Frequently asked questions

CJIS questions, answered plainly.

What CJIS compliance requires, what happens in an audit, and how Peak fits, for states, local agencies, and the vendors who serve them.

CJIS basics

General questions about the FBI CJIS Security Policy and what it asks of the organizations it covers.

CJIS requirements vary by state. The answers below describe the federal CJIS Security Policy. For what applies to your organization specifically, check with your state CJIS Systems Agency.

What is CJIS compliance?

CJIS compliance means meeting the FBI's CJIS Security Policy, the standard that governs how criminal justice information is protected. Version 6.0 organizes the policy into 20 policy areas covering access control, encryption, training, incident response, physical security, and more. It applies to any organization that handles criminal justice information, not only law enforcement agencies.

Who has to take CJIS security awareness training?

Anyone with access to criminal justice information, and anyone with unescorted access to areas where it is handled. That includes officers and dispatchers, IT staff, and vendor employees. Training is required before access is granted, and again on the schedule the policy and your state require.

What happens in a CJIS audit?

Auditors review written policies, training records, access logs, and technical controls, interview staff, and inspect facilities. The FBI CJIS Audit Unit audits each state CJIS Systems Agency, and state CSAs audit their local agencies and contractors.

How often does a CJIS audit happen?

The FBI audits each state's CJIS Systems Agency on a three-year cycle. How often a local agency is audited depends on its state, and the FBI may also select local agencies directly. Most of the work sits between audits, in keeping policy, evidence, and training current rather than assembling it at audit time.

What does a CJIS compliance program involve?

Day to day it comes down to a few things running continuously: training everyone who touches criminal justice information and keeping that training current; certifying and recertifying the people who query state and national systems; validating records so what is in the system is still accurate; keeping written policy current as the CJIS Security Policy changes; collecting the evidence that shows controls are working; and handling audits when they come. The hard part is usually not any single piece, it is keeping all of them current at the same time between audits.

Can a vendor be "CJIS certified"?

No. There is no national CJIS certification for vendors or products. What is required is that vendor employees with access to criminal justice information complete security awareness training, sign the FBI CJIS Security Addendum, and pass fingerprint-based background checks for the agencies they serve. A vendor describing itself as "CJIS certified" is describing something that does not exist.

What is the CJIS Security Addendum?

A uniform agreement that contractors with access to criminal justice information are required to sign. It creates a legal obligation to protect that information and to limit access to authorized people. It is an agreement, not a certification.

What is the difference between a CSA, a CSO, a TAC, and a LASO?

The CJIS Systems Agency is the state body responsible for CJIS within its borders, usually the state police or department of public safety. The CJIS Systems Officer runs it. A Terminal Agency Coordinator manages CJIS at a local agency. A Local Agency Security Officer is that agency's security point of contact.

What changed in CJIS Security Policy 6.0 and 6.1?

Version 6.0 reorganized the policy into 20 policy areas and aligned it more closely with NIST 800-53. Version 6.1 was a maintenance release that tightened vulnerability scanning frequency, encryption, incident reporting, and role-based training. We wrote up both: what changed in 6.0 and what changed in 6.1.

For states

Questions from CJIS Systems Agencies running compliance across every agency in a state.

What does a CSA have to manage statewide?

A CJIS Systems Agency is responsible for CJIS within its state. In practice that means providing security awareness training to agencies across the state, administering certification testing for people who query state and national systems, running the monthly NCIC validation cycle, auditing local agencies and contractors, and being ready for the FBI's own audit of the CSA.

Which Peak products do states run?

Five core products: CJIS Online for security awareness training, nexTEST for NCIC certification testing, CJIS Audit for electronic audit management, Validations for browser-based NCIC record validation, and Compliance Shield for governance, risk, and compliance. States buy a la carte, starting with the core platform and adding modules as the program grows.

What add-ons does Peak offer states?

Add-ons include Peak Training Extension for delivering an agency's own courses, Cyber and Incident Response Training, ARM, Audit Docs, Security Roles, and CJO Access.

Which audits can you run in CJIS Audit?

CJIS audits, technical audits, non-criminal justice agency audits, and any custom audit your program defines, all in the same platform. About CJIS Audit →

What does Compliance Shield do?

It automates the management controls of your security process. Compliance Shield assumes you already have firewalls and MFA; it is the layer that ties policies, controls, evidence, incidents, and vendors together and keeps them current. About Compliance Shield →

Which security courses are included in Cyber and IR Training?

Eight courses: Cybersecurity 101, Social Engineering, Phishing, Malware, Physical Device Security, Password Security, Web Browsing, and Artificial Intelligence. All eight are compatible with nexTEST so completion tracks alongside certification. About Cyber & IR Training →

How do agencies run those security courses?

Two ways, and they are not exclusive. Courses can run always-on across a workforce as standing security awareness, or be provisioned to specific people after an incident. Agencies choose which courses to run continuously and which to hold in reserve.

For local agencies

Questions from police departments and other local agencies, usually without dedicated compliance staff.

What does CJIS compliance require of a local agency?

The same CJIS Security Policy that applies to a state applies to a local agency: written policy across the 20 policy areas, risk assessments, training and certification for anyone touching criminal justice information, evidence that controls are working, and readiness for audit. Most departments carry that alongside other duties rather than with dedicated compliance staff.

What is the difference between Peak LITE and Peak COMMAND?

Your people already train in CJIS Online through your state. LITE adds single sign-on and API integration, bulk certification downloads, reporting dashboards, visibility into the clearance status of vendors who work with your agency, and eight cybersecurity and incident response courses. COMMAND includes all of that and adds the governance layer: policy generation across all 20 CJIS Security Policy areas, automated risk assessments, incident response logging, evidence storage, and up to 30 slots for your department's own training.

Do we need Peak LITE before we can get COMMAND?

No. COMMAND includes everything in LITE. Agencies that already run LITE move up to COMMAND without losing anything.

Is COMMAND the same as the CJIS training our state provides?

No. CJIS security awareness training is what your state provides to meet the FBI requirement. COMMAND is the compliance layer a department adds on top of it, covering policies, controls, evidence, and agency-specific training.

Can we sign up for COMMAND online?

Not currently. COMMAND is configured with the Peak team so the policy library and controls reflect how the agency operates. It starts with a demo.

What powers the policy and risk features in COMMAND?

Compliance Shield, Peak's governance, risk, and compliance platform, purpose built for CJIS and NIST and adaptable to frameworks like HIPAA, CMMC, and ISO. About Peak COMMAND →

For vendors

Questions from public safety companies clearing employees with the agencies they serve.

What does CJIS compliance require of a public safety vendor?

Every employee who touches criminal justice information goes through three stages for each agency served: security awareness training completed before access and renewed on schedule, signing the FBI Security Addendum along with any state-specific version, and fingerprint-based background checks plus whatever forms and documentation that agency requires.

What does CJIS Online do for a vendor?

CJIS Online is where a vendor workforce gets trained, signs security addendums, and gets cleared with the agencies it serves, with status visible across every agency relationship. See it for vendors →

What are the Peak vendor tiers?

Access and Pro are software tiers. Pro Archive and Pro Managed add services. Access covers the core platform, Pro adds clearance tracking and reporting, Pro Archive adds fingerprint archiving, and Pro Managed adds fully managed compliance operations.

How does Peak fingerprint archiving work?

An employee is fingerprinted once at a local location. Peak processes and securely archives the prints, then builds a fingerprint card to each agency's state-specific requirements. At Pro Archive the card is returned to the vendor to submit. At Pro Managed, Peak submits it on the vendor's behalf.

How do agencies and vendors use CJIS Online differently?

Agencies run training across their own workforce, assigning, tracking, and renewing it across every person and agency in the state. Vendors use it to train their people, sign security addendums, and manage clearance across every agency relationship from one account.

Still have questions?

Tell us how your CJIS program runs today and we will walk you through what fits.

Book a demo