Skip to content

CJIS Compliance Checklist: What Security Policy v6.1 Requires of Vendors

A CJIS compliance checklist for vendors under Security Policy v6.1: the controls that apply, monthly scans, fix deadlines, MFA, encryption and audits.

Invadel Team12 min read

CJIS compliance means meeting the CJIS Security Policy, the FBI Criminal Justice Information Services Division’s rules for protecting criminal justice information (CJI) everywhere it is stored, processed or transmitted. For a software vendor selling to police departments, sheriffs, courts or a city IT department, it is also a sales gate: the agency cannot put CJI in your product until your controls meet the policy, your contract carries the CJIS Security Addendum and your staff with access have passed fingerprint-based background checks. This checklist covers what a vendor has to meet under version 6.1 of the policy, published by the FBI CJIS Division on June 25, 2026, with the control behind each item and whether it can be sanctioned today.

Two things up front. First, there is no CJIS certification. The FBI does not certify products or vendors; compliance is shown through agreements with each agency and audits by the state CJIS Systems Agency (CSA). Second, the policy does not require a penetration test. It requires monthly vulnerability scanning and a control assessment at least every three years, and those are where outside testing helps. Invadel runs the scanning and the testing. We are not a CJIS auditor.

What CJIS compliance means for a vendor

The policy applies to “every individual” with access to CJI or who operates in support of criminal justice services, and that includes contractors and private entities. A vendor meets it through three layers:

  • The contract. A private contractor’s agreement with the agency carries the CJIS Security Addendum (Appendix H of the policy, called for by control SA-9). It authorizes access to criminal history information, limits its use to the contracted purpose and provides for sanctions.
  • The controls. Section 5 of the policy is 20 policy areas: Information Exchange Agreements, the NIST SP 800-53 Rev. 5 control families from Access Control to Supply Chain Risk Management, and Mobile Devices. Your system has to meet the controls that apply to it.
  • The audits. The agency must audit its external service providers at least once every three years and can run unannounced inspections of their facilities (SA-9). Separately, each CSA is audited by the FBI CJIS Division every three years.

Because agreements are made state by state, large cloud providers sign the Security Addendum with each state’s CSA. Microsoft’s CJIS page is a useful model of what that looks like, and it says plainly that the FBI does not certify a provider’s CJIS compliance.

What changed in versions 6.0 and 6.1

Version 6.0, released December 27, 2024, completed the policy’s modernization: the old 13 policy areas were rebuilt around NIST SP 800-53 Rev. 5 controls. Version 6.1 adds the changes the Advisory Policy Board approved during 2025. If you have a FedRAMP or other 800-53 program, most control names will look familiar, but the CJIS values (lockout counts, timers, deadlines) are its own.

The part vendors miss is the priority marking on each control:

  • Requirements that existed before modernization (marked Existing) and those marked Priority 1 have been the sanctionable set since October 1, 2024.
  • New requirements marked Priority 2, 3 or 4 sit in a “zero-cycle” that runs from October 1, 2024 to September 30, 2027. Plan to have them in place before it ends.

One date has already passed. Control SC-13 says FIPS 140-2 certificates are not acceptable after September 21, 2026. Encryption modules protecting CJI now need FIPS 140-3 certification, or the data must be encrypted with FIPS 197 AES and a key of at least 256 bits. Newer versions of approved modules that are under review for FIPS 140-3 can be used until their certification is complete.

The CJIS compliance checklist

Each row is one of the CJIS requirements a vendor meets on its own system, with the control from version 6.1 and its status. “Now” means the requirement is Existing or Priority 1 and can be sanctioned today. “By 9/2027” means it is in the zero-cycle.

# Requirement Control Status
1 CJIS Security Addendum in the contract with each agency SA-9 Now
2 State and national fingerprint-based record checks before anyone gets access to CJI PS-3 Now
3 Tell the agency within 24 hours when staff with credentials or privileges leave or transfer PS-7 Now
4 Security literacy training before access to CJI and annually after AT-2 Now
5 Multi-factor authentication for privileged and non-privileged accounts IA-2(1), IA-2(2) Now
6 Check passwords against a list of common and compromised passwords, updated and compared quarterly; minimum 8 characters when user-chosen IA-5(1) Now
7 Lock the account after 5 invalid logons in 15 minutes, until an administrator releases it AC-7 Now
8 Lock devices after at most 30 minutes of inactivity AC-11 Now
9 Disable accounts within one week once inactive for 90 days, expired or no longer tied to a person AC-2(3) Now
10 Review every account at least annually AC-2 Now
11 Encrypt CJI in transit outside a physically secure location: FIPS 140-3 certified modules or FIPS 197 AES, with a key of at least 256 bits SC-8, SC-13 Now
12 Encrypt CJI at rest outside a physically secure location to the same standard SC-28 Now
13 Store CJI in the cloud only within APB-member countries (the United States, its territories, Indian Tribes and Canada) SC-28 Now
14 Do not use metadata derived from unencrypted CJI for advertising or other commercial purposes SC-8, SC-28 Now
15 Review and analyze audit records weekly AU-6 Now
16 Keep audit records for at least one year AU-11 Now
17 Scan the system and hosted applications for vulnerabilities at least monthly, and when new vulnerabilities are reported RA-5 Now
18 Remediate within 15 days (critical), 30 (high), 60 (medium) and 90 (low) RA-5, SI-2 Now
19 Publish a channel for outside researchers to report vulnerabilities RA-5(11) Now
20 Keep a component inventory recording installation date, model, serial number, supplier and software version, among other fields CM-8 Now
21 Run a continuous monitoring strategy with the metrics the policy lists CA-7 Now
22 Report suspected incidents immediately, and never later than one hour after discovery IR-6 By 9/2027
23 Test incident response annually (tabletop, walk-through or simulation) IR-3 By 9/2027
24 Review and update the risk assessment at least quarterly RA-3 By 9/2027
25 Assess the controls at least once every three years, with independent assessors CA-2, CA-2(1) By 9/2027
26 Replace components their vendor no longer supports, or arrange continued support from the original manufacturer or vendor SA-22 By 9/2027
27 Test and evaluate your own software, with a verifiable flaw remediation process SA-11 By 9/2027

The policy is the minimum. Section 1.3 lets agencies and states set stricter requirements, so read the security terms in each contract as well.

Does CJIS require a penetration test?

No. Version 6.1 has no penetration testing control; the NIST control for it (CA-8) is not in the policy. Penetration testing comes up only in passing: as one approach to testing custom software in the discussion under SA-11, and as testing the FBI itself may carry out, on its own network from a CSA’s interfaces and on fingerprint channelers that access CJI directly. None of it puts a testing duty on a software vendor.

What the policy does require, and where testing earns its place:

  • Monthly scanning (RA-5) is Priority 1 and sanctionable now. It is the recurring evidence an auditor asks to see.
  • A control assessment every three years (CA-2) must be planned, approved by the authorizing official before it starts, and run by assessors independent of the system. A penetration test is not a control assessment, but it is strong evidence that access control, authentication and boundary protection work against a real attacker.
  • Developer testing (SA-11) asks you to test your own software and fix what you find, and names penetration testing, code review and static and dynamic analysis as ways to do it.

Our guide to penetration testing vs vulnerability scanning explains what each one finds, and why a CJIS program needs the scanning either way.

Monthly scanning under RA-5

RA-5 is short, but it is specific. To meet it, a vendor needs to:

  1. Scan the whole system at least monthly, including hosted applications, and again when a relevant new vulnerability is announced.
  2. Update the scanner’s checks within 24 hours before each scan (RA-5(2)).
  3. Scan with privileged access where the check requires it (RA-5(5)). Authenticated scans find the missing patches and weak settings an unauthenticated pass cannot see.
  4. Analyze the results, rather than filing the raw export.
  5. Fix within the deadlines: 15 days for critical, 30 for high, 60 for medium, 90 for low. SI-2 applies the same deadlines to installing security updates.
  6. Share what you learn with the people who run the other systems, so the same flaw is fixed everywhere.

Keep each month’s report, the ticket for every finding with its open and close dates, and a plan of action for anything that misses its deadline. Our guide to vulnerability remediation covers how to run that loop without missing dates.

We run this as a service. A validated vulnerability scan is $1,500 for up to 250 devices and $2,500 for up to 1,000, with an analyst removing false positives and ranking what is left. A monthly cadence runs as a recurring vulnerability management program at those published per-scan prices.

The three-year control assessment under CA-2

CA-2 asks for more than a test. The assessment needs a plan that names the controls in scope, the procedures and the team, and that plan is approved before work begins. The result is a written report, delivered to the person who signed the CJIS User Agreement or holds the contract with the FBI. CA-2(1) requires independent assessors: people who did not build or run the system and have no stake in the result.

Testing fits in two places. Before the assessment, an external network penetration test (from $4,200) and a web application penetration test of the product agencies log into (from $5,200) show whether the controls in the checklist hold up, while there is still time to fix them. During it, the dated report, the remediation evidence and the retest give the assessor proof that the controls work, not only that they are documented. Both prices are fixed in writing before work starts and include a free retest.

A 90-day plan for a vendor starting out

Days 1 to 30: scope and paperwork. Map where CJI enters, is stored and leaves your product, including backups, logs and support tools. Identify the contracting agency and its CSA, get the Security Addendum into the contract, and start background checks and security training for everyone who will have access, since both must be complete before anyone touches CJI. Confirm your cloud region keeps CJI inside APB-member countries.

Days 31 to 60: identity and encryption. Turn on MFA for every account that can reach CJI. Set lockout to 5 attempts in 15 minutes, the device lock to 30 minutes and automatic disabling at 90 days of inactivity. Check that every encryption module protecting CJI holds a FIPS 140-3 certificate, or that you use FIPS 197 AES with a 256-bit key. Run your first monthly scan and open tickets against the deadlines.

Days 61 to 90: monitoring and response. Start weekly log review and keep a year of records. Write the incident response plan around the one-hour reporting rule, and run a tabletop. Schedule the annual training refresh, publish your vulnerability reporting channel (a policy page like ours is enough), and close the first month’s findings.

Then book the penetration test far enough ahead of the agency’s audit to fix and retest what it finds.

Frequently asked questions

Is there a CJIS certification? No. The FBI does not certify vendors or products. Compliance is established through the Security Addendum in each agency contract, agreements with the state CSA and the audits that follow. Be wary of anyone selling a “CJIS certified” badge.

Does CJIS require penetration testing? Not by name. Version 6.1 has no penetration testing control. It requires monthly vulnerability scanning (RA-5) and a control assessment at least every three years (CA-2), and a penetration test is useful evidence for both. Agencies can also set stricter requirements in their contracts.

How often do we have to scan for vulnerabilities? At least monthly, and whenever a new vulnerability that could affect the system is reported. Critical findings must be fixed within 15 days, high within 30, medium within 60 and low within 90.

Who audits a CJIS vendor? The agency, or the CSA acting for it, must audit external service providers at least every three years and can inspect their facilities without notice. The FBI CJIS Division audits each CSA on a three-year cycle.

Can CJI be stored in a commercial cloud? Yes, if the data centers are inside APB-member countries (the United States, its territories, Indian Tribes and Canada) and under the legal authority of an APB-member agency, with CJI encrypted outside physically secure locations using FIPS 140-3 certified modules or FIPS 197 AES, with a key of at least 256 bits.

Will your testers need access to CJI? It is better if they do not. Testing a staging environment that mirrors production, with no live CJI in it, keeps the test from adding people to your CJI access list. Where only production will do, the agency’s screening rules apply, so agree the approach with the agency during scoping, before testing starts.

Can Invadel run our CJIS audit? No. Audits are run by the agency or its CSA, and the control assessment by independent assessors you appoint. We supply the monthly scans and the penetration test evidence those reviews rely on, at published prices and independent of your assessment.

Fixed price, fixed scope, free retest. Scope your scanning or test and get the price in writing.

Written by

Invadel Team

Senior penetration testers writing from real engagements, the same team that scopes, tests, and reports for our clients. About Invadel →

Find out what an attacker sees.

Tell us what to test and see your fixed price.

Prefer the full scoping questionnaire? 
Start the conversation