Is Microsoft 365, AWS, or Azure CJIS Compliant? The Straight Answer
No, not automatically. Is Microsoft 365, AWS, or Azure CJIS compliant out of the box? No cloud platform is. “CJIS certified” is not a real credential. The FBI does not certify any cloud vendor or software product for CJIS compliance, full stop.
That does not mean these platforms are off limits. Specific configurations of Microsoft 365, AWS, and Azure can support Criminal Justice Information (CJI) when they are set up correctly. The real question is not “is my vendor certified.” It’s “which configuration am I actually running, and who is responsible for what.”
That distinction matters because the wrong assumption is expensive. A police department or a vendor that assumes “we’re on Microsoft, so we’re covered” can miss encryption requirements, personnel screening obligations, or a missing CJIS Security Addendum. All three of those gaps get caught in an audit.
Is Microsoft 365 CJIS Compliant?
Only specific Microsoft government-tier products are. Regular, commercial Microsoft 365 or Office 365, the version most businesses run, is not on Microsoft’s own in-scope list.

Per Microsoft’s CJIS compliance documentation, the products Microsoft actually lists as in scope for CJIS attestation are:
That last row is the one people miss. Standard Office 365 or Microsoft 365, the license most small and midsize agencies default to, is a different environment from GCC. It is not built or attested for CJI.
Being on the in-scope list is not the whole story either. Microsoft still has to sign a CJIS Security Addendum with your state before that coverage applies to you. Microsoft does this through state-level CJIS Management Agreements. The exceptions named on that page are Delaware, Louisiana, Ohio, South Dakota, and Wyoming. Either way, check your specific state’s status before you assume coverage.)
The FBI does not certify any cloud service for CJIS compliance. There is no such thing as a “CJIS certified” cloud platform, from Microsoft or anyone else.
That caveat comes straight from Microsoft’s own compliance page, not from a competitor trying to knock Microsoft down a peg. Microsoft’s compliance posture is an attestation built into its agreements with a state’s CJIS authority and with its customers. It is not a government-issued seal of approval, because no such seal exists.
Is Azure CJIS Compliant? The Part Most People Get Wrong
Here’s the surprising part. Both Azure commercial and Azure Government can support CJI workloads. Azure commercial is not automatically disqualified the way regular Microsoft 365 is.
The real difference between the two is not “compliant vs. not compliant.” It’s who is contractually responsible for screening the people who could touch your data.
| Factor | Azure Commercial | Azure Government |
|---|---|---|
| Can support CJI workloads | Yes, with extra steps you must configure | Yes |
| CSP staff fingerprint screening | Not contractually covered by Microsoft | Contractually covered under signed CJIS Management Agreements |
| Your encryption obligation | Full encryption in transit, at rest, and in use, with keys you control | Standard controls; confidential computing required only in states without a signed agreement |
Azure Government’s operations staff are contractually committed, under Microsoft’s CJIS Management Agreements with most states, to fingerprint-based background checks. Azure commercial’s operations staff are not covered by that same commitment.
That gap does not disappear on its own. If you run CJI on Azure commercial, or on Azure Government in a state without a signed agreement, you have to close it yourself. Per Azure’s CJIS compliance documentation, citing CJIS Security Policy Appendix G.3, you have to fully encrypt CJI three ways:
- In transit, using FIPS-validated encryption.
- At rest, on Microsoft’s storage.
- In use, meaning while it’s actively being processed in memory.
That third piece requires confidential-computing virtual machines, a hardware-based trusted execution environment that keeps data encrypted even while it’s running. You also have to keep sole control over the encryption keys yourself (customer-managed keys). Do all of that correctly, and Microsoft’s own staff can never see your unencrypted CJI, which is what removes the fingerprint-screening requirement in the first place.
Skip that step, and you are running CJI on infrastructure where Microsoft’s own operations staff are not contractually screened to touch it. That is exactly the gap a CJIS audit is designed to catch.
So the takeaway on Azure is not “avoid commercial Azure.” It’s “know which tier you’re on, and know exactly what that tier does and does not do for you automatically.”
Is AWS CJIS Compliant? GovCloud vs. Commercial Regions
AWS is blunt about this too. There is no official CJIS certification anyone can hold, cloud vendor or otherwise.
Per AWS’s own compliance page, there is no central CJIS authorization body. There is no accredited pool of independent assessors. There is no standardized way to declare a solution “CJIS compliant.” AWS describes itself as “committed to helping customers meet CJIS requirements,” not as CJIS certified.
That last phrase matters. AWS isn’t claiming certification. It’s offering to help you meet requirements you’re still responsible for.
Many agencies assume they need AWS GovCloud (US) for CJIS work. That assumption comes from ITAR, where GovCloud really is mandatory. CJIS doesn’t work the same way.
| Factor | AWS Commercial Regions | AWS GovCloud (US) |
|---|---|---|
| Can support CJI workloads | Yes | Yes |
| FIPS-140-3-validated encryption APIs | Available | Available |
| Strictly required for CJIS | No | No, but common practice |
| Aligns to FedRAMP High baseline | Not by default | Yes |
| Aligns to DoD Cloud Computing SRG | Not by default | Yes, Impact Levels 2, 4, and 5 |
FIPS-140-3-validated encryption APIs needed to encrypt CJI in transit exist in both environments. GovCloud adds extra alignment to FedRAMP High and DoD Impact Levels 2, 4, and 5. Useful for some agencies. Not a CJIS-specific requirement on its own.
AWS’s shared-responsibility model applies here the same way it does everywhere else on AWS. AWS operates and secures the underlying infrastructure. You configure and secure what runs on top of it.
That includes:
- Any locally-deployed resources, like Storage Gateway disk volumes or Snowball data-transfer workstations.
- Data isolation between workloads.
- Access controls on every account and role that can reach CJI.
- Encryption configuration and key management.
Choose the wrong region type and skip this configuration work. It doesn’t matter whether you picked commercial or GovCloud. The gap is the same either way.
The Pattern Across All Three Vendors
Line up Microsoft, Azure, and AWS, and the same shape repeats.

A government-tier environment, Office 365 GCC, Azure Government, AWS GovCloud, reduces one specific burden. It contractually screens the cloud provider’s own staff for you. Fingerprint-based background checks, handled by the vendor, not by you.
That’s it. That’s what the government tier buys you.
It does not configure any of the following for you:
- Multi-factor authentication on every account that can reach CJI.
- Access controls that limit who can see what.
- Audit logging with retention long enough to survive a review.
- Encryption key ownership, especially if you’re on a commercial tier.
- Your own CJIS Security Addendum coverage with your state.
No cloud vendor’s compliance posture is sufficient on its own. It’s necessary, not sufficient. The customer configures the rest.
Skip any one of those five items. A government-tier subscription won’t save you. The audit checks your configuration, not just your vendor’s tier.
What an MSP Actually Configures On Top
Picking a tier, GCC, Azure Government, GovCloud, is step one. It’s not the finish line.
An MSP working with CJI-handling clients configures the same core controls no matter which cloud tier sits underneath. The CJIS Security Policy audits these directly:
- FIPS-validated encryption for CJI in transit
- Advanced (multi-factor) authentication on every account that can reach CJI
- Access logging and audit-trail retention
- Patch and configuration management
- A documented incident response process with a clear escalation chain
For the full walkthrough vendor by vendor, see the CJIS compliance checklist for IT vendors.
See Where You Stand
Not sure which cloud tier your agency or vendor is actually running, or what’s misconfigured on top of it? The free 2-minute CJIS Risk-Check walks through plain-English questions about your setup and flags the gaps to fix. No sign-up required to see your result.
Take the free 2-minute CJIS Risk-Check
Related Guides
- What Is CJIS Compliance? A Plain-English Guide
- CJIS Compliance Checklist for IT Vendors
- CJIS Security Policy Areas Explained: The Original 13 and the Current 19
Frequently Asked Questions
No, not standard commercial Microsoft 365. Microsoft’s own in-scope list for CJIS attestation includes Azure Government, Dynamics 365 U.S. Government, and Office 365 GCC. Regular Office 365 or Microsoft 365 is a separate, non-GCC environment and isn’t on that list.
No. AWS says CJI workloads can run in either AWS GovCloud or standard commercial regions. FIPS-140-3-validated encryption APIs are available in both. GovCloud adds extra alignment to FedRAMP High and DoD Impact Levels, which some agencies want, but it isn’t a CJIS-specific requirement.
It’s a uniform, Attorney General-approved addendum that authorizes a private contractor to access Criminal History Record Information. It limits how the contractor can use that data. It also holds the contractor to the same training, certification, and audit standards as the government agency itself.
It can support CJI, but only with extra work. Microsoft’s guidance requires full encryption in transit, at rest, and in use, with confidential-computing virtual machines and customer-controlled encryption keys. Skip that configuration, and Microsoft’s own staff aren’t contractually screened to touch your data the way they are on Azure Government.
No. Microsoft still has to sign a CJIS Security Addendum with your specific state through a CJIS Management Agreement before that attestation applies to you. Check your state’s status directly rather than assuming coverage.
The agency is, or the vendor operating on its behalf under a signed CJIS Security Addendum. No cloud vendor is CJIS certified, because that certification doesn’t exist. Microsoft and AWS both say plainly that compliance stays the customer’s ongoing, audited responsibility.
The FBI CJIS Division’s Audit Unit can start a formal sanctions process for noncompliance. In serious or unresolved cases, an agency can lose access to FBI CJIS systems, including NCIC and CHRI queries. Each CJIS Systems Agency also audits the CJAs, NCJAs, and contractors under it every three years.
Get Your Cloud Environment CJIS-Ready
Picking Office 365 GCC, Azure Government, or AWS GovCloud is a real step. It isn’t the finish line though.
LeadingIT configures the controls a CJIS audit actually checks, on top of whichever cloud tier you’re running. That includes FIPS-validated encryption, advanced authentication, access logging, and a documented incident response process.
See LeadingIT’s CJIS compliance IT services for the done-for-you path. Or book a call to walk through your specific setup.
Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.
