The CJIS Security Policy Explained: Requirements, Framework Comparisons, and an MSP Prep Guide

The In-Brief: An Introduction to the CJIS Security Policy

Picture the scene. A patrol officer runs a plate during a traffic stop. Somewhere behind that ten second query sits a fingerprint database, a criminal history repository, a records management system, and, more likely than not these days, at least one managed service provider keeping the lights on for that department’s network. Nobody in the squad car is thinking about information security controls in that moment. Somebody has to be, though, and that somebody answers to a document many GRC professionals have never had reason to open: the CJIS Security Policy.

In this blog, I’m diving into the CJIS Security Policy. I want to talk a bit about its history and what to expect with it, who it applies to, its uniqueness and similarities compared to other GRC priorities in other industries, and finally, how Managed Service Providers get pulled into the mix. Along the way, I’ll try to use principles and concepts from NIST SP 800-171, CMMC, and DFARS clauses since most of my readers are probably more familiar with those. Hopefully this is helpful. If not, I deserve handcuffs. Ok, between the headers and the puns, I should probably already be locked up.

The Crime Scene: What Is the CJIS Security Policy, Anyway?

The CJIS Security Policy, or CJISSECPOL if you want to speak the lingo, is published by the Criminal Justice Information Services Division of the FBI. CJIS itself has been around since 1992, and the security policy has served as the FBI’s mechanism for protecting Criminal Justice Information (CJI) ever since, updated on a rolling basis as technology and threats evolve.

The current version, 6.1, was released on June 25, 2026, building on the version 6.0 modernization released in December 2024, the biggest structural overhaul the policy has seen in over a decade. That modernization effort realigned the entire control structure around NIST SP 800-53 Revision 5, the same catalog underpinning FedRAMP. If you’ve spent time in the FedRAMP Moderate Equivalency conversation with me before, you already know why that alignment matters: it means CJIS now speaks a dialect of the same control language as NIST 800-171, CMMC, and FedRAMP, even though it governs a completely different universe of data.

NOTE: v6.1 is the current version published by the FBI, but some agencies and localities haven’t begun enforcing the new policy’s set of requirements yet and are still auditing against v5.9.5. If this is currently pertinent to a contract or obligation your organization has, you may want to get clarification as to the version of the policy that should be used.

The essential premise, straight from the policy’s own executive summary, is to protect the full lifecycle of CJI, from creation through dissemination or destruction, whether it’s sitting at rest or moving across a network. It applies to every individual, contractor, private entity, noncriminal justice agency representative, or member of a criminal justice entity, with access to, or who operates in support of, criminal and noncriminal justice services and information. Read that again if you’re an MSP. “Operates in support of” is pointing at you, and it’s the reason your helpdesk technician remoting into a records management system counts just as much as the detective who’s logged in directly on the daily.

Persons of Interest: Who Actually Has to Answer to CJIS?

CJI itself isn’t one monolithic data type. The policy breaks it into five buckets: biometric data (fingerprints, palm prints, iris scans, facial recognition), identity history data, biographic data tied to a case, property data, and case or incident history. Sitting inside that broader category is Criminal History Record Information (CHRI), sometimes called “restricted data.” CHRI gets extra handling requirements because it’s the stuff that can follow a person around: arrest records, warrant status, criminal history summaries.

Who has to comply? The obvious answer is criminal justice agencies (CJAs), courts, and state repositories. The less obvious answer, and the one that matters most for the readers I’m writing this for, is anyone who touches CJI on their behalf. That includes noncriminal justice agencies (NCJAs) that receive CHRI for background check purposes, and it includes every contractor, cloud provider, software vendor, records management vendor, dispatch software company, and yes, managed service provider that stores, processes, or transmits CJI while supporting one of these agencies. There is no small business carve out. There is no “we just do helpdesk tickets” exemption. If your access lets you view, touch, or transmit CJI, or lets you operate in support of a system that does, you’re in scope.

The Usual Suspects: How CJIS Stacks Up Against ISO 27001, HIPAA, and NIST SP 800-171/CMMC

Here’s where I get to have some fun, because if you already speak fluent NIST 800-171 or CMMC, a lot of CJIS is going to feel like meeting a cousin you didn’t know you had.

FrameworkData ProtectedGovernance / Enforcement ModelPrescriptiveness
CJIS Security PolicyCriminal Justice Information (CJI/CHRI)Federated: CJIS Systems Agencies, state audits, FBI CJIS Audit UnitHighly prescriptive (specific timers, numeric thresholds)
NIST SP 800-171 / CMMCControlled Unclassified Information (CUI)C3PAOs, DIBCAC, CyberAB AccreditationPrescriptive, objective-based assessment criteria
ISO/IEC 27001Organizational information assets generallyAccredited certification bodies; portable international certificatePrinciple-based, risk-driven
HIPAA Security RuleElectronic Protected Health Information (ePHI)Self-attested “reasonable and appropriate”; OCR enforcement after the factFlexible; required vs. addressable specifications

The structural overlap is real. CJIS’s modernized control families, Access Control, Audit and Accountability, Configuration Management, Identification and Authentication, Incident Response, Personnel Security, Risk Assessment, System and Communications Protection, and so on, map almost one for one onto the same NIST 800-53 lineage that produced NIST SP 800-171’s fourteen domains. If you’ve built a 3.5.x authentication story or a 3.3.x audit logging story for a DIB client, you already understand the shape of the corresponding CJIS controls. CJIS actually goes a bit further than 800-171 by keeping full fledged Contingency Planning, Planning, and Supply Chain Risk Management as their own dedicated control families, plus Policy Area 20 on mobile devices.

Where things diverge is enforcement. Currently, CMMC leans on self-assessments or third-party assessments (C3PAOs or DIBCAC) with the CyberAB acting as the accreditation body for that program. ISO 27001 works similarly, with an accredited certification body issuing a portable certificate that customers around the world recognize. CJIS has neither. There’s no “CJIS certified vendor” credential you can hang on your website. Compliance runs through the CJIS Systems Agency and State Identification Bureau structure in each state, with periodic audits performed by the state, while the FBI’s own CJIS Audit Unit audits the CSAs above them. It’s federated by design, which means requirements and processes, like fingerprint submissions, can vary state by state even though the underlying policy is national.

HIPAA sits at the opposite end of the prescriptiveness spectrum from CJIS. HIPAA’s Security Rule asks covered entities and business associates to implement “reasonable and appropriate” safeguards, with a mix of required and merely “addressable” specifications, leaving much of the “how” up to the organization’s own risk analysis.

NOTE: This is in reference to the current HIPAA requirements. It’s important to be aware of the HIPAA Notice of Proposed Rulemaking (NPRM). The statements above about HIPAA do not take into account the significant changes proposed under this instance of rulemaking from the Office for Civil Rights (OCR) that we anticipate to see more movement on in mid-2027. Check out the blog I’ve written on that here.

CJIS, by contrast, hands you exact numbers. Accounts inactive for 90 calendar days get disabled within one week. Temporary and emergency accounts get automatically removed within 72 hours. Accounts belonging to individuals identified as a direct threat get disabled within 30 minutes of discovery. Suspected incidents get reported internally within one hour, then escalated to the CSO, SIB Chief, or Interface Agency Official and the FBI CJIS ISO. Terminated employees lose access within 24 hours, and if you’re the vendor, you owe the agency notice of that termination within 24 hours too. That’s a level of specificity you don’t currently see in NIST SP 800-171 or ISO 27001’s Annex A, which provides some general requirements without putting a clock or specific threshold on things most of the time and allowing the organization to decide such thresholds.

CJIS’s contractor flow down mechanism is the CJIS Security Addendum, grounded in 28 CFR 20.33(a)(6) and (7) and reproduced in Appendix H. Functionally, it plays the same role that DFARS flow down requirements play, or a Business Associate Agreement plays for HIPAA. It’s the legal instrument that extends the policy’s requirements onto a private entity that wasn’t a criminal justice agency to begin with. If you don’t have a signed addendum, then you don’t have legal access to CJI.

Unique Fingerprints: Where CJIS Stands Alone

A few things about CJIS genuinely don’t have a clean analog anywhere else in the compliance frameworks I usually write about.

First, the fingerprinting. CJIS requires a state and national fingerprint-based record check, not just a background check in the generic sense, for personnel with unescorted access to unencrypted CJI or to a “physically secure location” during CJI processing. The policy defines a physically secure location precisely: a facility, criminal justice conveyance, or an area, room, or group of rooms within a facility, with both physical and personnel security controls sufficient to protect CJI. That definition is what makes the screening trigger concrete: whether your technician needs a fingerprint-based check turns on whether the CJI they can reach is encrypted, and whether the space they can enter meets that bar. Encrypt the data or escort the visit, and the screening obligation narrows with it — which is why the definition is worth more than a skim. For MSPs with high access to systems and facilities, this is something really worth considering.

Second, the enforcement timeline is baked directly into the policy text itself, which is unusual. Effective in version 5.9.5, and carried forward through 6.0 and 6.1, requirements marked “Existing” (carried over from version 5.9) and those marked “Priority 1” have been sanctionable since October 1, 2024. Everything marked Priority 2 through Priority 4 sits in what the policy calls a “zero cycle” status, a grace period running from October 1, 2024, through September 30, 2027. If that phased rollout structure sounds familiar, it should. It follows a similar pattern to the CMMC rollout debates I’ve written about before, except here the FBI codified the grace period inside the policy document itself rather than issuing it through separate rulemaking (i.e., 48 CFR).

Third, there’s no independent accreditation marketplace, which I mentioned above but want to underline. Local law enforcement agencies remain the ones ultimately accountable for every vendor touching their data, and they can’t really outsource some of that accountability to a third-party assessor the way an OSC can lean on a C3PAO’s certification decision. That doesn’t mean nobody assesses you, though. SA-9 requires agencies to audit every external service provider with system access at least triennially.

Fourth, the cryptography requirement gives you an option the DIB has never had. SC-13 requires either a FIPS 140-3 certified module or a FIPS-validated algorithm (FIPS 197/AES) with a symmetric key of at least 256-bit strength for CJI in transit outside a physically secure location, and SC-28 sets the same bar for CJI at rest. That “or” matters: you can reach for FIPS-validated algorithms instead, drawn from the CAVP list rather than sourcing CMVP-validated modules, which has been the bane of the DIB’s cryptographic ambitions for years. One deadline to note: SC-13 states that FIPS 140-2 certificates are not acceptable after September 21, 2026.

NOTE: Confirm this reading with the agency before you build to it. FIPS-Validated Algorithms are much easier to come by than FIPS-validated modules, so get clarity in writing before you make architectural and support decisions.

Fifth, confidentiality isn’t the only priority. Where NIST 800-171’s primary agenda was protecting the confidentiality of CUI, CJIS carries a healthy set of availability AND integrity requirements too! Things like “Water Damage Protection” from PE-15 and “System Backup” expectations from CP-9 are all in play. For companies who’ve spent a lot of time with NIST SP 800-171, DFARS 252.204-7012, and 32 CFR Part 170, looking into requirements like these that are outside of the lens of “confidentiality” might be quite startling (or fun if you’re someone like me!)

Reading MSPs Their Rights: Preparing to Support Law Enforcement

If you’re an MSP reading this because you just landed a police department, a courts client, or a 911 center, here’s your practical to do list.

  1. Confirm whether you actually touch CJI. Remote access to a records management system (RMS) or computer aided dispatch (CAD) platform counts, even if it’s occasional and even if it’s just for patching or troubleshooting. “Operates in support of” is broad on purpose.
  2. Get the CJIS Security Addendum signed with the contracting agency, not just a generic MSA. This is a legal prerequisite to access, not paperwork you can circle back to later.
  3. Fingerprint everyone who could touch CJI, including incidentally, before they touch anything. Some states run vendor management programs that consolidate this across multiple agency relationships, so it’s worth asking your contact whether one exists before sending every technician through a separate fingerprint submission for every customer.
  4. Map where CJI actually lives, physically and logically. On prem RMS server closet? Cloud hosted CAD? Backups replicated to a data center outside the agency’s four walls? Each of those locations needs to clear the physically secure location bar, and “the cloud” doesn’t get you out of that conversation. CJIS is architecture independent, meaning it doesn’t care whether your infrastructure is racked in a closet or spun up in a cloud region. The controls travel with the data.
  5. Build the technical baseline early: MFA for privileged and non-privileged accounts alike (IA-2(1) and IA-2(2), both Priority 1), plus the separate advanced authentication requirement that applies when CJI is accessed from a mobile device, FIPS validated encryption for CJI at rest and in transit, and account lifecycle automation that actually matches CJIS’s specific timers rather than your generic password policy borrowed from a different framework.
  6. Treat the Priority 1 versus zero cycle distinction as a roadmap, not a hall pass. Priority 1 controls are sanctionable now. 2027 sounds far away until you’re mid implementation with a backlog of Priority 2 through 4 items still on the list.
  7. Get Familiar with Section 5: Policy and Implementation of the CJIS Security Policy. There are a lot of requirements and many of them are, as stated before, a mish-mash of unique policy statements as well as injections of NIST SP 800-53 requirements with already specified values and thresholds for the organization-defined parameters (ODPs) from the control set. They pull 18 of the 20 families (everything but Program Management and PII Processing and Transparency) and 298 priority-marked requirements: 75 Priority 1, 153 Priority 2, 52 Priority 3, and 18 Priority 4. That’s a lot in comparison to the 110 requirements (controls) from NIST SP 800-171 Rev 2!

None of this is meant to scare you off supporting law enforcement clients. It’s genuinely rewarding work. It’s just important MSPs show up already speaking the language instead of learning it live during an audit. Get the addendum signed, get your people fingerprinted, and map your data flows before you touch a single CJI record, not after, and read up on the requirements from the CJIS Security Policy to be sure you’ve got the requirements you’re responsible for implementing in place.

Case Closed

The CJIS Security Policy isn’t nearly as widely discussed as NIST SP 800-171 or CMMC in the circles I usually write for, but for the MSPs and vendors who serve law enforcement, it’s every bit as consequential, and in a few places, more prescriptive than anything the DIB has to work with. If you’re already fluent in access control policies, audit logging, and personnel screening from your CMMC or ISO 27001 work, you have a real head start. Just don’t assume the frameworks are interchangeable, especially when it comes to physical security, fingerprinting, and the total absence of a certification you can simply buy.

If you’re an MSP trying to figure out how CJIS fits alongside a NIST 800-171 or FedRAMP Moderate Equivalency program you’re already running, or you’re just trying to figure out where to start, reach out to us through our Contact Us page at intelligrc.com/contact-us or at sales@intelligrc.com. You can also find me, Steven Molter, on LinkedIn if you want to keep the conversation going.

Happy Implementing!

Steven Molter Lead GRC Consultant and GRC Evangelist, IntelliGRC

Key Takeaways

  • Scope is broad: the CJIS Security Policy applies to any entity, including MSPs, that stores, processes, transmits, or “operates in support of” systems handling Criminal Justice Information (CJI).
  • Current version: 6.1, released June 25, 2026, building on the December 2024 (v6.0) modernization that realigned CJIS’s control structure with NIST SP 800-53 Revision 5, the same lineage behind NIST SP 800-171 and CMMC.
  • Structural overlap, broader scope: CJIS shares strong overlap with NIST SP 800-171/CMMC but adds dedicated Contingency Planning and Supply Chain Risk Management control families, plus a Mobile Devices policy area.
  • No certification marketplace: unlike CMMC or ISO 27001, CJIS has no accredited third party certification; compliance runs through a federated CJIS Systems Agency and state audit structure.
  • Fingerprinting is mandatory: state and national fingerprint based record checks are required for personnel with unescorted access to unencrypted CJI or physically secure locations.
  • Enforcement is phased and codified: “Existing” and Priority 1 requirements are sanctionable now; Priority 2 through 4 requirements sit in a zero cycle grace period through September 30, 2027.
  • The Addendum is the gate: any MSP touching CJI must have a signed CJIS Security Addendum with the contracting agency before access begins, comparable to a DFARS flow down clause or a HIPAA Business Associate Agreement.

FAQ

Does the CJIS Security Policy apply only to police departments?

No. It applies to any Criminal Justice Agency, Noncriminal Justice Agency receiving CJI/CHRI, and any contractor or vendor, including MSPs, cloud providers, and software vendors, that stores, processes, transmits, or supports systems handling CJI.

What is the current version of the CJIS Security Policy?

Version 6.1, released June 25, 2026. It builds on the version 6.0 modernization released December 27, 2024, which realigned the policy’s control structure with NIST SP 800-53 Revision 5.

Is there a “CJIS certification” an MSP can obtain like a CMMC certificate?

No. CJIS compliance is verified through the CJIS Systems Agency and State Identification Bureau structure, along with periodic audits by state authorities and the FBI’s CJIS Audit Unit, not through an accredited third party assessment organization.

Do MSP employees really need fingerprint based background checks?

Yes, for personnel with unescorted access to unencrypted CJI or to a physically secure location during CJI processing. This goes beyond a standard background check. One caveat: PS-3 exempts agencies that lack statutory authority to run civil fingerprint checks on personnel with CHRI access, until they obtain it.

How does CJIS compare to NIST SP 800-171 and CMMC?

Both trace back to the NIST SP 800-53 control catalog, so many control themes overlap: access control, audit logging, incident response, personnel security. CJIS’s modernized policy is broader in some respects (Contingency Planning, Supply Chain Risk Management, and a dedicated Mobile Devices section) and is enforced through a federated, agency based audit model rather than CMMC’s C3PAO and CyberAB marketplace.

What happens if an MSP accesses CJI without a signed CJIS Security Addendum?

It isn’t legally permitted. The addendum, grounded in 28 CFR 20.33(a)(6) and (7), is a prerequisite for any private contractor’s access to CJI, comparable in function to a DFARS 252.204-7012 flow down clause or a HIPAA Business Associate Agreement.

References

  • Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy, Version 6.1, June 25, 2026. le.fbi.gov
  • Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy, Version 6.0, December 27, 2024. le.fbi.gov
  • 28 CFR Part 20, Criminal History Record Information
  • CJIS Security Addendum (U.S. Department of Justice / FBI standardized form)
  • NIST SP 800-53 Revision 5, Security and Privacy Controls for Information Systems and Organizations
  • FIPS 140-3, Security Requirements for Cryptographic Modules; FIPS 197, Advanced Encryption Standard
  • CJIS Security Policy Appendix H, Security Addendum
  • Security and Management Control Outsourcing Standards (Channeling and Non-Channeling)
  • NIST SP 800-171 Revision 2, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
  • HIPAA Security Rule, 45 CFR Part 164, Subpart C
  • ISO/IEC 27001:2022, Information Security Management Systems