Skip to main content
  • For Support:

    815-308-2095

  • New Client
    815-788-6041

Free CJIS Compliance Risk Check:
Is Your Agency, or Your IT Vendor, Actually Ready?

CJIS Security Policy Risk Check

  • 9 quick questions
  • Takes about 2 minutes
  • No sign-up to see your result

Your top next moves

    Nothing critical flagged. Keep everything current and re-check yearly.

    Book a call

    Use the interactive risk check below to see where your agency, or the IT company that supports it, actually stands against the FBI’s CJIS Security Policy.

    Answer 8 quick questions covering the CJIS Security Addendum, fingerprint background checks, and the technical basics (MFA, encryption, audit logging, physical security) across the policy’s 20 areas, and get your risk level in about 2 minutes: your risk band, the specific gaps to close, and a printable checklist you can hand to your IT provider.

    No sign-up to see your result.

    What the CJIS Security Policy Actually Covers (the short version)

    The Criminal Justice Information Services (CJIS) Security Policy is the FBI’s set of security rules for anyone who accesses, stores, or transmits criminal justice information (CJI), fingerprint records, criminal history data, and similar law-enforcement and court records. It applies well beyond police departments:

    Dispatch centers, courts, prosecutors, corrections, and the municipal or county IT staff and outside IT vendors who support any of those systems can all fall in scope. The current version, CJIS Security Policy v6.1, groups its requirements into 20 policy areas covering things like access control, identification and authentication, audit and accountability, physical protection, media protection, incident response, personnel security, and mobile devices.

    Two requirements matter more than the rest to most agencies:

      • Every private contractor or vendor with CJI access has to be bound by a CJIS Security Addendum, a specific FBI-approved document separate from any ordinary vendor contract.
      • Every individual with unescorted access to CJI, employee or vendor, has to pass a state and national fingerprint-based background check. The checklist below is organized around those requirements and the policy areas that back them.

    The checklist below focuses on the main gaps a CJIS auditor may uncover

    The Full CJIS Compliance Checklist

    Work through each area below. Anything you can’t confirm is a gap. If you can’t prove it, a CJIS Division audit can’t either.

    • 1. CJIS Security Addendum (Vendor and Contractor Obligation):

      ✓ A signed CJIS Security Addendum on file with every private vendor or contractor, including your IT provider or MSP, not just a standard service agreement or NDA.

      ✓ Confirmation that whoever manages your network, backups, help desk, or remote support actually knows they’re bound by it, not just that a document was signed once.

      ✓ The Addendum reviewed and reconfirmed any time you change IT providers or add a new vendor that can touch CJI.

    • 2. Personnel Security (Fingerprint Background Checks):

      ✓ A state and national fingerprint-based background check on file for every individual with unescorted physical or logical access to CJI, agency staff and vendor staff alike.

      ✓ Coverage that reaches beyond the primary technician: anyone at your IT provider who could remotely view, support, or troubleshoot a system showing CJI is in scope.

      ✓ A process for re-checking access status whenever a vendor’s staff changes, not a one-time check at contract signing.

    • 3. Identification, Authentication, and Access Control:

      ✓ A unique login for every user, no shared accounts, on any system with CJI.

      ✓ Access granted on a least-privilege, need-to-know basis.

      ✓ Multi-factor authentication required for every person accessing CJI, including remote and mobile access, a fully enforceable requirement since October 2024.

    • 4. Encryption and Systems/Communications Protection:

      ✓ CJI encrypted at rest wherever it’s stored, including backups, and encrypted in transit whenever it moves across a network.

      ✓ Encryption coverage confirmed on vendor-side systems too, remote-monitoring tools, backup copies, and support tickets that may contain CJI or screenshots of it.

      ✓ Network boundaries and remote-access paths into CJI systems documented and controlled.

    • 5. Audit and Accountability:

      ✓ Audit logging enabled on every system that touches CJI: who accessed it, when, and what they did.

      ✓ Logs retained for the required period and actually reviewed by a person, not just collected and left unread.

      ✓ A documented process for investigating anomalies the logs turn up.

    • 6. Physical Protection:

      ✓ Physical access to rooms, devices, or workstations where CJI is viewed or stored controlled with locked doors, badge access, or a visitor log.

      ✓ Vendor and contractor staff working onsite covered by the same physical-access rules as employees.

      ✓ Visitor logs and escort procedures in place for any physically secure location.

    • 7. Media Protection and Disposal:

      ✓ Digital and physical media containing CJI (drives, backup tapes, printed reports) tracked and controlled.

      ✓ Secure wipe or destruction of any device or media before disposal, reuse, or return to a vendor.

    • 8. Security Awareness Training:

      ✓ Annual CJIS-required security awareness training completed and documented for everyone with CJI access.

      ✓ Coverage that includes your outsourced IT team’s staff, not just agency employees.

      ✓ Signed training records retained and available for audit.

    • 9. Incident Response and Formal Audits:

      ✓ A documented incident-response plan covering CJI-related security events, with clear escalation steps.

      ✓ Familiarity with your state CJIS Systems Agency’s audit cadence and what a formal CJIS audit actually requests.

      ✓ A designated point of contact responsible for coordinating any incident or audit response.

    • 10. Mobile Devices and Configuration Management:

      ✓ Mobile devices that access CJI managed, encrypted, and covered by the same authentication requirements as desktop systems.

      ✓ Systems configured to a documented baseline, with changes tracked rather than made ad hoc.

    • 11. CJIS Security Policy v6.0 readiness (the October 2027 deadline):

      ✓ Awareness of which of v6.0’s 20 policy areas actually apply to your agency’s specific systems and vendors.

      ✓ A written plan, owned by someone specific, to close any gaps before full enforcement.

      ✓ A shared understanding with your IT provider of who owns which parts of that plan.

    How to read your gaps?

    • 0 – 2 Gaps (No Critical Gaps)

      Strong Shape

    • 3 – 6 Gaps (or a Single Critical Gap)

      Real, findable gaps that would draw attention in a CJIS review.

    • 7+ Gaps (or 2+ Critical Gaps)

      Your agency (or your vendor) likely hasn’t nailed down the two things CJIS cares about most: who’s contractually bound, and who’s been vetted to touch the data.

    CJIS Compliance FAQ

    What is the CJIS Security Policy?

    It’s the FBI’s security policy governing how criminal justice information, fingerprint records, criminal history data, and similar law-enforcement and court records are accessed, stored, and transmitted. The current version, v6.1, organizes its requirements into 20 policy areas covering access control, encryption, audit logging, physical security, personnel security, incident response, and more.

    Does CJIS apply to us if we’re not a police department?

    Often, yes. Any agency that can access, store, or transmit criminal justice information can be in scope: dispatch and 911 centers, courts, prosecutors’ offices, corrections, and the municipal or county government departments and IT staff that support any of those systems. The private IT vendors and MSPs that serve those agencies are pulled in too, through the CJIS Security Addendum.

    What is a CJIS Security Addendum, and does our IT provider need to sign one?

    It’s a specific, FBI-approved contractual document that legally binds a private contractor or vendor to the CJIS Security Policy, separate from any regular service agreement or NDA. If your IT provider can access, store, transmit, or remotely support any system containing CJI, and most managed IT providers to public-safety and municipal clients can, they need one on file. It’s common for an MSP to manage this kind of network for years without realizing it was never signed.

    Do IT technicians really need a fingerprint background check, not just a normal one?

    Yes. CJIS specifically requires a state and national fingerprint-based background check for anyone with unescorted physical or logical access to CJI, and a standard employment background check does not satisfy this. The requirement reaches further than most agencies expect: a help-desk technician who can remotely view a screen showing criminal history data is in scope, not only the people who built or administer the system.

    What happens if we’re not CJIS compliant?

    Consequences can include denial of access to FBI criminal justice systems (which for a law enforcement agency can mean officers losing the ability to run checks in the field), fines, and other sanctions, and can extend to the vendor relationship itself if an IT provider is found to be out of compliance with a Security Addendum it signed.

    Is LeadingIT CJIS certified?

    No, and no legitimate IT company holds a “CJIS certification,” because CJIS compliance isn’t a certification an outside vendor can earn once and display. It’s an ongoing set of controls and a signed Security Addendum, agency by agency, vendor by vendor. LeadingIT helps clients get and stay ready for CJIS the same way we approach HIPAA, PCI, and FTC Safeguards: as a service we deliver for you, not a badge we claim. And because we can be the vendor bound by a Security Addendum on a municipal or law-enforcement engagement, we hold our own team to the same fingerprint-background-check and security-control bar this checklist describes.

    Ready to close your gaps?

    If your result flagged an unsigned Security Addendum, un-vetted technicians, or incomplete MFA and encryption, that’s IT vendor management work, not paperwork, and it’s exactly what a managed IT and cybersecurity partner should already be doing for you.

    LeadingIT helps Chicagoland municipal, public-safety, and government agencies close CJIS gaps, and holds its own team to the same standard as the vendor in that relationship.

    Email yourself the full result from the tool above, book a free 30-minute gap review, or contact us and see how we deliver this as a managed service.