HomeFrameworksCloud & Government AuthorizationCJIS

Framework  Cloud & Government Authorization

CJIS

The CJIS Security Policy is the FBI's rulebook for anyone who accesses or handles criminal justice information (CJI) from FBI CJIS systems: state and local law enforcement, courts, dispatch centers, and the contractors and cloud providers that serve them.

Version 6.0 (December 27, 2024) restructured the policy around NIST SP 800-53 control families with priority tiers, and a corrections release, version 6.1, is dated June 25, 2026 (verify against the FBI resource center). Priority 1 controls have been sanctionable since October 1, 2024; the remaining priority tiers become sanctionable on September 30, 2027.

Several secondary sources state the FBI continues to audit against v5.9.5 until March 31, 2027; verify that date with your CJIS Systems Agency.

There is no certificate. Compliance is demonstrated through written agreements and documentation: signed user agreements with the state CJIS Systems Agency, the FBI CJIS Security Addendum for every contractor with CJI access, personnel screening and security awareness training records, an incident response plan and reporting procedure, and policies covering access control, audit logging, encryption, media protection and physical security.

AI-compiled
Share
Sponsored
CJIS
help
Consultants  Assessors  Quotes
Matched3 quotesread by a human
The Shortlist is Yoursfrom this directory
Comply the Modern WayFind help with CJIS
01
Verified listings first
Unverified ones follow, labeled
02
Published prices where they exist
“Quote only” where we confirmed it, “Not published” where we have not
03
Up to three quotes, one form
Firms don’t see you until you choose
House ad. This slot is open to firms listed for this page. Get help Advertise here

Who has to comply

Any agency or organization with access to CJI from FBI CJIS systems: criminal justice agencies, non-criminal-justice agencies with authorized access, and private contractors, hosting and cloud providers that store, process or transmit CJI on their behalf. Contractor obligations flow down through the CJIS Security Addendum.

What the assessor asks to see

Signed user agreement and management control agreements; CJIS Security Addendum for each contractor and its personnel; fingerprint-based background check records; security awareness training completion; written information security policy set (access control, identification and authentication, audit and accountability, media protection, physical protection, system and communications protection); incident response plan and incident reports; encryption and MFA configuration evidence; network diagram and asset inventory; audit log samples and review records.

Where the requirement sits: CJIS Security Policy v5.9/6.0 policy areas

Assessors

Who assesses CJIS

Government audit only. The FBI CJIS Audit Unit audits each state CJIS Systems Agency (CSA), and the CSA audits the local agencies and contractors that connect through it. There is no third-party certification body for CJIS.

Enforcement authority sits with the FBI CJIS Division and the state CSA.

No firm has claimed a CJIS assessor listing yet. Claim yours →

Consultants

Who helps with CJIS

Yes. Consultants and managed service providers offer gap assessments against the current policy version, policy writing, cloud architecture reviews, and audit preparation. Cloud vendors publish CJIS-aligned offerings, but a vendor cannot certify an agency; the agency and its CSA remain responsible.

Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.

No firm has claimed a CJIS consultant listing yet. Claim yours →

Software

Tools for CJIS

Tools that name this framework in their own material.

Related reading

  1. Criminal Justice Information Services (CJIS) - Azure complianceExplains how a cloud provider signs CJIS security addenda with states and which obligations stay with the agency.Microsoft
  2. Criminal Justice Information Services complianceCovers version 6.0 hosting expectations, data boundary controls and the personnel screening the policy still requires.Google Cloud

Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.

Need a hand implementing it?

Find a Consultant for CJIS

Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.

Not sure where to start?

Get Help with CJIS

Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.

About this data

Pages on this site are compiled with AI from two or more linked sources, rewritten in our words, and reviewed by people in stages. Each record shows its stage and date. Nothing here is legal, audit or tax advice, and policyandcompliance.com accepts no responsibility for errors or for decisions made on it. Read the source, then decide.
How we compile and verify →

Think something is wrong?

corrections@policyandcompliance.com
Tell us the page and what you found. We check it against the source and fix it.
Corrections log →

Want to advertise here?

ads@policyandcompliance.com
A primary ad and a secondary placement, flat fee. Buying one changes nothing else on the page.