Framework Cloud & Government Authorization
CJIS
The CJIS Security Policy is the FBI's rulebook for anyone who accesses or handles criminal justice information (CJI) from FBI CJIS systems: state and local law enforcement, courts, dispatch centers, and the contractors and cloud providers that serve them.
Version 6.0 (December 27, 2024) restructured the policy around NIST SP 800-53 control families with priority tiers, and a corrections release, version 6.1, is dated June 25, 2026 (verify against the FBI resource center). Priority 1 controls have been sanctionable since October 1, 2024; the remaining priority tiers become sanctionable on September 30, 2027.
Several secondary sources state the FBI continues to audit against v5.9.5 until March 31, 2027; verify that date with your CJIS Systems Agency.
There is no certificate. Compliance is demonstrated through written agreements and documentation: signed user agreements with the state CJIS Systems Agency, the FBI CJIS Security Addendum for every contractor with CJI access, personnel screening and security awareness training records, an incident response plan and reporting procedure, and policies covering access control, audit logging, encryption, media protection and physical security.
help
Who has to comply
Any agency or organization with access to CJI from FBI CJIS systems: criminal justice agencies, non-criminal-justice agencies with authorized access, and private contractors, hosting and cloud providers that store, process or transmit CJI on their behalf. Contractor obligations flow down through the CJIS Security Addendum.
What the assessor asks to see
Signed user agreement and management control agreements; CJIS Security Addendum for each contractor and its personnel; fingerprint-based background check records; security awareness training completion; written information security policy set (access control, identification and authentication, audit and accountability, media protection, physical protection, system and communications protection); incident response plan and incident reports; encryption and MFA configuration evidence; network diagram and asset inventory; audit log samples and review records.
Where the requirement sits: CJIS Security Policy v5.9/6.0 policy areas
Assessors
Who assesses CJIS
Government audit only. The FBI CJIS Audit Unit audits each state CJIS Systems Agency (CSA), and the CSA audits the local agencies and contractors that connect through it. There is no third-party certification body for CJIS.
Enforcement authority sits with the FBI CJIS Division and the state CSA.
No firm has claimed a CJIS assessor listing yet. Claim yours →
Consultants
Who helps with CJIS
Yes. Consultants and managed service providers offer gap assessments against the current policy version, policy writing, cloud architecture reviews, and audit preparation. Cloud vendors publish CJIS-aligned offerings, but a vendor cannot certify an agency; the agency and its CSA remain responsible.
Firms that name this framework in their own material. Listings we have not verified yet come from public filings and partner lists. Each firm can confirm its own.
No firm has claimed a CJIS consultant listing yet. Claim yours →
Software
Tools for CJIS
Tools that name this framework in their own material.
Related reading
- Criminal Justice Information Services (CJIS) - Azure complianceExplains how a cloud provider signs CJIS security addenda with states and which obligations stay with the agency.Microsoft
- Criminal Justice Information Services complianceCovers version 6.0 hosting expectations, data boundary controls and the personnel screening the policy still requires.Google Cloud
Independent third-party explainers, chosen by hand. Not affiliated with this site and not paid placements. All links are nofollow.
Need a hand implementing it?
Find a Consultant for CJIS
Tell us what you need done and we will point you to firms that do this work. Your details go to a firm only when you choose it.
Not sure where to start?
Get Help with CJIS
Tell us what you are trying to put in place. We will point you to the right tool, a consultant who can implement it, or both.