Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

What Is CJIS Compliance? The Plain-English Guide

August 11, 2026
hero-what-is-cjis-compliance-1.png

CJIS compliance means following the security rules in the FBI’s CJIS Security Policy. The FBI’s Criminal Justice Information Services (CJIS) Division writes and maintains that Policy. It sets minimum security rules for anyone who accesses FBI CJIS systems or handles Criminal Justice Information (CJI).

The Policy isn’t limited to police departments. Courts, corrections agencies, and city IT departments fall under it too. So do private contractors and MSPs that support those agencies’ technology, even if they never log into a police database themselves.

This guide breaks down what CJIS actually covers, who has to follow it, and what compliance looks like day to day.

What Is the CJIS Security Policy?

The CJIS Security Policy is the FBI’s rulebook for protecting CJI. The FBI’s CJIS Division owns it and keeps it current. It draws on presidential directives, federal law, FBI directives, and NIST guidance.

The Policy exists to do three things:

  • Set minimum security rules for who can access FBI CJIS systems
  • Protect CJI “from creation through dissemination,” whether it’s sitting on a server or moving across a network
  • Give every agency, and every vendor working for one, the same baseline to follow

The Policy also isn’t a “set it and forget it” document. It updates roughly twice a year, tied to the CJIS Advisory Policy Board’s spring and fall recommendation cycles.

What Counts as Criminal Justice Information (CJI)?

Most people hear “CJIS” and think “criminal records.” That’s too narrow. CJI is the FBI’s umbrella term, and it covers a lot more ground.

CJI includes:

  • Biometric data (fingerprints, DNA, and similar identifiers)
  • Identity history data
  • Person data tied to an individual
  • Organization data
  • Property data, but only when it’s linked to information that identifies a person
  • Case and incident history data

There’s an important exception worth knowing. Plain transaction ID numbers, like an ORI, NIC, or UCN, aren’t CJI on their own. They only become CJI when they’re paired with identifying data. That distinction matters for anyone deciding what actually needs to be locked down versus what’s just a routine reference number.

Who Has to Comply With CJIS?

This is the part most people get wrong. CJIS doesn’t just apply to police departments. It applies to any entity that accesses, or supports access to, FBI CJIS systems and data.

Entity TypeExamplesCJIS Obligation
Criminal Justice Agency (CJA)Police departments, courts, corrections agenciesFull CJIS Security Policy compliance for any CJI they access
Noncriminal Justice Agency (NCJA)City IT departments, licensing boards with authorized CJI accessSame Policy requirements as a CJA, scoped to their authorized access
Private contractor or vendorMSPs, cloud providers, cabling techs doing work for a CJA or NCJACovered under a CJIS Security Addendum, held to the same training, screening, and audit standards

That third row is the wider-than-you-think point. Any private contractor performing criminal justice functions for a CJA, or for a government NCJA, must be covered by a CJIS Security Addendum. This is a uniform, Attorney-General-approved document. It authorizes the contractor’s access to Criminal History Record Information (CHRI). It also limits how that data can be used.

Once a contractor signs the Addendum, they’re on the hook for the same training, certification, and audit standards as the agency itself. That’s why an IT vendor’s field technicians, remote-access admins, or help desk staff can end up squarely inside CJIS scope, even if their day-to-day work looks like ordinary network support. If you’re managing IT for a police department, court, or an agency with CJI access, this is exactly what our CJIS Compliance Checklist for IT Vendors walks through step by step.

How the CJIS Security Policy Is Organized

The Policy breaks its rules into 19 Policy Areas. Each one covers a specific slice of security, from who can log into a system to how an agency reports a breach.

Trying to read all 19 in a row is a slog. Here’s the practical grouping:

GroupPolicy AreasWhat It Covers
Access & AuthenticationAccess Control, Identification and Authentication, Systems and Communications Protection, Mobile DevicesWho can reach CJI, how they prove who they are, and how networked and mobile systems protect data in transit
Physical & PersonnelPhysical and Environmental Protection, Personnel Security, Media Protection, Configuration ManagementWho can be physically near CJI, background screening, and how storage media and system settings get locked down
Incident Response & OversightIncident Response, Auditing and Accountability, Formal Audits, Risk AssessmentDetecting and reporting incidents, logging activity, and the audit cycle that checks all of it
Program & ContinuityInformation Exchange Agreements, Awareness and Training, System and Services Acquisition, System and Information Integrity, Maintenance, Planning, Contingency PlanningAgreements between agencies, staff training, vendor vetting, system upkeep, and staying operational through a disruption

Every one of these areas sets both a reasoning (“why this matters”) and a tactical, auditable requirement. An auditor doesn’t just ask if you have a policy. They check whether you’re actually following it.

What Happens When CJIS Compliance Fails

CJIS compliance isn’t a one-time checkbox. It’s enforced on a recurring schedule, and the consequences for failing it are real.

The FBI CJIS Division’s Audit Unit audits every CJIS Systems Agency (CSA), typically a state police or state identification bureau, once every three years. That CSA then has its own job: auditing every CJA and NCJA under it on the same triennial cycle. That includes any private contractor working under a CJIS Security Addendum.

Noncompliance can trigger a formal sanctions process. In serious or unresolved cases, an agency can lose access to FBI CJIS systems entirely, cutting off NCIC and CHRI queries.

For a police department, that’s not a paperwork problem. It’s an operational one. Losing CJIS access means officers can’t run the criminal history and warrant checks their job depends on.

That’s also why vendors get pulled into scope. A contractor’s noncompliance can expose the agency that hired them to the same sanctions.

What Compliance Actually Involves Day to Day

Reading the Policy Areas is one thing. Living inside them is another. For a small agency, or the MSP supporting one, CJIS compliance comes down to a handful of concrete, ongoing controls.

Core CJIS Compliance Controls

That includes something as ordinary as a networked copier faxing a report to another agency. The only exception is CJI moving over a closed, non-networked phone line.

Advanced authentication. A username and password alone isn’t enough. The Policy requires a second authentication factor for anyone accessing CJI, including from a mobile device. MSPs serving CJI-handling clients should treat MFA as mandatory, not optional.

Personnel screening. Before anyone, staff or vendor, gets unescorted access to unencrypted CJI, the agency must run a state-of-residency and national fingerprint-based background check. A felony conviction means the agency has to deny access, with a narrow exception reviewed by the CJIS Systems Officer (CSO). This applies to field technicians and remote-access admins too, not just sworn staff.

Training. Everyone with CJI access needs security awareness training within six months of starting, and again every two years after that.

Incident response and logging. Agencies need a working incident-handling process: detection, containment, and recovery, with a defined escalation path. A local incident gets reported up to the state CSA’s Information Security Officer, and from there to the FBI CJIS ISO.

Here’s the short version, as a checklist:

  • Encrypt CJI in transit with FIPS-validated encryption
  • Require a second authentication factor on every account that can reach CJI
  • Fingerprint-screen anyone with unescorted access to unencrypted CJI
  • Refresh security awareness training every two years
  • Maintain a documented incident response and escalation process

For a small agency’s IT team, or the vendor supporting one, this is where LeadingIT operates. LeadingIT runs the technical controls CJIS audits actually check: encryption, multi-factor authentication, access logging, patch management, and a documented incident response process. LeadingIT also helps track the procedural side, like who needs fingerprint-based screening and when training is due.

To be clear: LeadingIT doesn’t replace your agency’s CJIS Systems Officer. No “CJIS certified” credential exists for a vendor to hold. Compliance stays the agency’s own audited, ongoing responsibility.

See Where You Stand

Not sure how exposed your agency or your vendor relationship actually is? Answer a few plain-English questions and get your risk level and gaps to fix, no sign-up required.

Take the free 2-minute CJIS Risk-Check

Frequently Asked Questions

No. No formal CJIS certification exists for an agency, vendor, or cloud platform. Compliance is an ongoing, audited responsibility the agency itself carries, using the standards in the CJIS Security Policy. Any vendor claiming to be “CJIS certified” is overstating what’s actually available.

Yes, if they perform criminal justice functions for a law enforcement agency or a government agency with CJI access. That contractor must be covered under a CJIS Security Addendum, which holds them to the same training, screening, and audit standards as the agency itself.

The FBI CJIS Division’s Audit Unit audits each state’s CJIS Systems Agency once every three years. That state agency then audits the local agencies and contractors under it on the same three-year cycle.

Noncompliance can trigger a formal sanctions process. In serious or unresolved cases, the agency can lose access to FBI CJIS systems entirely, which for a police department means losing the ability to run criminal history and warrant checks.

It’s a uniform, Attorney-General-approved document that authorizes a private contractor’s access to Criminal History Record Information. It limits how that data can be used and holds the contractor to the same training, certification, and audit standards as the government agency it works for.

Yes. The Policy requires advanced authentication, meaning more than just a username and password, for anyone accessing Criminal Justice Information, including from a mobile device.

Everyone with access to Criminal Justice Information, including contractor and vendor staff. Initial training is due within six months of starting, and refresher training is required every two years after that.

Get Your CJIS Exposure Checked

If your agency, or the vendor managing your network, touches Criminal Justice Information, the controls above aren’t optional. LeadingIT helps Chicagoland police departments, courts, and the vendors supporting them put the technical and procedural pieces in place. Learn more about our CJIS compliance IT services, or book a call to talk through where you stand.

Want our cybersecurity insights first? Add LeadingIT as a preferred source on Google and see more of our guidance in your results.


Stephen Taylor is the founder and driving force behind LeadingIT, a Chicagoland-based IT and cloud services company, where he focuses on delivering practical, client-first technology solutions for businesses. A Microsoft Certified professional and author of Technology Should Just Work, he combines hands-on expertise with a passion for making IT simple, transparent, and effective. Read more about the author.

Let Us Be Your Guide In Cybersecurity Protections
And IT Support With Our All-Inclusive Model.