- What Is CJIS? The FBI Division, the Security Policy, and What It Requires
- What CJIS Stands For, and What It Actually Means
- CJIS, CJI, and CHRI
- The FBI CJIS Division
- What the CJIS Security Policy Requires
- Who Must Comply With CJIS
- The 20 Policy Areas, and Why Most Articles Say 13
- Where the Policy Stands Right Now
- How to Simplify CJIS Compliance
- Key Takeaways
- CJIS Frequently Asked Questions
What Is CJIS? The FBI Division, the Security Policy, and What It Requires
Criminal Justice Information Services (CJIS) is the FBI division that operates the national criminal justice databases. It also publishes the security standard governing how everyone else handles that data.
CJIS compliance means complying with the CJIS Security Policy, the document that sets the minimum controls for protecting criminal justice information. The current version is 6.1, published June 25, 2026.
This guide covers what CJIS is, who must comply, and what the policy requires. It also covers how the current version differs from the one most articles still describe.
What CJIS Stands For, and What It Actually Means
CJIS stands for Criminal Justice Information Services, the FBI division that runs the national criminal justice databases. In practice, “CJIS” usually means the CJIS Security Policy: the minimum security requirements any agency, contractor, or vendor must meet to handle criminal justice information. The current version is 6.1, published June 25, 2026.
Criminal Justice Information Services (CJIS) is the FBI’s Criminal Justice Information Services Division and the security policy it publishes. The Division runs the national databases that law enforcement queries every day. The policy sets the minimum controls any agency, contractor, or vendor must meet to handle that data.
The Division is an organizational unit of the FBI. It runs the national systems that law enforcement and authorized civil agencies query every day. It provides those systems to state, local, tribal, territorial, and federal agencies.
The Security Policy is a document the Division publishes. Its full name is the Criminal Justice Information Services Security Policy, abbreviated CJISSECPOL. It sets the security requirements that any organization touching criminal justice information must meet.
So, when an agency says it “needs CJIS,” a vendor says a product is “CJIS ready,” it is making a claim about the policy. But when an auditor arrives, they are auditing against the policy itself. And auditing and any certification decisions sit with state agencies.
CJIS, CJI, and CHRI
CJIS, CJI, and CHRI describe three different things, and mixing them up produces real compliance errors.
- CJIS (Criminal Justice Information Services) is the FBI division and the security policy it publishes, governed by the FBI CJIS Division, with the Advisory Policy Board and the Compact Council.
- CJI (Criminal Justice Information) is governed by the CJIS Security Policy and includes all FBI CJIS-provided data agencies need to perform their missions, including biometric, identity history, biographic, property, and case/incident data.
- CHRI (Criminal History Record Information): is a restricted subset of CJI, sometimes called “restricted data,” that is governed by the CJIS Security Policy plus Title 28, Part 20 of the Code of Federal Regulations.
The practical difference is the handling rule. All CJI must be protected under the policy. Because of its sensitivity, CHRI carries extra restrictions on access, use, and dissemination.
CHRI used for noncriminal justice purposes — background checks for employment or licensing, for example — picks up a second layer of oversight. The National Crime Prevention and Privacy Compact Council governs that interstate exchange, and each participating state designates a State Compact Officer. An agency running employment background checks is subject to both the policy and the Compact Council’s rules.
The FBI CJIS Division
The FBI CJIS Division operates the national criminal justice information systems and makes them available to authorized agencies. Appendix D of the current policy lists six systems and major programs the Division makes available:
- LEEP: Law Enforcement Enterprise Portal, the access gateway for federated services.
- NCIC: National Crime Information Center, the national index of wanted persons, stolen property, and related files.
- NICS: National Instant Criminal Background Check System, used for firearm transfer checks.
- N-DEx: National Data Exchange, which shares incident and case records across agencies.
- NGI: Next Generation Identification, the biometric identification system.
- UCR: Uniform Crime Reporting, the national crime statistics program.
But the Division does not govern policy alone. Instead, it operates a shared management model with state and federal criminal justice agencies.
Established in March 1994, the CJIS Advisory Policy Board (APB) recommends policy through subcommittees and working groups. An advisory board for NCIC has existed since 1969. The policy is prepared by the FBI CJIS Information Security Officer and approved by the APB and the Compact Council.
What the CJIS Security Policy Requires
The CJIS Security Policy sets minimum security requirements for protecting criminal justice information across its entire lifecycle. The lifecycle it covers is explicit:
- Creation
- Viewing
- Modification
- Transmission
- Dissemination
- Storage
- Destruction
Protection applies to data at rest and data in transit, inside and outside physically secure locations.
“Minimum” means the policy is a floor that agencies and states can build above. A state CJIS Systems Agency may impose more stringent or additional protection measures, and the policy requires those decisions to be documented and kept current. An agency that satisfies the federal text has satisfied only the federal text. Whether it satisfies its state depends on what its state added.
The stated legal basis is the Federal Information Security Modernization Act of 2014. The policy cites it as further legal grounding for the APB-approved requirements that protect CJI.
Who Must Comply With CJIS
CJIS applies to every individual with access to criminal justice information, or who operates in support of criminal and noncriminal justice services. That includes contractors, private entities, noncriminal justice agency representatives, and members of criminal justice entities.
But the scope is broader than most vendors expect. A hosting provider that never reads CJI but stores it is in scope. A support technician with administrative access to a system that processes CJI is in scope. Physical access counts too: unescorted access to a location where CJI is processed brings training and screening requirements with it.
The policy assigns responsibility through a defined role structure:
- CJIS Systems Agency (CSA) — establishes and administers the security program across its user community, usually a state police agency or department of public safety
- CJIS Systems Officer (CSO) — appointed by the head of the CSA, administers the CJIS network and holds ultimate responsibility for the security of CJIS systems in that state
- Terminal Agency Coordinator (TAC) — the point of contact at each local agency
- Criminal Justice Agency (CJA) and Noncriminal Justice Agency (NCJA) — the two categories of user agency
- Contracting Agency and Agency Coordinator — where functions are outsourced
- Organizational Personnel with Security Responsibilities — the agency-level security role
Private contractors are bound through the CJIS Security Addendum, a standard agreement that extends the policy’s obligations to the contractor and its personnel.
The 20 Policy Areas, and Why Most Articles Say 13
The current CJIS Security Policy has 20 policy areas. Articles citing 13 are describing version 5.9, published in June 2020 and superseded in December 2024.
Version 6.0 restructured the policy onto NIST SP 800-53 control families. That restructure produced the current count:
| # | Policy area | NIST 800-53 family |
|---|---|---|
| 1 | Information Exchange Agreements | — |
| 2 | Access Control | AC |
| 3 | Awareness and Training | AT |
| 4 | Audit and Accountability | AU |
| 5 | Assessment, Authorization, and Monitoring | CA |
| 6 | Configuration Management | CM |
| 7 | Contingency Planning | CP |
| 8 | Identification and Authentication | IA |
| 9 | Incident Response | IR |
| 10 | Maintenance | MA |
| 11 | Media Protection | MP |
| 12 | Physical and Environmental Protection | PE |
| 13 | Planning | PL |
| 14 | Personnel Security | PS |
| 15 | Risk Assessment | RA |
| 16 | System and Services Acquisition | SA |
| 17 | System and Communications Protection | SC |
| 18 | System and Information Integrity | SI |
| 19 | Supply Chain Risk Management | SR |
| 20 | Mobile Devices | — |
Areas 2 through 19 are the eighteen NIST 800-53 control families, in order. Areas 1 and 20 have no direct NIST equivalent and retain the older “policy area” framing.
For a team that already runs a NIST 800-53 or NIST CSF program, the control set will look familiar. One caveat is that CJIS prescribes specific parameter values where 800-53 leaves them organization-defined.
Where the Policy Stands Right Now
The most current version of CJIS is Version 6.1, dated June 25, 2026. Version 6.0, dated December 27, 2024, is superseded.
| Version | Date | What it did |
|---|---|---|
| 5.9 | June 1, 2020 | The 13-policy-area structure most online content still describes |
| 6.0 | December 27, 2024 | Policy Modernization Completion: restructured onto NIST 800-53 families, producing 20 areas |
| 6.1 | June 25, 2026 | Incorporate Calendar Year 2025 Changes: a corrections release |
But enforcement runs on a separate clock. Requirements marked [Existing] or [Priority 1] have been the sanctionable set since October 1, 2024. Requirements marked [Priority 2] through [Priority 4] sit in a zero cycle that runs from October 1, 2024 to September 30, 2027. During that window, findings are recorded but not sanctioned. Non-modernized sections carry no marking at all and remain auditable.
How to Simplify CJIS Compliance
For agencies and vendors working through CJIS, the work is proving that each control is met across every system and agency in scope, with evidence a state auditor can trace.
Isora GRC is the GRC Assessment Platform™ that gives security teams one connected workspace to run assessments, manage vendors and assets, track risks, and prove compliance.
Assessment Management. Teams run structured assessments against the control set their program already uses, distribute them across departments and agencies, and track completion from one dashboard.
Reports & Scorecards. Reports pull straight from live assessment data, so an auditor can trace any finding back through the response, the evidence, and the mapped control in one place.
Inventory Management. A single inventory of systems, vendors, and applications shows what falls in scope for CJI, and each record links to its assessments and risks.
Evidence is captured as the work happens, so audit prep becomes a reporting task.
See the GRC Assessment Platform™ in action →
Key Takeaways
CJIS is two things wearing one name: the FBI division that runs the national criminal justice systems, and the security policy that division publishes. Almost every practical question about “CJIS compliance” is a question about the policy.
The most useful move for most teams is to check which version their program is mapped to. The policy restructured in December 2024 and now has 20 policy areas, not 13. Areas 2 through 19 are the eighteen NIST 800-53 control families, which means an existing NIST program transfers structurally, with CJIS-prescribed parameter values to verify. Requirements marked Priority 1 have been sanctionable since October 2024.
See the GRC Assessment Platform™ in action →
CJIS Frequently Asked Questions
What does CJIS stand for?
CJIS stands for Criminal Justice Information Services. It is the FBI division that operates the national criminal justice systems, including the National Crime Information Center and Next Generation Identification. The name is also used informally to mean the CJIS Security Policy.
What is the CJIS Security Policy?
The CJIS Security Policy is the FBI’s minimum security standard for protecting criminal justice information across its full lifecycle, from creation and viewing through modification, transmission, dissemination, storage, and destruction. It applies whether the data is at rest or in transit. Agencies and state CJIS Systems Agencies may impose stricter requirements on top of it.
How many CJIS policy areas are there?
The current policy, version 6.1, has 20 policy areas. Area 1 covers Information Exchange Agreements, areas 2 through 19 are the 18 NIST SP 800-53 control families, and area 20 covers Mobile Devices. Articles citing 13 policy areas are describing version 5.9, published in June 2020.
What is the current version of the CJIS Security Policy?
Version 6.1, dated June 25, 2026. It replaced version 6.0 of December 27, 2024. Version 6.1 is a corrections release that incorporates calendar-year 2025 changes rather than restructuring the policy.
Who has to comply with CJIS?
Every individual with access to criminal justice information, or who operates in support of criminal and noncriminal justice services. That includes contractors, private entities, and noncriminal justice agency representatives. Private contractors are bound through the CJIS Security Addendum.
What is the difference between CJIS, CJI, and CHRI?
CJIS is the FBI division and its security policy. CJI is criminal justice information, meaning the data itself. CHRI is criminal history record information, a restricted subset of CJI. It carries additional handling rules and, for noncriminal justice use, oversight from the Compact Council.
Is there a CJIS certification?
No, there is no FBI-issued organizational CJIS certificate. Agencies are audited against the CJIS Security Policy by their state CJIS Systems Agency, typically on a three-year cycle. Individuals complete security awareness and role-based training, which the policy defines by named role rather than numbered level.
This content is for informational purposes only and does not constitute legal or compliance advice. See our full disclaimer.