Do you create, store, open, or send Criminal Justice Information (CJI)? Then the U.S. Department of Justice (DoJ) Security Policy applies to you. You must comply.
CJIS compliance guards sensitive data. That means case records, fingerprints, mugshots, and other personally identifiable information. The rules reach well past police work. They cover:
Non-criminal justice agencies (NCJAs) must comply too. NCJAs include firms that run background checks or handle immigration cases. State licensing boards, 911 dispatch centers, adoption agencies, school boards, and even banks also make the list.
These groups do not fight crime. But they can see criminal records. So the same rules bind them.
Penalties for noncompliance are severe. They can include:
Does that sound like your world? Are you a third-party supplier to one of these groups? Then this guide is for you.
It will help you spot where CJI touches your environment. It shows you how to build the people, process, and technology controls the CJIS Security Policy demands. It also gets you ready for the audits that follow.
The FBI CJIS Division owns the policy. That policy is the launch pad for every step you take next.
The CJIS Security Policy governs the full life of two data types. The first is Criminal Justice Information (CJI). The second is criminal history record information (CHRI).
The CJIS Audit Unit (CAU) reviews a sample of agencies every three years. That sample covers Criminal Justice Agencies (CJAs) and Non-Criminal Justice Agencies (NCJAs) alike.
A CJIS readiness assessment starts the work. Essendis compliance experts check where you stand on the current 217 CJIS requirements. NIST assessment guidance shapes that review. The four-week process hands CJAs and NCJAs a detailed gap analysis. You also get a readiness report to share with leaders and other stakeholders.
The CJIS Security Policy (CJISSECPOL) sets the floor for security. It covers how you make, change, send, share, store, view, and destroy CJI.
Below is a typical path through the process. It maps to CJISSECPOL Version 5.9.5. Each step lists what to do, why it matters, and what you get.
CJIS rules apply to anyone who handles CJI. That includes third-party contractors and cloud vendors. Get this step right, or every later step inherits a scoping error.
Write a one-page CJIS scope statement. List every system, data flow, and owner.
CJIS compliance needs a clear chain of roles. You need one at every level: local, state, and federal. Key roles include:
The Deliverable
A governance org chart and contact list. It names your state CJIS and State Identification Bureau contacts.
The inventory drives risk management. It tells you which security controls to set up. It also clears up vendor roles and gets you ready for audit.
Tag each part as CJI in-scope or CJI out-of-scope.
The Deliverable
A full CJI inventory plus a simple network and data flow diagram.
Pull the latest CJIS Security Policy checklist. Map each required control to what you have. Versions matter here. The current version is 5.9.5, and policy changes can swing your audit result.
Now run three reviews. Check the technology: authentication, encryption, and logging. Check the data policies. Check the people. Each review surfaces gaps and weak spots.
Score every gap by risk and by effort. Those scores build a ranked fix list. The list feeds incident response and moves you from reactive to structured security.
The Deliverable
A ranked gap remediation plan. It maps a clear road to the strict demands of CJISSECPOL.
This step is about formal policies and tight document control. You write them, review them, and get them signed off.
Cover every required security policy area, including:
Keep each policy short and clear. Put it under version control. Then get the right leader to approve it.
Map each policy to the CJIS Security Policy sections it serves. A traceability matrix does that job. It shows an auditor how you meet and enforce each rule.
The Deliverable
An indexed, versioned CJIS policy binder. It gives you an enforceable frame for CJI governance and backs you up at audit.
Strong personnel controls keep CJI in the right hands. Only cleared people should reach it.
Every person with CJI access needs a CJIS background check and fingerprints. State and local rules set the details.
Grant access by role. Use least privilege, so each person gets only the access the job needs.
Every CJI user must finish CJIS security awareness training. Log each completion and keep the record for audit.
The Deliverable
A personnel access roster. It carries trackable proof of background checks and training.
Next, tighten who can log in to systems that hold or process CJI.
Turn on multifactor authentication (MFA) for privileged users. Do the same for anyone with remote access to CJIS environments.
Run identity from one place. A SAML or SSO solution keeps sign-on consistent across systems.
Then guard the credential life cycle. Set up new users, review access on a schedule, and cut off accounts the moment a role changes or the need ends.
The Deliverable
An authentication architecture diagram with proof that MFA is live.
Next, protect CJI across the whole environment.
Encrypt CJI in transit with TLS versions that meet CJIS guidance. Encrypt it at rest where policy or system design calls for that.
Segment the network to fence CJI off from the rest. Firewalls, access control lists (ACLs), and other boundary guards enforce strict traffic rules.
Harden every endpoint that touches CJI. Use standard config baselines, full-disk encryption, and anti-malware. Add endpoint detection and response (EDR) where you can.
The Deliverable
A full network segmentation plan and a device hardening checklist.
Logs prove accountability. They also feed CJIS oversight.
Turn on audit logging for all CJI access. Each log must show who touched the data and what they did. It must also show when that happened and where it came from, by location and device.
Keep logs in one place. Use a secure log platform or a SIEM. Match retention to CJIS and to state or local guidance.
Then write audit response playbooks. They spell out how to gather, protect, and hand over evidence when the CAU asks.
The Deliverable
A logging architecture, a CJI retention policy, and an audit report bundle you can run on demand.
Set a fixed cadence for vulnerability scans and patching on all CJI systems. Tie that cadence to your change control approvals.
The link keeps risks tracked, fixed, and shipped in a controlled way.
Write an emergency change process too. It needs approvals, rollback steps, and re-testing after the fact. That keeps systems sound when a fix cannot wait.
The Deliverable
An enforceable VM scan schedule, a patching policy, and CMDB entries for CJI systems.
Every vendor and service provider must back your CJIS work. They must comply too.
Put CJIS language in every contract. Spell out the right to audit, data handling and retention, encryption standards, and background checks for their people.
Cloud providers must meet the CJIS controls that apply. Build a shared responsibility matrix so both sides know who owns what.
Do you use a regional or state CJIS host, such as Nlets or a state-run CJIS system? Then collect their compliance attestations and audit reports. Keep them on file as proof.
The Deliverable
A finished vendor compliance questionnaire and signed addenda.
Write a CJIS-specific incident response (IR) playbook. It sets out how to isolate a system and preserve evidence. It also names who to notify: the CJIS Systems Agency (CSA) and the CJIS Audit Unit.
Test the playbook each year with a tabletop exercise. Write down the results and the gaps. Feed the lessons back in. That sharpens response, keeps you aligned with the rules, and shows you are ready.
The Deliverable
An incident response runbook, a step-by-step technical guide, plus exercise reports. Those reports record each process, prove it works, and stand as audit evidence.
Run internal self-assessments on a regular basis. They keep you aligned with CJISSECPOL.
Keep all your proof in one audit binder. That means policies, procedures, training records, and access rosters. It also means config screenshots, log exports, and vendor compliance records.
Review the binder often to stay ready. Best practice is a full check each year, backed by quarterly spot checks. Early warning keeps small gaps small.
The Deliverable
A detailed audit binder and a remediation tracker. Together they prove due diligence, show accountability, and speed up the audit.
Watch for change all year. CJISSECPOL evolves, and the Advisory Policy Board issues updates.
Track policy versions as they ship. Start by subscribing to CJIS Division updates and other law enforcement channels. Then read the guidance they send.
Use a formal changelog and a risk-based review. It helps you weigh, rank, and adopt new or revised CJIS controls. Day-to-day work stays on track.
The Deliverable
A change log and a subscription to CJIS updates. CJISSECPOL is a living document. You own the job of spotting changes and acting on them to stay compliant.
CJIS compliance guards national security. It also protects the civil rights of people and businesses. And it shields the sensitive data that law enforcement and other agencies collect, process, store, and share.
Endpoints are now the hard part. Third-party providers, remote work, and BYOD have spread data across more devices than ever. Complex data flows widen the risk of a gap or an unplanned access path.
Essendis runs readiness assessments to speed your path to CJIS compliance. We work with companies of every size and scope. Our advice fits your environment, keeps costs down, and limits disruption.
In the readiness assessment, Essendis CJIS compliance experts check where you stand on the current 217 CJIS requirements. NIST assessment guidance shapes the review.
The work takes about four weeks. You then get a detailed gap analysis with the next steps to take before the official audit. You also get a readiness report with an executive summary. It suits every audience, from the C-suite on down.
A Secure Enclave suits some organizations. It walls CJI off in its own segregated system. You avoid a rebuild of the whole IT environment.
That fits when only a small share of your people or systems handle CJI. Talk to an Essendis expert to see if a Secure Enclave is right for you.
At Essendis, we know how much CJI compliance means to your business continuity. Our approach finds the weak spots across your whole organization. You get the insight and the expertise to stay secure and compliant against today’s threats.
Maybe you are launching a new business. Maybe you face your first audit, weigh new contracts, or just want to get ahead. We can help.
Our advisors take time to learn your business, your processes, and your people. We walk you through the compliance process. We explain what we do and how we do it, in plain English.
The readiness assessment moves fast. The findings may call for deeper work to make results stick. Your Essendis team stays with you the whole way, through every part of the change.
Getting started is easy. Send us a few basic details about your business. We will reply as soon as we have reviewed them.
Connect with an advisor today. Take the first step toward lasting CJIS compliance.

