CJIS Security Addendum: Signing, Background Checks, and Audits

Compliance with the CJIS Security Addendum requirements means signing the FBI-approved contract and then actually meeting the CJIS Security Policy behind it: fingerprint-based background checks and security awareness training for every person with access, FIPS-validated encryption, multi-factor authentication, controlled physical spaces, one-hour incident reporting, media sanitization, and full audit access for the FBI and the state CJIS Systems Agency. Without a signed addendum, a private contractor cannot legally touch criminal history records, fingerprint data, or anything else flowing through the FBI’s criminal justice databases.1eCFR. 28 CFR 20.33 – Dissemination of Criminal History Record Information

Who Has to Sign

The addendum applies to any private business, organization, or individual that enters an agreement to perform criminal justice functions for a criminal justice agency or a non-criminal justice agency.2Federal Bureau of Investigation. CJIS Security Addendum That sweeps in IT vendors supporting police departments, cloud providers hosting records, software developers building applications that touch CJIS databases, and technicians maintaining hardware in facilities where the data is accessible.

Coverage runs deep, not just wide. It extends to all personnel, systems, networks, and support facilities working on behalf of the agency.2Federal Bureau of Investigation. CJIS Security Addendum A help-desk technician who could remotely view a screen showing criminal records is in scope, not just the engineers who built the system. Cloud service providers face the same screening and agreement requirements as any other private contractor. The policy is architecture-independent, so moving to the cloud doesn’t change what you owe.3Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0

The technical rulebook behind the contract is the CJIS Security Policy. The current version is 6.0, effective December 27, 2024, and a contractor commits to the version in effect when the contract is executed.3Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0

Background Checks for Every Person With Access

Every person who might access criminal justice information must clear a state and national fingerprint-based background check before getting access. Fingerprints are typically collected at a local law enforcement agency, though some states allow electronic submission through authorized channelers. The FBI charges $18 for its portion; state fees vary.4Federal Bureau of Investigation. Identity History Summary Checks FAQs

A felony conviction of any kind results in denial by default. The requesting agency can petition the CJIS Systems Officer for a variance review in extenuating circumstances, but that is a narrow exception. Misdemeanors are not automatically disqualifying; the reviewing official weighs the nature and severity of the offense. Active warrants or unresolved arrest history are handled case by case.3Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0

Security Awareness Training

Everyone with access to criminal justice information, including anyone with unescorted physical access to a secure location where the data is stored, must complete CJIS Security Awareness Training within six months of initial assignment and renew it every two years. Local Agency Security Officers must train before assuming duties (or within six months at the latest) and renew annually.5Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy Keep records of who trained and when; auditors check.

Encryption, Authentication, and Physical Security

Encryption

Criminal justice information must be encrypted in transit and at rest whenever it leaves a physically secure location, using cryptographic modules certified to FIPS 140-3. Data in transit requires a symmetric key of at least 128-bit strength (AES). Data at rest requires 256-bit AES or an equivalent FIPS 140-3 method.6Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v5.9.5

Mark September 21, 2026 on the calendar. FIPS 140-2 certificates go historical on that date and can no longer be used for new federal acquisitions, so any contractor still on FIPS 140-2 validated modules needs to migrate before then. For cloud arrangements, watch key management: anyone holding decryption keys effectively has unescorted access to unencrypted criminal justice information, which triggers the full background-check and training obligations.3Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0

Multi-Factor Authentication

Multi-factor authentication has been required since Policy version 5.9.2.7NIST. MFA for CJIS – NIST IR 8523 It applies to remote access and to access from any location that doesn’t qualify as physically secure. Username and password alone will not clear the bar; authentication must combine at least two distinct factors.

Physical Safeguards

Server rooms, data centers, and any location housing systems that store or process criminal justice information must have restricted physical access, monitored entry points, visitor controls, and environmental protections. A server room that uncleared personnel can walk into is a compliance failure regardless of how strong the encryption is.

One-Hour Incident Reporting

Suspected security incidents must be reported immediately, and no later than one hour after discovery.3Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0 The clock starts at discovery, not confirmation. Waiting to investigate or to hold a meeting isn’t an option. The Contracting Government Agency reports violations to both the CJIS Systems Officer and the FBI Director, including what happened and what is being done about it.2Federal Bureau of Investigation. CJIS Security Addendum Have an incident response plan ready before you start work. Building one after a breach is too late.

Audits You Agree To By Signing

Signing the addendum grants both the FBI CJIS Division and the state CJIS Systems Agency the right to audit your facilities and systems, including unannounced inspections. Auditors verify that controls are actually in place and working, not just documented. Passing today doesn’t close the door; the FBI can return at any time.6Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v5.9.5

Areas commonly examined include:

  • Access control, including account management, least privilege, and remote access
  • Audit and accountability, including event logging and log review
  • Encryption and boundary protection for data in transit and at rest
  • Personnel security screening records for anyone with unescorted access to unencrypted data
  • Configuration management, including baselines, change control, and system inventories
  • Physical and environmental protection
  • Incident response planning and handling
  • Contingency planning, backups, and recovery testing

Media Disposal

Digital media containing criminal justice information cannot simply be deleted and thrown out. It must be overwritten at least three times or degaussed before disposal or reuse. Inoperable media that can’t be overwritten must be physically destroyed. Paper and microfilm must be crosscut shredded or incinerated.3Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0

Keep written documentation of the sanitization or destruction steps, and make sure the work is witnessed or performed by authorized personnel.8Federal Bureau of Investigation. Media Protection Policy This covers hard drives, USB devices, and the scanners, copiers, and printers that hold data in memory.

Subcontractors and Data Use

Access is limited to the contractor’s officers and employees who need it to perform services for the sponsoring agency. Data cannot be passed to a subcontractor or fourth party unless that subcontractor meets the same requirements: background checks, training, and the full set of security controls. Using criminal history records for marketing, research, or any commercial purpose outside the contract is prohibited.9Federal Bureau of Investigation. Legal Authority for and Purpose and Genesis of the Security Addendum

What Non-Compliance Costs

Security violations can justify termination of the entire contract. On notice of a violation, the FBI reserves the right to suspend or terminate access and services, including the telecommunications links connecting the contractor to CJIS systems. Access is only restored after both the Contracting Government Agency and the contractor provide satisfactory assurances that the violation has been addressed.2Federal Bureau of Investigation. CJIS Security Addendum

Losing the contract isn’t the ceiling. Improper access, use, or dissemination of criminal history record information can trigger state and federal criminal penalties on top of administrative sanctions.3Federal Bureau of Investigation. Criminal Justice Information Services (CJIS) Security Policy v6.0 When a contract ends, the contractor must delete or return all records containing criminal history information to the Contracting Government Agency.2Federal Bureau of Investigation. CJIS Security Addendum

Signing and Submitting the Addendum

The addendum must be signed by someone with legal authority to bind the contractor, typically a CEO, president, or senior director, and by a corresponding authority at the government agency. The Security Addendum Certification Page requires the contractor’s full legal name, physical address, and the Originating Agency Identifier of the partnering agency.

The completed package goes to the State CJIS Systems Officer for review. That officer confirms background checks are current and training certifications meet federal standards before granting formal approval. Some states accept digital submission through a designated portal; others require physical copies. Processing timelines vary, so build lead time into project schedules rather than assuming approval will be immediate.