Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

CJIS Compliance Checklist for IT Vendors: What You’re On the Hook For

August 11, 2026
hero-cjis-compliance-checklist-it-vendors-1.png

This CJIS compliance checklist covers what an IT vendor or MSP needs under a signed or pending CJIS Security Addendum. Contractors count too, along with anyone else with signed CJI access. It skips the background reading and goes straight to the controls auditors actually check.

The stakes are simple. Miss these requirements and an agency can cut off your access to Criminal Justice Information. No CJI access means no contract.

Seven checklist items make up the full picture, all pulled straight from the FBI’s own policy text:

  • Personnel screening (fingerprint-based background checks)
  • The CJIS Security Addendum itself
  • Encryption in transit
  • Advanced Authentication (MFA)
  • Security awareness training
  • Incident response
  • Audit readiness

This piece covers the first four in detail: personnel screening, the Addendum, encryption, and MFA. Each section states the requirement, then what it actually means for the day-to-day work of running IT for a CJI-handling client.

Who This Checklist Is For (and What’s at Stake)

This checklist is for IT vendors, managed service providers, and contractors with a signed or pending CJIS Security Addendum. That covers any private company doing technical work for a police department, court, or corrections agency. It also covers any government agency that touches Criminal Justice Information, called CJI.

CJIS Suspension Risk Chain

The CJIS Security Policy is the FBI’s rulebook for anyone who touches CJI. It sets the minimum security bar for law enforcement and noncriminal justice agencies. Private contractors working under those agencies must meet the same bar.

That reaches further than most vendors assume. Entities covered include:

  • State and local law enforcement
  • Courts and corrections agencies
  • Noncriminal justice agencies with CJI access, like a city IT department running a jail management or CAD system
  • Any private contractor performing criminal justice functions for one of the above

Losing that status is not hypothetical. The FBI runs a triennial compliance audit on every CJIS Systems Agency. Unresolved findings can mean suspension. A suspended agency can lose access to FBI CJIS systems. That includes NCIC and CHRI queries, the tools police actually use to do their jobs.

For an MSP, that risk sits one layer down. If your work is the reason a client fails its audit, you are the vendor that gets replaced.

1. Personnel Screening: Fingerprint-Based Background Checks

Background Check Outcomes

Before any tech, yours or a subcontractor’s, gets unescorted access to unencrypted CJI, that person needs a background check. The fingerprint-based background check requirement applies before access starts, not after the fact.

Identity verification plus a state-of-residency and national fingerprint-based background check must clear before anyone gets unescorted access to unencrypted CJI.

The specific requirements:

  • Identity verification, plus a state-of-residency and national fingerprint-based background check, before access is granted
  • A felony conviction requires the agency to deny access, with a narrow, CSO-reviewed exception
  • A misdemeanor is a case-by-case call for the CJIS Systems Officer (CSO) or their designee
  • Background re-investigation is recommended every five years, unless the agency uses Rap Back continuous monitoring

This is why field techs, cablers, and remote admins get fingerprinted. A badge check alone is not enough if they can see unencrypted CJI.

A standard HR background check does not satisfy this. Most commercial pre-employment screens check county or state records, not a national fingerprint-based check run through the proper channel. If your onboarding process was built for a normal client, it almost certainly does not clear this bar for a CJIS client.

Plan for this before you bid. Fingerprinting and adjudication take time. An agency will not grant access until it clears.

There is also a scope question worth settling early: who actually needs to be screened. It is not just the technician doing the hands-on work. Anyone who could see unencrypted CJI counts, including a remote support engineer who might screen-share into a system during a ticket, or an on-call admin with standing access outside business hours.

The CJIS Security Addendum is the document that actually authorizes your access to Criminal Justice Information. It is a uniform agreement approved by the U.S. Attorney General. Every Criminal Justice Agency signs one with each contractor it uses.

The Addendum limits how you can use Criminal History Record Information, or CHRI. It also holds you to the same training, certification, and audit standards as the agency itself. The document spans several areas: personnel, physical sites, systems, data, and technical controls.

One detail catches a lot of vendors off guard: a subcontractor needs its own signed Addendum coverage. The prime contractor’s Addendum does not cover a subcontractor automatically. Your subcontractor performing criminal justice functions must be covered by its own Addendum too. Skip this and the subcontractor is operating without authorization, even if you are fully covered.

This matters most for MSPs that lean on outside specialists, a cabling crew, a cloud migration partner, an after-hours help desk. If any of them can touch unencrypted CJI or the systems that hold it, that arrangement needs its own Addendum coverage before the work starts, not after.

Practically, this means tracking Addendum coverage the same way you’d track an insurance certificate. Know who has signed, who has not, and don’t hand off CJI-adjacent work to anyone who hasn’t.

3. Encryption in Transit: FIPS-Certified, 128-Bit Minimum

Any CJI crossing a public network or the internet needs FIPS-certified encryption, 128-bit minimum. That means FIPS 140-2, or FIPS 140-3 during the transition period, with at least 128-bit symmetric strength.

The bar is lower than most vendors expect for what counts as “in transit.” Even a networked fax machine or copier sending a report to another agency counts. If it crosses a network, it needs to be encrypted to this standard.

There is one exception. A closed, traditional phone line, not networked, does not require encryption.

CJI Transmission PathEncryption Required
Internet or public network (email, web apps, networked fax/copier)Yes: FIPS 140-2/140-3 certified, 128-bit minimum
Closed, traditional (non-networked) phone lineNo

For an MSP, that usually means a VPN, TLS, or an equivalent FIPS-validated channel. A password alone does not meet this bar, and neither does a generic “encrypted” claim from a vendor that hasn’t confirmed FIPS validation specifically.

This is worth auditing early in any CJIS engagement. Walk every path CJI takes: email between staff, file transfers to other agencies, backups, remote access sessions, even that old networked copier in the records room. Any hop that isn’t FIPS-certified is a finding waiting to happen.

4. Advanced Authentication (MFA) on Every CJI-Reaching Account

Advanced Authentication means anything beyond a single username and password, a real second factor. It is required for every authorized user accessing CJI, including from a phone or tablet. The only exception is indirect access, where a person never touches CJI directly.

Accounts That Need MFA

Since October 1, 2024, MFA sits in the sanctioned, audited baseline, not just a recommendation. That shift matters: it is one of the specific controls an auditor now checks, not a best practice you can defer.

In practice, “every account that can reach CJI” is broader than the obvious login screen. It typically includes:

  • Desktop and laptop logins for staff with CJI access
  • Remote access tools: VPN, RDP, remote support software
  • Mobile devices that can reach CJI
  • Any admin or service account with a path to CJI

MFA is one of the simplest boxes to check technically. It is also one of the most commonly skipped, usually on legacy systems that predate the requirement. Older records management or CAD systems built years before this rule often still run on shared logins with no second factor. Those are exactly the accounts an auditor will ask about first.

5. Security Awareness Training: Within 6 Months, Then Every Two Years

Everyone with CJI access needs security awareness training. That includes contractor and vendor staff, not just agency employees. The timing is fixed:

  • Complete within six months of initial assignment
  • Repeat every two years after that (biennial)
  • Cover the specific topics the Policy specifies as baseline content

One workaround exists: a CSO or SIB can accept training-completion documentation from another agency. But the accepting agency then owns the risk if that training didn’t fully meet the requirement. That’s a real liability, so verify the content before relying on someone else’s certificate.

For an MSP, training tracking is straightforward to build once, easy to forget after. Set a calendar trigger tied to each tech’s assignment date, not a single annual date for the whole team. Miss the window and that person’s access should be paused until they catch up.

6. Incident Response: The Escalation Chain

CJIS requires a documented incident response capability, not just a plan on paper. That means preparation, detection, analysis, containment, and recovery, all documented and actually followed. Every incident has a required reporting path:

  1. Local agency identifies and documents the incident
  2. Local agency reports up to the state’s CSA Information Security Officer (ISO)
  3. The CSA ISO escalates to the FBI CJIS ISO
  4. The FBI CJIS ISO can loop in the FBI’s Computer Security Incident Response Capability (CSIRC), and in serious cases, the DOJ’s own incident response team

For an MSP, this means your response plan can’t stop at “we contained it.” You need a documented handoff to the agency’s own reporting chain, with clear ownership of who notifies whom.

If your team detects something first, on a managed endpoint or a monitored network, say so immediately. The agency still owns reporting it up their own chain. Build that handoff into your incident response plan now, not during an actual incident.

7. Audit Readiness: What a Triennial Audit Actually Checks

The FBI’s CJIS Division Audit Unit runs a triennial audit of every CJIS Systems Agency (CSA). That’s typically the state police or state identification bureau.

What Auditors Ask

Each CSA then audits the agencies under it on the same three-year cycle. That includes private contractors covered by a Security Addendum.

As of this writing, the FBI conducts audits against Policy version 5.9.5.

An audit checks whether the controls in this checklist actually work, not just whether they’re written down. Expect an auditor to ask for:

  • Proof of fingerprint-based background checks for staff with unescorted CJI access
  • Signed CJIS Security Addendum coverage for every contractor and subcontractor
  • Evidence encryption in transit meets the FIPS 140-2/140-3 standard
  • Confirmation Advanced Authentication is active on every account that reaches CJI
  • Training completion records within the six-month and biennial windows
  • A documented, followed incident response plan with the correct escalation chain

A finding triggers a formal sanctions process. Unresolved findings can lead to suspension of the agency’s access to FBI CJIS systems, including NCIC and CHRI queries. For a vendor, a finding traced to your systems is the fastest way to lose the contract.

Who Owns What: MSP vs. Agency

Not every CJIS control belongs to the IT vendor. Some sit with the vendor, some sit with the agency, and getting that split wrong is its own risk.

A competent MSP typically operates the technical controls an audit checks directly. The agency, or the vendor’s own leadership, owns the procedural and legal pieces: who gets Addendum coverage, who gets fingerprinted, who signs off on access.

RequirementTypically MSP-OperatedAgency / Vendor Leadership Owns
Encryption in transitImplements and maintains FIPS-validated channelsConfirms CJI never crosses an unencrypted path
Advanced Authentication (MFA)Configures and enforces MFA on every accountDecides who gets an account in the first place
Access logging and audit trailSets up and retains logsReviews logs, responds to audit requests
Patch and configuration managementApplies patches, hardens systemsApproves major configuration changes
Incident response (technical)Detects, contains, documents incidentsOwns the escalation chain and required reporting
Personnel screeningTracks who has active CJI accessCSO approves or denies fingerprint-based clearance
CJIS Security AddendumCannot self-authorize accessSigns and maintains Addendum coverage
Security awareness trainingCan deliver and track completionEnsures completion, owns training documentation

This is roughly how LeadingIT splits the work for CJIS-touching clients. LeadingIT operates the FIPS-140-validated encryption, MFA, logging, patching, and incident response the Policy audits. LeadingIT also helps track fingerprint screening status and keep training current. The agency’s CJIS Systems Officer stays the final authority. No MSP holds a “CJIS certification,” because none exists.

See Where You Stand

Not sure where your vendor or agency stands against this checklist? Take the free 2-minute CJIS Risk-Check. Answer a few plain-English questions about your CJIS readiness and see your risk level and gaps, no sign-up required.

Take the free 2-minute CJIS Risk-Check

Frequently Asked Questions

A finding triggers a formal sanctions process against the agency, and by extension the vendor whose systems caused it. Unresolved findings can lead to suspension of the agency’s access to FBI CJIS systems, including NCIC and CHRI queries. For a police department, that means losing the ability to run the record checks its officers rely on daily. For the vendor, it usually means losing the contract.

Yes. The prime contractor’s Addendum does not automatically cover a subcontractor. Any subcontractor performing criminal justice functions or touching CJI needs its own signed Addendum coverage. Skipping this step leaves that subcontractor operating without authorization, even if the prime vendor is fully covered.

No. Neither Microsoft nor AWS claims formal CJIS certification, and the FBI does not certify any cloud platform for CJIS compliance. AWS describes itself as committed to helping customers meet CJIS requirements, not as certified. Either way, the customer or MSP still owns configuring MFA, access controls, and encryption correctly.

Everyone with CJI access, including contractor and vendor staff, needs training within six months of their initial assignment. After that, it repeats every two years. A CSO can accept training documentation from another agency, but the accepting agency then owns the risk if that training falls short.

CJI covers the data law enforcement needs to do its job: biometric data, identity history, person data, organization data, case and incident history, and property data when it’s tied to identifying information. It also covers FBI CJIS-provided data used for tasks like hiring decisions. Plain transaction ID numbers on their own, without identifying data attached, don’t count as CJI.

Yes. Advanced Authentication, meaning a real second factor beyond a username and password, is required for every authorized user accessing CJI, including from a mobile device. Since October 1, 2024, this sits in the audited baseline rather than being optional. The only exception is indirect access, where a person never touches CJI directly.

The FBI’s CJIS Division audits every CJIS Systems Agency once every three years. Each CSA in turn audits the agencies and contractors under it on that same triennial cycle.## Ready to Take CJIS Off Your Plate?This checklist covers what a CJIS audit checks: personnel screening, Addendum coverage, encryption, MFA, training, incident response, and audit readiness. Building and running all seven in-house is a real lift for a small IT team.LeadingIT operates these controls for CJIS-touching clients across Chicagoland. That spans FIPS-validated encryption to the incident response plan an auditor expects to see. Learn more about LeadingIT’s CJIS compliance IT services, or book a call to walk through your specific setup.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.