Compliance you can actually prove.
Generated policies, live risk assessments, and evidence filed against the controls it supports — so an audit finds a program, not a scramble.
What's inside
Four Peak products, packaged for your agency.
COMMAND is built on Compliance Shield, Peak's governance, risk, and compliance platform, with a learning management system, security training, and single sign-on around it.
- Policy generation across all 20 CJIS Security Policy areas
- Automated risk assessments
- Employee and vendor compliance tracking
- Incident response logging
- Centralized evidence storage for audit readiness
- Up to 30 custom SCORM or PDF training slots for your own agency content
- Assign by organization, unit, or individual
- Completion tracked alongside CJIS certification
- Eight cybersecurity and incident response courses
- Run always-on, or provision to specific people after an incident
- Single sign-on and API integration for automated user provisioning
- Bulk certification downloads
- Enhanced reporting dashboards
- Vendor employee clearance visibility
Everything in Peak LITE is included. COMMAND is set up with our team rather than self-serve, so your policy library and controls are configured against how your agency actually operates.
Inside the GRC
A closer look at Compliance Shield, the platform at the core of COMMAND.
The screens below are Compliance Shield. Policy generation, risk assessments, and evidence storage all happen here. See the full product →
The Compliance Shield dashboard: policy status, control coverage, and risk findings for your agency in one view. Everything below lives here.
Start from a library, not a blank page
The CJIS Security Policy carries more than 1,500 requirements across 20 policy areas. COMMAND generates agency policy documents against those areas so you are editing rather than authoring.
Find the gaps before an auditor does
Risk assessments are mandatory under the CJIS Security Policy. COMMAND walks you through your assets and the threats against them, then produces risk scores and a heat map showing what is unaddressed.
Audit prep becomes retrieval
Most agencies keep evidence across shared drives, inboxes, and filing cabinets. COMMAND stores each item against the control it supports, so producing it is a lookup.
Common questions about COMMAND
Do we need Peak LITE before we can get COMMAND?
No. COMMAND includes everything in LITE. Agencies that already run LITE move up to COMMAND without losing anything.
Is COMMAND the same as the CJIS training our state provides?
No. Your state provides CJIS security awareness training through Peak. COMMAND is the compliance layer your department adds on top of it, covering policy, risk, evidence, and your own agency-specific training.
Can we sign up for COMMAND online?
Not currently. COMMAND is configured with our team so your policy library and controls reflect how your agency actually operates. Start with a demo and we will scope it with you.
What powers the policy and risk features?
Compliance Shield, a governance, risk, and compliance platform purpose built for CJIS and for any other security framework your agency needs to baseline against.
See COMMAND for your agency
Tell us how your department handles policy, risk, and audit prep today. The first call is 30 to 60 minutes.
More questions about COMMAND? See the FAQ →
Not sure which package fits? Compare COMMAND and LITE for local agencies.