Framework · Last verified

FBI CJIS Security Policy

The FBI CJIS Security Policy sets security rules for Criminal Justice Information; compliance runs through a signed Security Addendum, not a certificate. The current version is v6.1 (25 June 2026), and it reaches criminal justice agencies, noncriminal justice agencies and their private contractors alike.

Class
Framework
Owner
Federal Bureau of Investigation (FBI), Criminal Justice Information Services (CJIS) Division
Last verified

What it is

The current version of the policy, per its own file name and page footer, is "CJISSECPOL v6.1", dated 06/25/2026. It governs Criminal Justice Information (CJI), which the policy defines as "the term used to refer to all of the FBI CJIS provided data necessary for law enforcement and civil agencies to perform their missions including, but not limited to biometric, identity history, biographic, property, and case/incident history data."

The policy defines a Criminal Justice Agency (CJA) as "a court, a governmental agency, or any subunit of a governmental agency which performs the administration of criminal justice pursuant to a statute or executive order," and separately addresses Noncriminal Justice Agencies (NCJAs) and Contracting Agencies (CAs) that access CJI.

Private contractors reach CJI through a CJIS Security Addendum, which the policy defines as "a uniform addendum to an agreement between the government agency and a private contractor, approved by the Director of the FBI... which specifically authorizes access to CHRI, limits the use of the information... provides for sanctions." The policy states: "Private contractors who perform criminal justice functions shall meet the same training and certification criteria required by governmental agencies... and shall be subject to the same extent of audit review as are local user agencies. All private contractors... shall acknowledge, via signing of the CJIS Security Addendum Certification page (page H-8), compliance with all aspects of the CJIS Security Addendum."

There is no single, central "CJIS Certified" organizational certification issued by the FBI. Compliance is established through three mechanisms named in the policy itself: signing the Security Addendum, audit review carried out by the local CJIS Systems Agency (CSA) or criminal justice agency (CJA) rather than an independent accredited third party, and personnel training/certification.

Who owns it

The policy is issued by the FBI's Criminal Justice Information Services (CJIS) Division.

Who assesses it

The policy states private contractors "shall be subject to the same extent of audit review as are local user agencies" — an audit review carried out by the local CJIS Systems Agency (CSA) or criminal justice agency (CJA), not by an independent third-party certification body of the kind used in FedRAMP or HITRUST.

Who asks for it

Statutory (scoped). The obligation runs to criminal justice agencies (CJAs), noncriminal justice agencies with CJI access (NCJAs), contracting agencies and private contractors who access Criminal Justice Information (CJI) under a signed CJIS Security Addendum — not to businesses generally. There is no single central "CJIS certified" organizational certification: compliance runs through the Security Addendum plus audit review by the local CJIS Systems Agency (CSA) or criminal justice agency (CJA), not a third-party accredited certification body.

The obligation reaches criminal justice agencies directly and reaches private contractors through the CJIS Security Addendum: the policy states such contractors "shall acknowledge, via signing of the CJIS Security Addendum Certification page (page H-8), compliance with all aspects of the CJIS Security Addendum."

Sources

Last verified:

This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.

Cite this page

Attributing this record helps other researchers verify it independently.

"FBI CJIS Security Policy." Certifidex, FutureTechnologies. Last verified 31 August 2026. https://certifidex.com/frameworks/cjis

All frameworks & audits →