ACCESS
Not your job title
CJIS applies to every entity that creates, stores, accesses, or transmits CJI — including non-justice agencies, vendors, MSPs, and IT admins. It's enforced individually, too.
The FBI's CJIS Security Policy applies to anyone who touches criminal justice information — agencies, courts, and the vendors and IT staff behind them. And with version 6.0, it's shifting from a checklist to continuous, audit-ready accountability. We map your scope, close the gaps, and get you ready for the audit.
Book a CJIS Strategy Call →// WHY CJIS, WHY NOW
ACCESS
CJIS applies to every entity that creates, stores, accesses, or transmits CJI — including non-justice agencies, vendors, MSPs, and IT admins. It's enforced individually, too.
MFA
Every account that touches criminal justice information must use multi-factor authentication — with the policy pointing to NIST 800-63 for phishing-resistant methods.
v6.0
Version 6.0 shifts agencies from point-in-time checklists to continuous governance and audit-ready accountability, with full expected compliance by October 1, 2027.
// "WE'RE JUST THE VENDOR" ISN'T A SHIELD
CJIS is access-based: it doesn't care whether you're a police department or a contractor's after-hours admin — if you can create, store, access, or transmit criminal justice information, you're in scope. That means background screening, security awareness training, and MFA for the actual people with access, not just a policy on the agency's shelf. Vendors and MSPs who assume CJIS is "the agency's problem" become the finding in the agency's audit — and lose the contract. We make sure your access is defensible before the auditor maps it.
// WHAT v6.0 ACTUALLY CHANGES
The controls aren't being thrown out — they're being held to a higher standard. The shift to continuous, audit-ready accountability is the heart of version 6.0, and it changes how every control area below is judged.
The defining change in version 6.0: CJIS moves from point-in-time checklist compliance to continuous governance, risk management, and audit-ready accountability, with full expected compliance by October 1, 2027. You're no longer proving you were compliant on audit day — you're proving you stay compliant. The three control areas below are the substance; this is the standard they're now held to.
// IDENTITY & ACCESS
MFA & Authentication
Mandatory MFA on every account reaching CJI, identity proofing, and NIST 800-63 phishing-resistant methods.
// THE CONTROL SET
Policy Areas
Access control, incident response, monitoring, supply-chain risk, and system controls across the CJI lifecycle.
// PEOPLE & AUDIT
Personnel & Audit
Background screening, security awareness training, and the recurring CSA audit you're measured against.
Architecture-independent — the policy applies on-prem, cloud, or hybrid alike.
// THE PATH
How agencies and vendors build a defensible CJIS posture. The amber stages are the oversight-facing moments — the CSA audit, and the continuous accountability v6.0 now expects between them.
Scope
Map CJI & Access
WK 1–3
Assess
Gap vs 5.9.5 & 6.0
WK 3–6
Identity
MFA & Access Control
MO 1–3
Implement
Controls & Personnel
MO 3–6
Audit
CSA / FBI Review
ON CYCLE
Sustain
Continuous Accountability
ONGOING
Amber stages are the oversight-facing moments — the recurring audit your CJIS Systems Agency and the FBI conduct, and the continuous accountability version 6.0 expects you to sustain between audits. Everything before is the work that makes the review routine.
// IS THIS YOU?
// 01 // JUSTICE AGENCY
You're law enforcement, a court, or a government body handling CJI, and the v6.0 modernization is reshaping what your next audit will expect.
// 02 // SUPPORTING VENDOR
You're a vendor, MSP, or contractor whose people can reach CJI. You're in scope — and the agency's audit can turn on your controls.
// 03 // CHECKLIST MINDSET
Your compliance is a document you dust off before audits. Version 6.0's continuous accountability won't accept that posture much longer.
// WHAT WE DO
// Phase 01 · Scope
We map where CJI lives and who can reach it, then assess your posture against the current 5.9.5 policy and the modernized 6.0 — so you know exactly what today's audit and tomorrow's expect.
// Phase 02 · Implement
We implement mandatory MFA and access controls, build the personnel-security and training program, and put the policy-area controls in place across on-prem, cloud, and hybrid systems.
// Phase 03 · Sustain
We prepare you for the CSA audit and stand up the continuous monitoring and documentation that version 6.0 expects — so accountability is ongoing, not a pre-audit scramble.
// THE BINDER ERA IS ENDING
// FREQUENTLY ASKED
Quite possibly, because CJIS is access-based, not title-based. The policy doesn't care about your job title or department name; it cares about whether you create, store, access, or transmit Criminal Justice Information. That sweeps in far more than police and courts: non-justice government agencies, IT administrators, managed service providers, cloud and software vendors, and even on-call support staff who can reach systems holding CJI.
CJI itself is broad — criminal history records, arrest and warrant data, fingerprints and mugshots, jail and inmate records, dispatch logs, and court records tied to criminal cases. Compliance is enforced at the individual level, not just organizationally, so the people with access must meet requirements like background screening, security awareness training, and strong authentication. If you support law enforcement in any way through technology, records, or infrastructure, assume CJIS likely applies and confirm it deliberately.
They represent the current state and near future, and you need both. Version 5.9.5 (July 2024) is the policy that audits are currently conducted against, so it's your primary reference today. Version 6.0 (December 2024) is a major modernization — roughly half new content — that shifts CJIS away from point-in-time, checklist compliance toward continuous governance, risk management, and audit-ready accountability, revising areas like assessment and authorization, continuous monitoring, personnel security, and supply chain risk.
Agencies are expected to meet the modernized requirements by October 1, 2027, with enforcement milestones phasing in before then, so the right posture is to keep meeting 5.9.5 while running gap assessments against 6.0. CJIS is also moving to a faster rhythm — version 6.1 is expected in 2026, with updates roughly every six to twelve months — which is itself a reason to treat compliance as an ongoing program, not a periodic project.
Yes. MFA is no longer optional: every account that accesses Criminal Justice Information must use it, so a stolen or guessed password alone cannot grant access to CJI. The policy doesn't lock you into a single product, but it points to NIST SP 800-63 Digital Identity Guidelines, which describe phishing-resistant authentication — an important nuance, because not all MFA is equally strong against modern credential-phishing.
Alongside MFA, the modernized policy tightens authenticator hygiene, including a banned or commonly-compromised password list and rules on how often certain authenticators must change. For most agencies and vendors, the challenge isn't understanding that MFA is required — it's implementing it consistently across every system and account that can reach CJI, including service accounts, admin access, and third-party connections, without breaking the workflows officers and staff depend on. That complete coverage is what an auditor looks for.
CJIS is not a certification you earn once; it's a security policy you're audited against on a recurring basis. Oversight is tiered: the FBI's CJIS Division sets the national policy, and within each state a CJIS Systems Agency (CSA) administers access to FBI criminal justice information and ensures the agencies and vendors under it comply. Audits are typically conducted on a recurring cycle — commonly every three years — by the FBI and the state CSA, assessing whether your technical, administrative, and physical controls actually meet the policy in practice.
Because version 6.0 emphasizes continuous accountability rather than a point-in-time snapshot, the expectation is increasingly that you can demonstrate compliance at any time, not just the week before an audit. That's why the durable approach is to build CJIS into ongoing operations — identity, monitoring, personnel security, and documentation maintained continuously — so an audit becomes a confirmation of what you already do. We help agencies and vendors reach that state and prepare for the CSA audit itself.
// THE NEXT MOVE
Book a 30-minute CJIS strategy call with a WatchUr6 advisor. Bring whether you're an agency or a vendor, where criminal justice information lives in your environment, and when your next CSA audit falls. You'll walk away knowing your scope, your gaps against 5.9.5 and 6.0, and a path to continuous compliance — whether you hire us or not.
Book a CJIS Strategy Call →SDVOSB · DVBE · SBE · CMAS #3-25-06-1018 · CAGE 9CQZ9 · VETERAN-LED