CJIS
CJIS MFA is now mandatory: the practical checklist
Advanced authentication for anyone touching Criminal Justice Information is no longer optional. Here's what the policy requires versus what an underfunded agency can actually deploy this quarter.
The CJIS Security Policy is one of the strictest frameworks a small IT team will ever meet, and its authentication requirements have tightened: multi-factor / advanced authentication is now required for access to Criminal Justice Information (CJI). For county agencies, courts, and the vendors that serve them, "we'll get to it" is no longer a defensible position.
What the policy is really asking
Advanced authentication means more than a password — a second factor that's resistant to replay and phishing, applied to anyone who can reach CJI, from any location. The spirit is simple: a stolen password shouldn't be enough to reach criminal-justice data.
The practical checklist
- Inventory the access paths to CJI — the records system, the mobile data terminals, remote access, and any integration that pulls the data.
- Apply MFA to every one of them, not just the obvious login. The forgotten VPN or vendor portal is where audits fail.
- Cover privileged accounts — the admins who manage those systems are the highest-value target.
- Document it. The auditor wants evidence the control operates, not a promise that it exists.
Budget reality
Underfunded agencies can meet this without a rip-and-replace: modern identity platforms bundle phishing-resistant MFA, and cooperative purchasing vehicles make it affordable. The mistake is scoping too narrowly and leaving one path uncovered. When one door is open, the whole control fails.
Before your renewal
Run the 3-minute insurability self-check
See where you’d pass or fail your carrier’s questionnaire, with a control-by-control gap list.
Start the self-check