policy, which sets security standards for any system storing, processing, or transmitting criminal justice information. Covered data includes criminal history records, arrest records, biometric data, surveillance footage, and investigative case files. Requirements span encryption, multi-factor authentication, access control, physical security, personnel background checks, and audit logging. The policy applies to law enforcement agencies, courts, dispatch centres, corrections, and any private vendor or contractor with access to criminal justice information.
The current standard is CJIS Security Policy version 6.1, dated June 25, 2026, a 473-page document incorporating changes approved during 2025 by the CJIS Advisory Policy Board and Compact Council. It follows version 6.0 of December 27, 2024, which completed a major modernisation restructuring the policy around NIST SP 800-53 Revision 5 control families rather than the 13 policy areas used previously. The FBI has moved to a faster update cadence, with new versions now expected every 6 to 12 months.
Yes. Multi-factor authentication has been a mandatory, auditable, and sanctionable control since October 1, 2024, applying to both privileged and non-privileged accounts. Compliant MFA must combine at least two of three factor types, something you know, something you have, and something you are. The requirement covers every access path to criminal justice information, including Windows logins, VPNs, remote desktop, and field applications. Mobile CJI access additionally requires device-level authentication alongside user-level MFA.
Yes, if they access criminal justice information. Private contractors performing criminal justice functions or data processing for an agency must operate under an agreement incorporating the CJIS Security Policy, sign the CJIS Security Addendum, and submit staff with access to unencrypted CJI to fingerprint-based background checks. Vendors must also notify agencies of security incidents affecting government systems. Companies already holding NIST 800-171, CMMC, or FedRAMP compliance generally find the path to CJIS significantly shorter due to control overlap.
Most law enforcement agencies are audited at least once every three years, with continuous compliance expected between audits. Auditors review access logs, authentication configurations, encryption implementation, physical security controls, background check records, and training documentation. Failing an audit can result in losing access to FBI systems including NCIC, alongside potential fines and sanctions. The most frequent failure point is a legacy application without MFA coverage, since agencies typically address email and VPN access first while older internal systems get overlooked.
