Skip to content

Resource

CJIS Readiness Checklist

A readiness checklist for Pennsylvania municipalities, police departments, and their IT providers, written against CJIS Security Policy v6.1.

Dawn SizerDawn Sizer · CEO and Co-Founder, 3rd Element Consulting ·

What the checklist covers.

The checklist walks through the areas a CJIS audit looks at: agreements, personnel, access, encryption, physical security, systems, logging and incident response, Microsoft 365, cloud, and AI tools.

It is written for the agency and for the IT provider together, because a vendor with access to criminal justice information is inside the compliance boundary too. For the full explanation of each requirement, read our guide to CJIS compliance requirements.

Use it before the audit, not during it.

Work through it with whoever owns IT for your agency and mark what is in place, what is partly in place, and what nobody owns yet. The gaps you find are the list to work on before the next audit cycle.

The checklist also recommends a written AI acceptable use policy. If you do not have one, our AI acceptable use policy guide is a good place to start. For how we support agencies directly, see our IT support for local government and police departments.

Schedule an IT Environment Review

The checklist

Download the CJIS Readiness Checklist.

Agreements, personnel, access, encryption, physical security, systems, logging and incident response, Microsoft 365, cloud, and AI tools, in one printable PDF. Free to download, no email required.

Common questions

Questions leadership usually asks first.

Next step

Get a clearer view of your IT environment.

Find out what is working, where the risks are, and what needs attention next.