
On Sept. 22, 2026, the National Institute of Standards and Technology (NIST) will move every Federal Information Processing Standards (FIPS) 140-2 cryptographic module certificate to historical status. The Criminal Justice Information Services (CJIS) Security Policy states separately that FIPS 140-2 certificates will not be acceptable after that date, which is why a CJIS compliance consultation may be beneficial before things change.
The CJIS Security Policy assigns responsibility to the agency holding the criminal justice information. The state CJIS Systems Agency then audits that agency’s controls, documentation, and evidence. A vendor can build the controls, sign the CJIS Security Addendum, and accept contractual obligations, but that doesn’t automatically transfer compliance status onto the agency.
The question worth asking during a consultation is narrower. Which controls does this product or service satisfy, and at what priority marking? What evidence does it produce when an auditor asks for it?
What Changed Under CJIS Security Policy 6.0
Version 6.0, dated Dec. 27, 2024, rebuilt the policy around NIST SP 800-53 Revision 5. There are now 20 policy areas, beginning with information exchange agreements (Policy Area 1) and ending with mobile devices (Policy Area 20). Requirements show up as control identifiers instead of narrative policy text, so a vendor compliance packet built against the 5.x structure will no longer line up with what your auditor is reading from.
Each modernized control also carries a priority marking. Since Oct. 1, 2024, the sanctionable set has been everything predating modernization plus everything marked Priority 1. Modernized Priority 2, 3, and 4 controls sit in what the policy calls zero-cycle status, a window that closes Sept. 30, 2027.
Remote access, account management, and identification and authentication carry Priority 1 at AC-17, AC-2, and IA-2, which makes them sanctionable today. The encryption controls SC-8, SC-13, and SC-28 carry Priority 2. Device lock at AC-11 and audit record retention at AU-11 carry Priority 4.
An agency reading that as license to defer encryption work until 2027 has misread it. The FIPS 140-2 sunset has nothing to do with priority tiers. A module whose certificate lapses stops satisfying SC-13 on Sept. 22, 2026, whatever cycle the control sits in.
Authentication Requirements a Remote Tool Must Meet
Under IA-2, organizational users have to be identified and authenticated individually, and the control’s enhancements cover multifactor authentication for privileged and non-privileged accounts. The policy defines a factor as something the user knows, something the user has, or something the user is, and multifactor authentication looks for two or more of them.
Authenticators relying on the public switched telephone network, including phone-based and SMS-based one-time passwords, are restricted. A texted code is a restricted second factor.
Account lifecycle sits at Priority 1 alongside authentication. AC-2 covers provisioning, review, and disabling accounts, and the practical test for a remote tool is how fast an administrator can revoke an account, end that user’s live sessions, and show a record of both.
Under AC-17, the agency documents usage restrictions, configuration and connection requirements, and implementation guidance for every type of remote access, then authorizes each type before anyone connects. While that documentation is yours to produce, a vendor experienced in criminal justice deployments will supply the technical detail that documentation needs.
Encryption, Logging, and Audit Trail Expectations
SC-13 covers criminal justice information (CJI) in transit and SC-28 covers CJI at rest. Both are concerned with data sitting outside a physically secure location. Each accepts a cryptographic module certified to FIPS 140-3 or a FIPS 197-validated algorithm. SC-13 sets a floor of 128 bits. So does SC-28 on the FIPS 140-3 route, though its FIPS 197 route requires at least 256 bits. Ask the vendor for the certificate number of the cryptographic module its product uses, then check that number against the NIST validated modules list.
SC-28 also requires that metadata derived from unencrypted CJI be protected as CJI, and a cloud service provider cannot use it for advertising or other commercial purposes. Storage of CJI is permitted only inside an APB (Advisory Policy Board) member country (i.e., the United States, its territories, federally recognized Tribal Nations, and Canada) under the legal authority of an APB-member agency.
Regarding logs, AU-11 sets one year for audit record retention, and AU-6 covers review, analysis, and reporting. If the vendor provides a demo, ask them to pull up live log output for a failed authentication, a permission change, and a session from an unrecognized device, then ask for an export your log platform can read.
The Incident Response Gap Auditors Keep Finding

Policy Area 9 requires a documented incident response plan specific to CJI, even if it is included in a general IT plan. Under IR-8, that plan has to define reportable incidents, supply metrics for the response capability, address how incident information gets shared, and go to agency executive leadership for review and approval every year. The plan also has to designate incident response responsibility explicitly to named personnel with incident reporting duties and to the CSO or CJIS WAN official.
Two things account for most findings here. First, the executive approval is annual, so a plan approved once at adoption and never re-approved may not satisfy the control. Second, the designation has to name someone specific in a specific role, which means a plan pointing at a vacant position will likely fail inspection.
The vendor’s obligation is narrower and belongs in writing. Find out how many hours they have to notify you when an incident touches your data or their systems, then check whether that number appears in the contract or only on a support page.
How to Verify a Vendor Claim Before the Audit
To verify a vendor claim before an audit, request mapping keyed to control identifiers and priority markings. A usable mapping separates what the product satisfies on its own, what you configure inside it, and what stays your responsibility.
Confirm that any vendor subject to the CJIS Security Addendum with whom you plan to work has signed it, with an agency coordinator managing the agreement and personnel screening and training obligations. Your own state’s CJIS Systems Agency (CSA) requirements matter here too, since state policy often adds requirements on top of the federal baseline.
Talk with CPI OpenFox about evaluating CJIS-compliant remote access software against the controls your CSA will actually audit.
