Defense & controlled data

FBI CJIS Security Policy

The CJIS Security Policy sets the minimum security controls for handling criminal justice information (CJI), covering access control, encryption, auditing, and personnel screening.

Official source (opens in a new tab): FBI Criminal Justice Information Services (CJIS) Security Policy

Scope

Who it applies to.

The CJIS Security Policy sets the minimum controls for Criminal Justice Information (CJI). By its own terms it “applies to every individual—contractor, private entity, noncriminal justice agency representative, or member of a criminal justice entity—with access to, or who operate in support of, criminal and noncriminal justice services and information.” Section 1.2 extends it to all entities that process, store, or transmit CJI. A private contractor reaches CJI only under an agreement incorporating the FBI-approved CJIS Security Addendum (Appendix H).

Fingerprint-based personnel screening
PS-3 requires screening before access is authorized: state-of-residency and national fingerprint-based record checks, conducted under an FBI-approved authority such as a federal statute or a state statute approved pursuant to Public Law 92-544. If a felony conviction of any kind exists, the agency shall deny access. Agencies must keep a current list of everyone with unescorted access to unencrypted CJI.
Multi-factor authentication
IA-2 requires unique identification and authentication of organizational users. Enhancement (1) mandates multi-factor authentication for privileged accounts and enhancement (2) for non-privileged accounts — both marked Priority 1, the sanctionable tier. The older “advanced authentication” terminology survives for CJI accessed from mobile devices at § 5.20.7.2, where CSO-approved compensating controls may substitute.
Encryption of CJI in transit
SC-13 requires FIPS 140-3 certified cryptographic modules, or a FIPS-validated algorithm (FIPS 197 / AES) with a symmetric cipher key of at least 256-bit strength, for CJI in transit outside a physically secure location. Version 6.1 raised that in-transit key strength from 128-bit. FIPS 140-2 certificates are not acceptable after September 21, 2026.
Encryption of CJI at rest
SC-28 requires CJI at rest outside physically secure locations to be protected using FIPS 140-3 certified modules with a symmetric cipher key of at least 256-bit strength. Metadata derived from unencrypted CJI must be protected the same way and may not be used for advertising or commercial purposes by any cloud provider. Cloud-stored CJI must reside within an APB-member country.
The CJIS Security Addendum for contractors
SA-9 requires providers of external system services to comply with the policy. Private contractors performing criminal justice functions must meet the same training and certification criteria as government staff, are “subject to the same extent of audit review as are local user agencies,” and each employee signs the Security Addendum Certification page. Only the FBI may modify the Addendum.
Triennial audits & inspections
Under SA-9, agencies must permit an inspection team to audit any alleged security violation, must at minimum triennially audit every external service provider with access to the system, and may conduct unannounced security inspections of provider facilities. Each CSA, Interface Agency, or SIB also completes a triennial audit of the agencies beneath it and is itself audited triennially by the CJIS Division.

The vendor & sub-processor obligation

What it puts on you.

Any provider with access to CJI — including cloud and support staff — must meet personnel-screening and access requirements, which means certifying and overseeing each vendor and their personnel who could reach the data.

How self-hosting addresses it

Remove the third party, remove the burden.

Operating on a self-hosted system where only your screened personnel can reach CJI keeps the data within a controlled boundary, rather than extending screening and oversight to an outside provider’s staff.

How FileFerret applies

Running search and AI on an appliance inside the agency’s own physically secure location means that in normal operation no outside provider’s staff gain unescorted access to unencrypted CJI — nothing to bring under the Security Addendum, and no external service provider to audit triennially. Support access the agency invites is different: if an engineer can view unencrypted CJI, PS-3 screening and the Addendum reach them. The policy’s own controls still apply to the appliance. See how it’s built →

Full, current text is maintained at the official source: FBI Criminal Justice Information Services (CJIS) Security Policy.

Enforcement

Who enforces it, and how.

Oversight runs through the shared-management structure: the CJIS Systems Agency (CSA) and its CJIS Systems Officer (CSO) approve access and monitor compliance, and the FBI’s CJIS Audit Unit audits on a triennial cycle. There is no statutory fine schedule. The CJIS User Agreement provides for non-monetary sanctions, and the APB or Compact Council may approve sanctions “to include the termination of CJIS services.” Improper access or dissemination can additionally draw state and federal criminal penalties (§ 4.2.5.2).

Common questions

Questions firms ask.

Can a cloud service provider host CJI?

Yes, if it can meet the requirements. Appendix G.3 answers the question directly: because the policy is device- and architecture-independent, the answer is yes — “assuming the vendor of the cloud technology is able to meet the existing requirements.” Storage must sit within an APB-member country, and anyone holding the encryption keys counts as having unescorted access to unencrypted CJI.

Does every vendor employee need a fingerprint-based check?

The Personnel Security section applies to all personnel with unescorted access to unencrypted CJI — logical or physical — and says so regardless of whether the implementation is a physical data center, a virtual cloud solution, or a hybrid. If a provider’s staff can view, modify, or make use of unencrypted CJI, PS-3 reaches them. The agency determines who falls inside that line.

Which version of the policy applies to a contract we signed earlier?

Version 6.1 (06/25/2026) is current, but the Security Addendum binds a contractor to “the CJIS Security Policy in effect when the contract is executed and all subsequent versions.” Since October 1, 2024, the sanctionable set is requirements that existed before modernization plus those marked Priority 1. Your CJIS Systems Agency sets the baseline an audit is actually conducted against.

More in Defense & controlled data

Related guides.

CMMC certification & assessments

Defense contractors handling Controlled Unclassified Information (CUI) must implement the security controls in NIST SP 800-171, with CMMC 2.0 adding assessment and certification to prove it.

ITAR (22 CFR 120-130)

The International Traffic in Arms Regulations control defense articles and technical data.

← All compliance guides

Modern software, kept inside your walls.

Tell us about your organization and the data you need to protect. We’ll help you put capable, modern tools to work on a private system we ship, install, and support — with nothing ever leaving your network.