To become a fingerprinting service provider, you register a legal business, pass a personal criminal background check, sign the FBI’s CJIS Security Addendum, buy FBI-certified Live Scan equipment, set up a facility that meets physical security standards, and apply to your state’s identification bureau for vendor authorization. If you also want to deliver FBI identity history results directly to customers, you apply separately to become an FBI-approved channeler. Everything else in the process, from staff training to audit logs, flows from those two authorization tracks.
Choose Your Authorization Track
Most providers start with state vendor authorization and add federal channeler status later. State-authorized vendors capture fingerprints for state-level background checks tied to professional licenses, childcare positions, healthcare roles, and other regulated employment. Authorization comes from your state’s Bureau of Criminal Identification, state police, or equivalent agency.
FBI-approved channelers receive fingerprint submissions, collect fees, electronically forward the data to the FBI’s Criminal Justice Information Services (CJIS) Division, and pass the identity history summary results back to the individual.1Federal Bureau of Investigation. List of FBI-Approved Channelers for Departmental Order Submissions A channeler is essentially a middleman that speeds up delivery of FBI results. If your customers need both state and federal checks, you will eventually need both authorizations.
Qualify Personally Before You Apply
Every owner, officer, and primary operator goes through personal vetting before the company touches a single fingerprint. You submit your own fingerprints for a state and federal criminal history check. If a record of any kind turns up on a contractor or applicant, the reviewing agency delays system access pending a full review of the criminal history information.2Federal Bureau of Investigation. CJIS Security Policy Version 5.9.5
Not every offense is an automatic disqualifier, but crimes involving dishonesty or violence carry the most weight. Fraud and identity theft are especially problematic for someone seeking access to sensitive criminal justice data. Disqualifying offenses vary by state, so pull your state identification bureau’s published list before investing time and money in an application. Some states use a seven-to-ten-year lookback for certain offenses; others treat particular felonies as permanent bars.
Register the Business and Assemble Documentation
Your fingerprinting business needs to be a formally registered legal entity, typically an LLC or corporation. That registration gives you legal standing to enter contracts with state agencies and creates a liability structure. You also need an Employer Identification Number from the IRS, which you can apply for using Form SS-4.3Internal Revenue Service. About Form SS-4, Application for Employer Identification Number (EIN)
The core of your application package is your state’s vendor application form, available from the state police or department of justice website. Alongside that form, you sign the CJIS Security Addendum, a federally standardized contract approved by the Attorney General that binds your business to specific security requirements. It authorizes your access to criminal history record information, restricts how you can use the data, and subjects you to the same audit standards that apply to government agencies performing similar work.4Department of Energy. FBI Criminal Justice Information Services Security Addendum Everyone at your company who will handle criminal justice information must personally sign the addendum’s certification page.
Most states also require professional liability insurance with errors-and-omissions coverage, and many require a surety bond. Minimum coverage and bond amounts vary by jurisdiction, and both are ongoing costs rather than one-time expenses. You will likely also need an Originating Agency Identifier, a nine-character number that functions as your agency’s ID for FBI communications. You obtain an ORI by contacting your State Identification Bureau’s CJIS Systems Officer.5FBI. Fingerprint Card Order Form and Training Aid Links
Buy Certified Equipment
Ink-and-roll fingerprint cards are mostly gone. Nearly all authorized vendors now use Live Scan technology: electronic scanners that capture fingerprint images digitally and transmit them to government databases. Your scanner must appear on the FBI’s Certified Products List, meaning it has been tested and verified to meet the FBI’s Next Generation Identification Image Quality Specifications. As of early 2026, the list includes devices certified at both 500 and 1,000 pixels per inch.6FBI. Certified Products List (CPL)
The software paired with your scanner must generate files in the FBI’s Electronic Biometric Transmission Specification format, which is how fingerprint data gets packaged for federal processing. Live Scan hardware and software packages generally run between $7,000 and $12,000, though prices vary by manufacturer and capability. The FBI is clear that electronic fingerprinting equipment must be properly maintained at all times, so plan on ongoing calibration, software updates, and platen cleaning.7Federal Bureau of Investigation. Recording Legible Fingerprints
You also need a secure internet connection for transmitting fingerprint data. The CJIS Security Policy requires that criminal justice information traveling outside a physically secure location be encrypted using a FIPS 140-3 certified cryptographic module with the AES algorithm and a symmetric key of at least 128-bit strength. In practice, most vendors use AES-256.2Federal Bureau of Investigation. CJIS Security Policy Version 5.9.5
Set Up a Compliant Facility
Your office needs to be commercially zoned and accessible to the public, but the security requirements go well beyond typical retail. Visitors must be escorted at all times in physically secure areas, and you must maintain visitor access logs that include names, organizations, identification presented, dates, entry and departure times, purpose of the visit, and who they visited. Logs must be kept for at least one year and reviewed quarterly, with any anomalies reported to your security staff.2Federal Bureau of Investigation. CJIS Security Policy Version 5.9.5
The computer terminals used for Live Scan transmissions need restricted access. During a site inspection, investigators look for physical controls that prevent unauthorized people from reaching your equipment or viewing data on screen: locked doors, dedicated workstations, and a layout that keeps the fingerprinting area separate from general office traffic.
Hire and Train Staff
Every employee who accesses criminal justice information must complete a fingerprint-based background check before they touch the system. New hires need security and privacy training before they begin work, with refresher training required annually after that.2Federal Bureau of Investigation. CJIS Security Policy Version 5.9.5
For the technical side of capturing quality prints, the FBI’s CJIS Division offers free biometric and criminal history training to employees of authorized agencies. The “Scientific Basics of Fingerprints” course covers proper techniques for recording legible fingerprints and palm prints, and is open to current employees of agencies with valid ORI numbers.8FBI. Biometric and Criminal History Record Training Many states have their own technician certification requirements with separate fees, so check your state’s program early in the hiring process.
Submit the Application
With documentation assembled, equipment purchased, and facility prepared, you submit your application package to your state’s identification bureau. Most states accept submissions by mail or through a dedicated online portal. Application fees vary, and some states charge separately for the background investigation, site inspection, and certification.
Expect a review period that commonly runs several weeks. The agency verifies your documentation, runs background checks on all listed personnel, and typically schedules a site inspection. Inspectors check that your facility meets privacy standards, that Live Scan terminals have restricted access, and that your security setup matches what you described. If the review uncovers deficiencies, you usually get a chance to correct them before a final decision.
A successful review results in an official certificate of approval or authorization letter. That document grants you the legal right to begin capturing and transmitting fingerprints. In most states the authorization is not permanent and comes with renewal requirements.
Understand the Money
Fingerprinting vendors earn revenue by charging a per-applicant service fee on top of the government processing fees that pass through to state and federal agencies. The vendor’s own rolling fee is typically modest, often $11 to $18 per transaction, though the exact amount varies by state and may be subject to periodic adjustment. Your total charge to the customer includes your service fee plus the government processing fees.
Volume drives the business. A single location processing 20 applicants a day at a $15 service fee generates roughly $300 daily in revenue before expenses. Providers who serve multiple employer accounts, contract with state licensing boards, or operate in high-traffic areas tend to build more sustainable businesses. Equipment, rent, insurance, bonding, and payroll all eat into that margin.
Plan for Ongoing Compliance
Getting certified is the beginning, not the finish line. Private contractors are subject to the same audit standards as government agencies performing similar functions.4Department of Energy. FBI Criminal Justice Information Services Security Addendum Periodic compliance reviews will require you to produce network diagrams, policy documentation, and detailed system logs.
Your systems must log every successful and unsuccessful login attempt, every effort to access or modify files and user accounts, every action taken by administrator-level accounts, and any attempts to tamper with the audit log itself. Each audit record must capture what happened, when, where, who was involved, and the outcome. Records must be retained for a minimum of one year.2Federal Bureau of Investigation. CJIS Security Policy Version 5.9.5
Security awareness training must be repeated every year for all staff. Many states require fingerprint-based background checks on your employees to be refreshed every two years, along with re-signing of the CJIS Security Addendum and training certificates. Build a compliance calendar the day you get certified. Missed renewals are one of the fastest ways to lose your authorization.
Follow the Privacy Rules
Handling biometric data puts you squarely in the reach of federal and state privacy law. The federal Privacy Act of 1974 restricts how agencies and their contractors may disclose records maintained in a system of records. No record can be disclosed without written consent from the individual it pertains to, except under specific enumerated exceptions such as law enforcement requests, court orders, or congressional oversight.9Office of the Law Revision Counsel. 5 US Code 552a – Records Maintained on Individuals Contractors who violate the Privacy Act face the same criminal penalties as government employees.10eCFR. 48 CFR Part 324 Subpart 324.1 – Protection of Individual Privacy
State laws add another layer. Roughly half the states now explicitly include biometric data in their breach notification statutes. About 20 states set hard deadlines for notifying affected individuals after a breach, with timeframes ranging from 30 to 60 days. The rest require notification without unreasonable delay.
As a practical matter, retain fingerprint images and related data only as long as needed to confirm successful transmission, then destroy them. Physical fingerprint cards belong in a locked container until they are shredded. Digital records must be wiped using methods that prevent recovery. If a breach occurs, you are legally required to notify your authorizing state agency and affected individuals within the timeframe your state mandates. An unreported breach is a fast path to losing your certification and facing civil liability.