Framework · Last verified
FBI CJIS Security Policy
The FBI CJIS Security Policy sets security rules for Criminal Justice Information; compliance runs through a signed Security Addendum, not a certificate. The current version is v6.1 (25 June 2026), and it reaches criminal justice agencies, noncriminal justice agencies and their private contractors alike.
- Class
- Framework
- Owner
- Federal Bureau of Investigation (FBI), Criminal Justice Information Services (CJIS) Division
- Last verified
What it is
The current version of the policy, per its own file name and page footer, is "CJISSECPOL v6.1", dated 06/25/2026. It governs Criminal Justice Information (CJI), which the policy defines as "the term used to refer to all of the FBI CJIS provided data necessary for law enforcement and civil agencies to perform their missions including, but not limited to biometric, identity history, biographic, property, and case/incident history data."
The policy defines a Criminal Justice Agency (CJA) as "a court, a governmental agency, or any subunit of a governmental agency which performs the administration of criminal justice pursuant to a statute or executive order," and separately addresses Noncriminal Justice Agencies (NCJAs) and Contracting Agencies (CAs) that access CJI.
Private contractors reach CJI through a CJIS Security Addendum, which the policy defines as "a uniform addendum to an agreement between the government agency and a private contractor, approved by the Director of the FBI... which specifically authorizes access to CHRI, limits the use of the information... provides for sanctions." The policy states: "Private contractors who perform criminal justice functions shall meet the same training and certification criteria required by governmental agencies... and shall be subject to the same extent of audit review as are local user agencies. All private contractors... shall acknowledge, via signing of the CJIS Security Addendum Certification page (page H-8), compliance with all aspects of the CJIS Security Addendum."
There is no single, central "CJIS Certified" organizational certification issued by the FBI. Compliance is established through three mechanisms named in the policy itself: signing the Security Addendum, audit review carried out by the local CJIS Systems Agency (CSA) or criminal justice agency (CJA) rather than an independent accredited third party, and personnel training/certification.
Who owns it
The policy is issued by the FBI's Criminal Justice Information Services (CJIS) Division.
Who assesses it
The policy states private contractors "shall be subject to the same extent of audit review as are local user agencies" — an audit review carried out by the local CJIS Systems Agency (CSA) or criminal justice agency (CJA), not by an independent third-party certification body of the kind used in FedRAMP or HITRUST.
Who asks for it
Statutory (scoped). The obligation runs to criminal justice agencies (CJAs), noncriminal justice agencies with CJI access (NCJAs), contracting agencies and private contractors who access Criminal Justice Information (CJI) under a signed CJIS Security Addendum — not to businesses generally. There is no single central "CJIS certified" organizational certification: compliance runs through the Security Addendum plus audit review by the local CJIS Systems Agency (CSA) or criminal justice agency (CJA), not a third-party accredited certification body.
The obligation reaches criminal justice agencies directly and reaches private contractors through the CJIS Security Addendum: the policy states such contractors "shall acknowledge, via signing of the CJIS Security Addendum Certification page (page H-8), compliance with all aspects of the CJIS Security Addendum."
Sources
- FBI CJIS Security Policy, v6.1 (25 June 2026) ↗ — accessed
- FBI — CJIS Security Policy Resource Center ↗ — accessed
Last verified:
This page is for information only; it does not accredit, certify or endorse any organisation. Requirements and programs change — always confirm against the primary source linked above.