CJIS Requirements: The 20 Policy Areas and the Values CJIS Fixes
CJIS requirements are the minimum security controls that systems and people handling Criminal Justice Information (CJI) must meet under the FBI’s CJIS Security Policy. The current version, 6.1, was released on June 25, 2026.
Under v6.1, CJIS requirements fall into 20 policy areas, 18 of which correspond to National Institute of Standards and Technology (NIST) Special Publication 800-53 control families. But where NIST SP 800-53 Revision 5 lets each organization define its own control parameters, CJIS sets fixed values for many of them.
Alongside the 20 policy areas, the 178 NIST-numbered base controls, and the CJIS-specific values, this guide covers current enforcement dates, audit consequences, and the evidence organizations need to document compliance.
The CJIS Requirements, by Policy Area
CJIS requirements are the minimum security controls for agencies, contractors, systems, and personnel that access or support Criminal Justice Information (CJI). The FBI defines these requirements in the CJIS Security Policy, establishing a minimum security baseline across participating jurisdictions.
CJIS requirements are the FBI’s mandatory baseline for agencies, contractors, and systems that access or support CJI. Version 6.1 combines information-exchange and mobile-device rules with eighteen NIST-aligned control families, then fixes thresholds and review cycles that NIST leaves open.
Within each state, a CJIS Systems Agency (CSA) controls access to CJIS systems and CJI, and may add stricter requirements on top of the FBI’s baseline. To stay compliant, agencies and contractors must follow both the federal policy and their state’s rules.
The current CJIS Security Policy, Version 6.1, organizes its requirements into 20 policy areas, grouped as follows:
- Area 1: Information exchange agreements
- Areas 2–19: The 18 NIST 800-53 control families covering core security functions
- Area 20: Mobile-device requirements
Under NIST 800-53, the organization’s own choices set the benchmark for assessment. In a CJIS audit, auditors compare those same settings against the values CJIS requires. Existing NIST work still gives teams a head start, but each configured value needs its own CJIS check.
To meet CJIS requirements, teams still need to:
- Verify that their configured values meet the CJIS-specific requirements in areas 2–19.
- Address the information exchange and mobile device requirements in areas 1 and 20 separately.
CJIS Requirements Across the 20 Policy Areas
| # | Policy area | What it requires |
|---|---|---|
| 1 | Information Exchange Agreements | Written agreements authorizing each exchange, reviewed at least triennially, specifying security requirements and the information’s impact level |
| 2 | Access Control (AC) | Account management, least privilege, session and device lock, remote access controls, and review of publicly accessible content |
| 3 | Awareness and Training (AT) | Literacy training for all users and role-based training for named roles, before access and annually |
| 4 | Audit and Accountability (AU) | Events that must be logged, log retention, and review of audit records on a defined cycle |
| 5 | Assessment, Authorization, and Monitoring (CA) | Control assessments, information exchange authorization, plans of action and milestones, and continuous monitoring |
| 6 | Configuration Management (CM) | Baseline configurations, change control, least functionality, and software usage restrictions |
| 7 | Contingency Planning (CP) | Contingency plans, training, testing, backups, and recovery |
| 8 | Identification and Authentication (IA) | Authenticator management, multi-factor authentication for privileged and non-privileged organizational accounts, and re-authentication |
| 9 | Incident Response (IR) | Response capability, incident handling, monitoring, and reporting to named recipients |
| 10 | Maintenance (MA) | Controlled maintenance, maintenance tools, nonlocal maintenance, and personnel authorization |
| 11 | Media Protection (MP) | Media access, marking, storage, transport, sanitization, and disposal |
| 12 | Physical and Environmental Protection (PE) | Physically secure locations, access authorization and control, monitoring, and visitor access records |
| 13 | Planning (PL) | System security plans, rules of behavior, and security architecture |
| 14 | Personnel Security (PS) | Screening before access, transfer and termination procedures, and sanctions |
| 15 | Risk Assessment (RA) | Security categorization, risk assessment, vulnerability monitoring and scanning, and risk response |
| 16 | System and Services Acquisition (SA) | Acquisition processes, developer requirements, and external system services |
| 17 | System and Communications Protection (SC) | Boundary protection, cryptographic protection, and protection of information at rest |
| 18 | System and Information Integrity (SI) | Flaw remediation, malicious code protection, system monitoring, and information handling |
| 19 | Supply Chain Risk Management (SR) | Supply chain plans, supplier assessments, and component authenticity |
| 20 | Mobile Devices | Additional requirements that apply when CJI leaves a physically secure location |
Some policy areas need closer attention because they add fixed values, recurring checks, or requirements that a typical technical-control program may not cover:
- Access Control and Authentication (Areas 2 and 8): CJIS sets exact values for failed logon attempts, device locks, and reauthentication. It also requires multi-factor authentication (MFA) for both privileged and non-privileged organizational accounts.
- Awareness and Training (Area 3): Everyone with system access needs training before they start and every year after, including managers, executives, and contractors. People with specific security roles also need additional role-based training.
- Audit and Accountability (Area 4): CJIS requires teams to review audit records weekly and to alert designated personnel within one hour if the logging process fails. Retaining logs without reviewing them does not satisfy the control.
- Personnel Security (Area 14): CJIS sets clear procedures for transfers, terminations, and personnel sanctions. For example, agencies must screen people and conduct a fingerprint-based record check where applicable, before granting access.
- Physical and Environmental Protection (Area 12): CJIS defines how agencies authorize, monitor, and document access to physically secure locations, including quarterly visitor-record reviews. As a result, teams need facility records and access logs alongside technical evidence for an audit.
- Incident Response (Area 9): Agencies must report suspected incidents within one hour of discovery. The policy asks teams to then route the details to the designated incident-handling personnel, the applicable CJIS official, and the FBI CJIS Information Security Officer.
- Risk Assessment (Area 15): At least monthly, teams must monitor and scan systems for vulnerabilities, along with risk assessment and response activities. An existing NIST program may need a shorter scanning cycle to meet that schedule.
- Information Exchange Agreements (Area 1): Agencies must document every CJI exchange in a written agreement that defines the security terms and information impact level. and review it at least once every three years. They must also review each agreement at least once every three years.
- Mobile Devices (Area 20): CJIS adds safeguards for mobile devices that handle CJI outside physically secure locations.
Because Areas 1 and 20 are unique to CJIS and fall outside the 18-family NIST mapping, a NIST crosswalk won’t cover them. Teams must review both areas separately from their NIST controls.
The remaining families cover configuration management, contingency planning, maintenance, media protection, planning, system and services acquisition, system and communications protection, system and information integrity, and supply chain risk management. Although their structure follows NIST 800-53, individual CJIS controls within them may still add mandatory values or implementation details.
The FBI CJIS Security Policy Resource Center publishes the current policy, the Requirements Companion Document, and other supporting materials.
Standard, Framework, Regulation, or Policy?
The CJIS Security Policy is a policy. It is not a law or certification standard. It sets the minimum security requirements for protecting CJI through agreements and audits.
- Agencies comply through agreements with their state CJIS Systems Agency (CSA), along with user agreements that authorize system access.
- Contractors comply through the CJIS Security Addendum, which sets out the same obligations.
There is no official CJIS certification, and no third party can grant one on the FBI’s behalf. Instead, organizations show compliance through audits. State CSAs audit agencies in their jurisdictions, while the FBI audits each CSA and a sample of local agencies on a three-year cycle.
How CJIS Differs From NIST 800-53
CJIS sets mandatory values for certain controls that NIST lets organizations define on their own. Across areas 2–19, however, it uses the same 18 control-family structure as NIST. From those families, CJIS selects 178 NIST-numbered base controls, plus control enhancements, and assigns each one a priority level that determines when it becomes auditable.
The NIST-based structure arrived with version 6.0 in December 2024, replacing the thirteen policy areas in version 5.9. Version 6.1 then kept the new structure and incorporated the FBI’s approved 2025 changes. Our CJIS Security Policy guide covers the broader policy and the full modernization timeline.
The One Control With No NIST Equivalent
CJIS v6.1 also includes IA-0, a control with no NIST equivalent. This extra control requires each CJIS transaction to use an FBI-authorized Originating Agency Identifier so the agency behind the transaction can be identified and given the correct access.
Because IA-0 has no NIST number, a NIST 800-53 crosswalk won’t flag it. And teams starting with an existing NIST 800-53 control need to apply IA-0 as a additional CJIS requirement.
Where CJIS Prescribes a Value and NIST Does Not
CJIS specifically sets thresholds, deadlines, and review cycles for parameters such as logon-attempt limits, device-lock periods, training schedules, and account-removal deadlines. In most cases, these values simply complete or tighten an existing control rather than creating a new one.
NIST 800-53, on the other hand, uses organization-defined parameters, so many of its controls describe what to do but leave the exact value to each organization. NIST SP 800-53A then provides customizable procedures to check whether those controls are implemented correctly and operating as intended. Those checks measure against the organization’s chosen values, not the ones CJIS requires.
So, while a passed NIST assessment confirms if the control works, it does not confirm the value meets CJIS.
The table below compares what NIST 800-53 leaves open with what CJIS prescribes.
| Control | What NIST leaves open | What CJIS prescribes |
|---|---|---|
| AC-7 Unsuccessful Logon Attempts | The attempt count and time window | Five consecutive invalid attempts in a 15-minute period, followed by a lock until an administrator releases it |
| AC-11 Device Lock | The inactivity period | 30 minutes |
| AC-22 Publicly Accessible Content | The review frequency | Quarterly |
| IA-5 Authenticator Management | Length, composition, and rotation | At least 8 characters when user-chosen and 6 when generated by an approved random generator Compare the banned-password list quarterly Rate-limit failed attempts to five |
| IA-11 Reauthentication | The session limit | At least every 12 hours during an extended session |
| AT-2 / AT-3 Training | The frequency | Before access and annually, plus within 30 days of a security incident for involved personnel |
| PE-8 Visitor Access Records | The review frequency | Quarterly |
| SI-2(2) Flaw Remediation Status | The check frequency | At least monthly and after qualifying security incidents |
| AC-2(2) Temporary and Emergency Accounts | The removal deadline | Within 72 hours |
As the first row illustrates, an organization can implement AC-7 under its NIST program, pass assessment, and still fail CJIS if its threshold allows ten failed logon attempts instead of five. Having the control alone doesn’t make an organization CJIS compliant. Even NIST-compliant teams need to check that their settings match CJIS values.
A NIST-to-CJIS mapping exercise, therefore, has to compare parameter values alongside control coverage.
Compare CJIS values across all 18 NIST control families.
Identify which existing NIST controls already support CJIS, which settings need adjustment, and which CJIS-specific requirements need separate work.
Which CJIS Requirements Are Enforceable Right Now
As of September 2026, auditors can sanction agencies for gaps in two places:
- Existing requirements: those carried over from earlier versions of the policy
- Priority 1 requirements: new requirements given top priority in CJIS Security Policy v6.1
Priority 2, 3, and 4 requirements are in a “zero cycle” through September 30, 2027. Until then, auditors can still review them and note gaps, but agencies won’t face sanctions for them.
| Marking | FBI policy status |
|---|---|
| Existing requirements and Priority 1 requirements | Sanctionable under the FBI’s modernization schedule |
| New Priority 2, Priority 3, and Priority 4 requirements | In a zero cycle through September 30, 2027 |
| Non-modernized, unmarked sections | Treated as existing requirements and remain auditable and sanctionable |
Whether a control is sanctionable depends on its priority level, and whether the requirement already existed in version 5.9. Check the FBI’s Requirements Companion Document to find the audit or sanction date for each requirement.
The FBI’s schedule doesn’t expect every CJIS Systems Agency to switch to the same audit baseline on the same day. Instead, it asks each CSA to manage its own transition within the federal requirements and to add stricter local rules. For example, the Texas Department of Public Safety will keep auditing against version 5.9.5 through March 31, 2027, while Texas agencies prepare for v6.1.
To be safe, organizations should confirm the current audit baseline with their applicable CJIS Systems Agency before planning an audit. Our CJIS compliance guide covers that program-level work in more detail.
What Happens When Requirements Are Not Met
When an audit finds a gap, the agency must respond with a documented corrective action plan. If the gap stays unresolved, or involves serious misuse, it can lead to sanctions. According to FBI’s corrective-action guidance, every finding needs a response that explains what will change, who owns it, the schedule, and the expected resolution. If full implementation will take longer, the agency can provide target dates with interim measures in the meantime.
FBI auditors often test how controls work in practice through administrative interviews, physical-security reviews, and network inspections. Under the FBI’s Information Technology Security Audit methodology, each audit report must identify required compliance actions and track remediation. As a result, evidence must exhibit that controls are actually operating across the full scope of their CJI environment.
A finding doesn’t automatically lead to a penalty. After an audit, the FBI CJIS Audit Unit first issues recommendations and tracks corrective actions until they are complete.
If sanctions are necessary, then the review path depends on how the organization uses CJI. The APB Compliance Evaluation Subcommittee reviews findings involving criminal justice use, while the Compact Council Sanctions Committee handles noncriminal justice use. In both cases, the committee reviews the audit results and the organization’s response before deciding what action, if any, is needed.
Beyond committee review, user agreements also allow the FBI to impose administrative sanctions, up to and including termination of services. The Security Addendum lets the FBI suspend or terminate a contractor’s access and services. Separately, improper access, use, or dissemination of CJI can carry legal consequences, including under the dissemination rules in Title 28, Part 20 of the Code of Federal Regulations.
How to Simplify CJIS Requirements
The simplest way to manage CJIS requirements is to keep every control connected to its required value, response, owner, and supporting evidence. However, a single program can involve 178 base controls, prescribed values, staggered audit dates, and multiple agencies and contractors, which can scatter evidence and blur ownership, especially if its maintained across separate spreadsheets and documents.
Isora GRC gives security teams one connected workspace to run assessments, collect evidence, manage risks, and report on CJIS requirements. The GRC Assessment Platform™ keeps each response, finding, owner, and supporting record connected from assessment through remediation. Teams can start with Isora’s prebuilt NIST questionnaire content and add the CJIS-specific requirements, or build a CJIS assessment from scratch.
See the GRC Assessment Platform™ in action →
Assessment Management
Coordinate each CJIS assessment by routing requirements to the right control owners and following every response through completion. In Isora, live progress and scoring data bring overdue work, missing evidence, and unresolved findings into one view across agencies, systems, and contractors.
Learn more about Assessment Management with Isora GRC →
Questionnaires & Surveys
Turn each CJIS requirement into a structured question, route it to the people closest to the control, and collect evidence with every response. In Isora, teams can start with prebuilt NIST questionnaire content, add CJIS-specific requirements, collaborate across one questionnaire, and keep evidence attached to the control it supports.
Learn more about Questionnaires & Surveys with Isora GRC →
Risk Management
Convert CJIS assessment findings into risks, assign owners and remediation milestones, and track each gap through closure. In Isora, every risk remains connected to the original questionnaire item, mapped control, framework requirement, and assessment objective.
Learn more about Risk Management with Isora GRC →
Reports & Scorecards
Build CJIS audit reports from current assessment data, compare results across agencies or contractors, and trace each finding to its response and evidence. In Isora, reports update as assessment data changes and export to PDF or CSV for auditors, leadership, and oversight bodies.
Learn more about Reports & Scorecards with Isora GRC →
Key Takeaways
CJIS v6.1 organizes its security requirements into 20 policy areas, with eighteen based on NIST 800-53 control families and two unique to CJIS. Across those families, the policy prioritizes 178 NIST-numbered base controls, plus one CJIS-only control, IA-0.
Teams with an existing NIST program should compare each implemented control against CJIS-specific values, including failed-logon limits, device-lock timeouts, review frequencies, account-removal deadlines, and training intervals. A control can pass a NIST assessment and still produce a CJIS finding when one of those values is wrong. On top of that, teams must assess Areas 1 and 20 separately, because the information-exchange and mobile-device requirements fall outside the NIST control-family mapping.
The FBI’s schedule shows which requirements are sanctionable now, and each CSA’s audit baseline shows which version audits actually use, so organizations should verify both. Isora GRC can connect assessments, evidence, exceptions, risks, and reports once the applicable requirements and dates are established.
See how Isora GRC supports CJIS compliance →
CJIS Requirements FAQs
What are the CJIS requirements?
CJIS requirements are the minimum security controls in the FBI’s CJIS Security Policy for systems and people handling criminal justice information. Version 6.1 organizes them into 20 policy areas. Eighteen align with NIST SP 800-53 control families, and the other two cover information exchange agreements and mobile devices.
Is CJIS a framework, a standard, or a regulation?
CJIS is a policy that sets minimum security requirements. Agencies enforce it through CJIS user agreements and the applicable state CJIS Systems Agency, while contractors operate under the CJIS Security Addendum. State CSA and FBI audits assess compliance, and no official CJIS certification exists.
How many CJIS controls are there?
The v6.1 List of Priorities contains 178 NIST-numbered base controls across eighteen families, plus control enhancements. CJIS-specific IA-0 is an additional existing requirement outside that count, while areas 1 and 20 add requirements outside the NIST family structure.
Which CJIS requirements are enforceable right now?
The FBI treats can sanction agencies for gaps in existing and Priority 1 requirements. New Priority 2 through Priority 4 requirements remain in the zero cycle through September 30, 2027. Because active baselines can vary by CJIS Systems Agency, organizations should confirm the version their jurisdiction assesses.
How is CJIS different from NIST 800-53?
CJIS uses eighteen NIST 800-53 control families but assigns mandatory values to many organization-defined parameters. For example, CJIS limits unsuccessful logons to five attempts within fifteen minutes before an administrator must release the lock.
What happens if an organization violates CJIS requirements?
A CJIS violation can result in an audit finding and required corrective action. If the organization does not restore compliance, it may face administrative sanctions, including loss of CJIS access or services. Improper access, use, or dissemination of criminal history information may also carry state or federal criminal penalties.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.
Dive into our research-backed resources–from product one pagers and whitepapers, to webinars and more–and unlock the transformative potential of powerfully simple GRC.
Learn More