Peak for state CJIS systems agencies

Training.Certification.Validations.Audits.Governance.

Distribute security awareness training to every agency in your state, certify the people who work in NCIC, run the monthly validation cycle, audit your agencies, and prove your own compliance when the FBI comes to you.

The job

What does a CSA have to manage statewide?

A CJIS Systems Agency is responsible for CJIS within its state. In practice that means providing security awareness training to agencies across the state, administering certification testing for people who query state and national systems, running the monthly NCIC validation cycle, auditing local agencies and contractors, and being ready for the FBI's own audit of the CSA. Each of those has its own cycle, its own records, and its own way of falling behind.

  • Security awareness training, every agency
  • NCIC certification testing
  • Monthly record validation
  • Audits of local agencies and contractors
  • Readiness for the FBI's audit of the CSA
  • Policy, controls, and evidence in between
Our products

Which Peak products do states run?

States run Peak à la carte. Start with the products you need and add modules as your program grows.

CJIS Online

The industry standard for security awareness training.

Affordable online training and testing that makes it simple to comply with required CJIS security and privacy training for practitioners, operators, vendors, and IT personnel.

Agencies and vendors work in the same platform, so vendors get cleared with the agencies they serve
Annual recertification tracked for everyone who touches CJI
ARM and CJO Access add-ons extend the admin experience
Explore CJIS Online →
nexTEST

Streamline your NCIC certification process.

The market leader in training and tracking State and NCIC certification status, with distinct workflows for Full Admin, Admin, and Assistant Admin user types.

Manage testing across every agency from one place
Course and test administration run statewide from the state
nexTEST and CJIS Online certification data in one dashboard
Explore nexTEST →
CJIS Audit

Audit management, digitized.

A complete electronic audit platform for state and federal CSAs. CJIS audits, technical audits, and non-criminal justice agency audits, all in one place.

Manage responses from every agency inside the tool
Thirty-seven states run their technical audits on CJIS Audit
State responses assembled automatically from agency submissions
Explore CJIS Audit →
CJIS Validations

The first browser-based NCIC validation system.

Import the NCIC validation file and replace printing, mailing, and paper handling with a monthly cycle agencies work in the browser.

Automated import and batch processing, no paper records
Built-in audit trail of who validated what records
Prepare validation data for every local agency at once, with record categories configured per state
Explore Validations →
Compliance Shield

Governance, risk, and compliance in one place.

Over 20 pre-written policy templates mapped to CJIS and NIST controls, a risk assessment wizard, and evidence stored against the control it satisfies. An Auditor role is built for external audits by the FBI.

Generate policy from a library across all 20 CJIS Security Policy areas
Run risk assessments automatically
Store evidence against controls, with roles for auditors
Explore Compliance Shield →
Beyond the core

What else can a state add?

Governance, custom training, and cyber readiness, added as your program grows.

Peak Training Extension

Turns CJIS Online into a full learning management system. Upload your own courses, video series, and quizzes alongside standard CJIS content, and assign them to your whole organization, to specific organization units, or to named people.

Explore Peak Training Extension →
Cyber & IR Training

Eight specialized security courses covering ground that required CJIS training does not. Run them always-on across your workforce, or provision them per incident.

Explore Cyber & IR Training →
Add-on modules

Extend the products you already run. Each module activates inside your existing platform.

ARM

Agency Relationship Management. Targeted messaging, task tracking, and custom agency and user classifications, plus two custom state certifications that auto-assign based on those classifications.

Explore ARM →
Audit Docs

Agencies upload audit evidence directly through a secure portal. Submissions are time-stamped and automatically linked to the audit, agency, and requirement, which ends the email chains.

Explore Audit Docs →
Security Roles

LASO designation, certification testing, compliance tracking, and reporting.

Explore Security Roles →
CJO Access

API access and single sign-on. Automates user provisioning, integrates certification data into your systems of record, and adds bulk certificate download.

Explore CJO Access →

Ready to see it work for your program?

Tell us how your state runs training, testing, validations, and audits today. We will walk you through how Peak handles each one.

More questions about running CJIS statewide? See the FAQ →