Investigative teams do more than organize case notes. They handle information that may influence decisions, support legal proceedings, and require dependable protection at every step. A case management system must therefore support security as part of the workflow, not treat it as a separate technical concern.
CJIS compliance means following the FBI’s CJIS Security Policy to protect Criminal Justice Information throughout its lifecycle, including creation, viewing, modification, transmission, storage, and destruction. For investigative software, that means aligning the platform and its operating practices with controls that preserve confidentiality, availability, and data integrity.
The policy applies to systems that process, store, or transmit this information, and its requirements extend beyond a single database or user account. Understanding what the policy covers is the first step toward evaluating whether case management software can support a secure investigative environment.
What Is CJIS Compliance?
CJIS compliance means following the FBI’s Criminal Justice Information Services (CJIS) Security Policy to protect Criminal Justice Information throughout its lifecycle. It covers how CJI is created, viewed, transmitted, stored, modified, shared, and destroyed, with safeguards for data both at rest and in transit.
The FBI’s CJIS Security Policy establishes information security requirements, guidelines, and agreements for systems that process, store, or transmit CJI. In practical terms, compliance is not a single software setting or a one-time checklist. It is a coordinated approach to controlling access, protecting sensitive records, monitoring activity, and maintaining secure handling procedures across the entire information environment.
What counts as Criminal Justice Information?
CJI is information obtained through a criminal justice agency or created in support of criminal justice services. Examples include fingerprint records, criminal histories, and personally identifiable information (PII) connected to investigations, subjects, victims, witnesses, employees, or other involved individuals. Depending on the workflow, related case notes, evidence details, identifiers, and investigative records may also require careful protection.
The important distinction is that protection must follow the information wherever it goes. A record can be exposed while a user views it, while a team transmits it to an authorized partner. While it sits in a database, or when it is copied, archived, or scheduled for destruction. The policy’s lifecycle approach therefore connects technical controls with user permissions, operational procedures, retention practices, and secure disposal.
Which technical controls support CJIS compliance?
At a minimum, systems handling CJI should protect stored data and data moving between users, applications, and services. AES-256 encryption at rest helps protect information stored in databases, files, and backups. TLS 1.2 or stronger encryption in transit helps protect CJI as it moves across networks. These controls address two parts of the FBI policy’s requirement to protect CJI whether at rest or in transit. But they are only part of a complete compliance program.
Organizations also need controls that limit access to authorized people, preserve useful audit records, and support secure administration. The appropriate control set depends on the agency, contractor, or private entity handling the information and may need to exceed the policy baseline. For investigative teams, choosing case management software with security controls designed around the CJI lifecycle can make those requirements easier to apply consistently.
Who Must Comply with the CJIS Security Policy?
CJIS compliance applies to every individual who can access Criminal Justice Information or support criminal and noncriminal justice services. That includes contractors, private entities, noncriminal justice agencies, and law enforcement personnel, so responsibility extends beyond government employees and police departments.
The FBI’s policy does not define compliance solely by an organization’s name. It focuses on access and operational support. If a person, vendor, or team handles CJI, the security requirements apply to the systems, procedures, and people involved in that work. The policy explicitly includes contractors, private entities, representatives of noncriminal justice agencies, and members of criminal justice entities. Read the FBI CJIS Security Policy.
Private investigative and security teams
Private investigators and investigative firms may encounter criminal justice data through records research, case collaboration, evidence handling, or work performed for a justice agency. Corporate security teams can face the same obligation when their work involves CJI or supports a criminal justice service. In each case, the practical question is whether the team has access to or operates in support of information covered by the policy. Not whether it carries a public-sector badge.
That scope makes vendor selection important. A case management platform, integration, hosting environment, or support process can become part of the information environment handling CJI. Organizations should document who can access the data, what each role can do, and how information is protected throughout its lifecycle. A platform’s security claims should be evaluated alongside the agency’s own policies, agreements, and operational controls.
How NCIC audits fit into compliance
The FBI’s NCIC Audit Program reviews every state and federal Criminal Justice Systems Agency with access to NCIC every three years. The purpose is to help ensure the integrity and reliability of data maintained in FBI CJIS systems. The review includes administrative policies and data quality procedures at the state agency and local agency levels. See the NCIC audit methodology.
Even when an organization is not itself the audited CSA, its handling of CJI can affect the broader compliance chain. Clear access controls, accountable vendors, and documented processes help every participating organization meet its responsibilities.
The 13 Key Areas of the CJIS Security Policy
Key takeaway: The FBI’s CJIS Security Policy organizes protection requirements into 13 connected areas, from access control and authentication to incident response and information integrity. Together, they establish a minimum security baseline for systems handling Criminal Justice Information, while allowing agencies to add stricter controls for local risks and operational needs.
The policy is not a single technical setting that makes a system compliant. It is a framework for designing, operating, and reviewing the people, processes, technology, and facilities that handle CJI. The FBI describes its security criteria as a way to reach a minimum level of risk and security protection. While preserving the latitude to adopt more stringent requirements based on an agency’s business model and local needs. Read the FBI CJIS Security Policy for the governing requirements.
For investigative teams evaluating case management software, the 13 areas provide a practical checklist:
- Policy and procedures: Document the rules, responsibilities, and operating practices that support CJIS security.
- Access control: Limit CJI and system access to authorized users, roles, and approved activities.
- Awareness and training: Ensure personnel understand security responsibilities and recognize potential threats.
- Audit and accountability: Record, review, and protect activity logs so access and changes can be traced.
- Configuration management: Establish and maintain secure system configurations throughout their lifecycle.
- Identification and authentication: Verify user and device identities before granting access.
- Incident response: Prepare teams to detect, report, contain, and recover from security incidents.
- Media protection: Control the handling, storage, transport, and disposal of media containing CJI.
- Physical protection: Safeguard facilities, equipment, and access points against unauthorized physical access.
- Personnel security: Address screening, authorization, transfers, and termination of personnel with access.
- Risk assessment: Identify threats and vulnerabilities, then use the findings to prioritize safeguards.
- System and communications protection: Protect networks, connections, and information exchanges from compromise.
- System and information integrity: Detect, prevent, and correct unauthorized changes, flaws, or malicious activity.
| Control Category | Policy Areas | Purpose |
|---|---|---|
| Management | Policy and procedures, Risk assessment, Personnel security | Establish the governance framework for security policies, personnel screening, and risk-based decision making |
| Operational | Awareness and training, Configuration management, Incident response, Media protection, Physical protection | Address day-to-day security practices including training, secure configurations, incident handling, media controls, and facility safeguards |
| Technical | Access control, Audit and accountability, Identification and authentication, System and communications protection, System and information integrity | Define the technology-level controls for identity verification, access enforcement, activity logging, network protection, and data integrity |
These areas also explain why CJIS compliance is an ongoing responsibility rather than a one-time purchase decision. Agencies with access to NCIC systems are audited every three years, with the audit focused on the integrity and reliability of data maintained in FBI CJIS systems. A case management platform should therefore support documented controls, consistent enforcement, and evidence that can be reviewed when requirements or local policies change.
Why CJIS Compliance Matters for Case Management Software
Case management software can become part of the Criminal Justice Information (CJI) environment, so its security controls directly affect confidentiality, data integrity, and contract eligibility.
Investigative platforms frequently process, store, and transmit sensitive information. That can include case details, reports, identifying information, communications, and digital evidence. The FBI’s CJIS Security Policy establishes requirements for systems that handle CJI throughout its lifecycle, including creation, viewing, modification, transmission, storage, and destruction.
Protecting data integrity across the case lifecycle
For investigators, a security failure is not limited to unauthorized access. Weak controls can expose information, undermine confidence in records, and jeopardize the integrity of data used to support an investigation. A case management system should therefore protect information both at rest and in transit while preserving a reliable record of who accessed or changed it.
Look for a technical foundation that includes AES-256 encryption for stored data and TLS 1.2 or higher for data moving between systems. Audit trails should record meaningful activity, while role-based access control limits users to the information and actions appropriate to their responsibilities. Two-factor authentication adds another barrier when credentials are compromised. Together, these controls support a more defensible approach to secure digital evidence management.
Supporting law enforcement contracts and readiness
CJIS compliance is often a prerequisite when software will support law enforcement work or interact with criminal justice information. It is not enough for a vendor to describe a product as secure. Agencies and partners need evidence that the platform’s controls, procedures, and oversight align with the applicable requirements.
CROSStrax’s SOC 2 Type II certification provides an independently audited technical and operational foundation for CJIS compliance readiness. It does not mean CROSStrax should be described as holding a CJIS certification. Instead, the certification demonstrates that established security controls are in place to help organizations evaluate and strengthen their own readiness. You can review the platform’s security approach on the CROSStrax user security page.
Choosing software with these safeguards built into its architecture helps investigative teams reduce avoidable risk while creating a clearer path through security reviews. Vendor assessments, and law enforcement procurement requirements.
How CJIS-Compliant Software Supports Investigative Teams
CJIS-compliant software gives investigative teams a secure operating foundation, so they can protect sensitive information and stay focused on casework. CROSStrax combines CJIS compliance readiness with independently audited security controls, practical access safeguards, and connected workflows.
Compliance should support good investigative work, not create another layer of friction. When security controls are built into the case management platform, teams can spend less time managing disconnected tools and more time collecting facts, coordinating staff, and serving clients.
SOC 2 Type II certification builds trust
CROSStrax’s SOC 2 Type II certification provides a trust foundation for organizations evaluating how a vendor protects data over time. The certification reflects an independent review of operational controls, giving investigative firms a clearer basis for assessing the platform’s security practices.
CROSStrax is designed for CJIS compliance readiness. That distinction matters: organizations still need to evaluate their own policies, contracts, user practices, and agency requirements. A platform prepared for those expectations can make that evaluation more manageable without claiming that every customer automatically meets every CJIS obligation.
Security controls protect access and accountability
Investigative teams need to know who can access case information, how access is granted, and what happened when records were viewed or changed. CROSStrax supports that oversight with role-based access control (RBAC), two-factor authentication (2FA), IP whitelisting, session management, and audit trails.
- RBAC limits information according to each user’s responsibilities.
- 2FA adds an additional verification step beyond a password.
- IP whitelisting helps restrict access to approved network locations.
- Session management supports safer handling of active user sessions.
- Audit trails create a record of relevant user and system activity.
Encryption for data at rest and in transit adds another layer of protection. Together, these controls help teams maintain defensible processes while preserving the visibility managers need for oversight and review.
Connected workflows reduce compliance friction
Security is easier to maintain when critical work does not depend on scattered spreadsheets, inboxes, and ad hoc handoffs. Through Zapier, CROSStrax connects with more than 1,500 applications, helping teams automate appropriate workflows while keeping case operations organized in one central system.
CROSStrax has operated for more than a decade without a compliance issue, reinforcing the value of a security-first approach. To assess the platform’s safeguards, review the CROSStrax user security controls and explore secure investigative software requirements for a broader look at selecting tools for investigative operations.
By Patrick Andrews
Frequently Asked Questions
What are the CJIS compliance requirements for 2026?
The requirements center on protecting Criminal Justice Information across its full lifecycle, including creation, viewing, modification, transmission, storage, and destruction. They include management, operational, and technical safeguards, with agencies able to apply stricter controls for local needs. Review the current FBI CJIS Security Policy for the applicable requirements.
What is considered a CJIS violation?
A violation can occur when an organization fails to apply required safeguards to CJI or the systems and infrastructure that process, store, or transmit it. Examples may include inadequate access controls, weak protection for data at rest or in transit, or failures in required policies and procedures. The specific finding depends on the applicable policy requirement and the facts of the incident.
Who must comply with the CJIS Security Policy?
The policy applies to every individual with access to, or who operates in support of, criminal and noncriminal justice services and information. That includes criminal justice personnel, contractors, private entities, and representatives of noncriminal justice agencies, as stated in the FBI policy.
Does CJIS compliance apply to cloud services?
Yes, when a cloud service processes, stores, or transmits CJI, the organization must evaluate whether its controls support the applicable CJIS requirements. Cloud architecture does not remove the responsibility to protect information at rest and in transit or to secure the underlying hardware, software, and infrastructure.
Ready to Start Your Free Trial?
Choosing case management software with strong security foundations can help investigative teams organize sensitive work with greater confidence. To start your free trial of CROSStrax case management software, get started here. You can review the platform’s capabilities and determine whether it fits your team’s workflow and compliance-readiness priorities.