The Criminal Justice Information Services (CJIS) Security Policy defines how criminal justice information (CJI) must be protected when accessed, stored, or transmitted. It is published by the FBI's CJIS Division; the current version is 6.1, dated June 25, 2026, hosted at le.fbi.gov.
It matters because CJIS sets the security baseline for law enforcement data across the United States.
If your organization works with law enforcement agencies, supports public safety or justice systems, provides IT, cloud, or software services to agencies, or has access to criminal justice data, CJIS compliance is not optional. At its core, CJIS is about controlling access, securing systems, and proving trustworthiness.
CJIS is not a privacy law and not a generic cybersecurity framework. It is a mandatory security policy that requires organizations to:
Unlike many standards, CJIS places equal weight on people, process, and technology. Think of it this way: CJIS is cybersecurity plus personnel trust plus strict accountability.
CJIS applies to:
If your staff can see, touch, or administer systems containing CJI, CJIS expectations apply - even if you are not a police agency. Private contractors formalize this through the CJIS Security Addendum, the agreement that binds them to the Security Policy's requirements.
CJIS protects Criminal Justice Information (CJI), including:
Scope follows access, so the covered systems include user accounts and admin access, endpoints and mobile devices, email and collaboration tools, cloud platforms and hosted applications, and logging, monitoring, and backup systems.
If the system can access CJI, the system is in scope.
CJIS overlaps heavily with other security frameworks, with stricter enforcement in specific areas:
The difference: CJIS adds personnel vetting, formal information exchange agreements, and audit rigor on top of standard cybersecurity.
Ignore policy section numbers. Focus on what must actually work:
CJIS expects controls to work and to be provable at any time.
CJIS enforcement is real and immediate. Common consequences:
The biggest risk is losing trust with law enforcement partners. Once access is revoked, recovery is slow and costly.
CJIS rewards exactly what a mature cyber risk program produces: disciplined access control, hardened and monitored systems, vetted people, and evidence on demand. Because the policy aligns to NIST SP 800-53 control families, work done for CJIS transfers directly to every other NIST-aligned obligation you carry.
For vendors serving both government and commercial customers, that overlap is the efficiency: one control set, multiple markets.
Reality check: CJIS is strict, but not exotic.
It feels intimidating because enforcement is real, audits are direct, and expectations are explicit. But technically, CJIS relies on strong access controls, secure systems, continuous monitoring, and trained, trusted personnel. Most failures are procedural, not technical - the missing agreement, the unscreened technician, the unreviewed log.
Our Cyber Risk & Compliance Gap Assessment helps organizations:
Our assessment checks your environment against the CJIS Security Policy's technical and personnel controls, including the agreements your agency partners expect to see.
Know which systems access CJI, who has access, and how the data flows. Scope follows access, so this map defines your entire obligation.
This is CJIS-critical: MFA, role-based access, admin separation, and regular access reviews. Unique IDs are mandatory - shared accounts are an audit finding waiting to happen.
CJI is often accessed in the field, so devices need hardening and monitoring - and CJI needs encryption both in transit and at rest.
Background checks, CJIS awareness training, and clear accountability - plus the formal agreements access requires, including the CJIS Security Addendum for private contractors.
Screenshots. Configs. Logs. Training records. Policies. Evidence turns security into compliance, and CJIS audits ask for it directly.
Yes. If your staff can see, touch, or administer systems containing criminal justice information, CJIS expectations apply - police agency or not. Private contractors formalize this through the CJIS Security Addendum, and agencies cannot lawfully give you access without that agreement in place.
The standard agreement that binds private contractors to the CJIS Security Policy's requirements when they handle CJI for an agency. It is part of the policy's information exchange agreement regime - the paperwork layer that makes third-party access legitimate. If you serve law enforcement customers and have never signed one, that is a gap to close now.
Version 6.1, dated June 25, 2026, published by the FBI CJIS Division at le.fbi.gov. The policy now updates on a regular cycle and aligns its requirements to NIST SP 800-53 control families - so always work from the current version, not a saved PDF.
Yes - personnel security is a core CJIS control, not an HR formality. Staff with CJI access undergo background screening, complete security awareness training on a defined cycle, and lose access promptly when roles change or employment ends.
Yes, both in transit and at rest. The current policy requires cryptographic protection of CJI in both states, alongside MFA for system access. Transit-only encryption - a common legacy posture - no longer meets the requirement.
Yes, when the environment meets the Security Policy's requirements - encryption, access control, personnel screening, audit capability, and the required agreements all follow the data into the cloud. The question is never "cloud or not"; it is whether that specific environment and its operators satisfy the policy.
It depends on how many systems and people touch CJI. We publish no pricing - you get a firm quote before any work begins, and the conversation costs nothing. Containing CJI to fewer systems is the most reliable way to contain the cost.
Map your CJI access first: systems, people, and agreements. Then close the gaps in identity, encryption, and personnel screening before an agency audit finds them. Our Cyber Risk & Compliance Gap Assessment covers the technical and the procedural side in one pass.
Official source: FBI CJIS Division, CJIS Security Policy Resource Center
Secondary source: FBI, CJIS Division
Source verified 2026-07-24
By Joshua Nelson, CXO & Compliance Coach · Last reviewed 2026-07-25