WHO THIS SERVICE IS FOR
For law enforcement agencies, criminal justice vendors, and every organization that stores, processes, or transmits Criminal Justice Information. FBI CJIS Security Policy compliance is not optional — and neither is knowing exactly where your gaps are.
THE PROBLEM YOU'RE FACING
Most agencies and vendors believe they are compliant. Most discover otherwise at the worst possible moment — during a state CSA audit, after a breach, or when a vendor relationship gets terminated for non-compliance.
The FBI CJIS Security Policy spans 18 control families and hundreds of discrete requirements that apply differently depending on your agency type, network architecture, vendor relationships, and personnel decisions. The problem isn't that organizations ignore compliance — it's that they don't know what they don't know.
What remains invisible today can become tomorrow's most expensive operational and legal exposure. Undocumented systems, improperly vetted personnel, unsecured vendor connections, and overlooked policy gaps can trigger audit findings, jeopardize access to Criminal Justice Information, and leave leadership defending risks they never knew existed.
Sound Familiar?
Complete Environment Mapping: You've never had an independent expert map every system, user, and vendor touching CJI in your environment.
Checklist-Only Reviews: Your last compliance review was a self-assessment or a vendor-provided checklist.
Audit Uncertainty: You have a scheduled CSA audit approaching and no clear picture of your current posture.
Unresolved Prior Findings: You've received prior audit findings and aren't confident the gaps have been fully closed.
Unassessed Technology Changes: Your agency recently deployed new technology, onboarded a new vendor, or expanded remote access — and nobody has assessed the compliance impact.

If any of these apply, you have compliance exposure you can't see. The sooner hidden gaps are identified, the easier and less expensive they are to fix. Schedule an independent CJIS Readiness & Gap Assessment to see exactly where you stand before an audit, breach, or contract issue forces the answer.
OUR METHODOLOGY
The CJIS Academy Readiness and Gap Assessment follows a structured, four-phase engagement methodology developed over two decades of hands-on CJIS compliance work across law enforcement agencies, criminal justice vendors, and federal environments.

PHASE 1:
CJI Environment Scoping
We trace every path CJI takes through your environment — every system, user, vendor relationship, network segment, and data flow. This phase alone surfaces issues most organizations didn't know existed, because most have never systematically mapped where their CJI actually goes.

PHASE 3:
Gap Documentation & Risk Rating
Every finding is documented with precision — the specific requirement not being met, the root cause, the severity rating, and the direct policy citation. Each issue is explained so you understand exactly what is at risk. No ambiguity. No softened language. An honest picture of where you stand.

PHASE 2:
Control Family Assessment
All 18 FBI CJIS Security Policy control families are evaluated against your actual configuration and operational practices — not a theoretical baseline. Each control family is assessed individually, with findings documented in real time so nothing is generalized, estimated, or assumed.

PHASE 4:
Remediation Roadmap & Executive Briefing
We deliver a prioritized, sequenced remediation roadmap that addresses your highest-severity exposures first — built for operational execution, not a file drawer. Findings are presented to agency leadership and legal counsel in plain language with clear risk context and recommended next steps.

Most organizations don't fail CJIS audits because they were careless — they fail because nobody ever gave them an honest, independent assessment of where the gaps actually were. That's what this engagement exists to do.
— Charles Denyer, Founder & CEO, CJIS Academy | CJIS Practice Lead

CJIS READINESS & GAP ASSESSMENT PACKAGE
Every Gap Assessment Engagement Produces a Complete, Audit-Ready Deliverable Package.

All deliverables are formatted and evidenced in the manner that state CSA auditors and CJIS Systems Officers expect to see.
WHAT YOU RECEIVE
Comprehensive Gap Assessment Report: All findings across all 18 CJIS control families, with severity ratings, root cause analysis, and direct policy citations
CJI Environment Map: A documented inventory of every system, user, vendor, and data flow touching CJI in your environment
Personnel Security Review: Background screening status, need-to-know authorization, and access scope verified for every individual with CJI access
Prioritized Remediation Roadmap: A sequenced action plan built for operational execution, not shelf storage
Executive Briefing Package: Findings translated into plain language for agency leadership, legal counsel, and board-level stakeholders
Downstream Engagement Scope: A scoped proposal for any remediation, documentation, or training work required to close identified gaps
WHY THIS ENGAGEMENT PAYS FOR ITSELF
The Gap Assessment is not a Cost — it is Risk Mitigation with a Measurable Return.

Avoid Audit Findings
Prevent findings that trigger mandatory remediation timelines and potential loss of access to Criminal Justice Information.

Reduce Remediation Costs
Identifying gaps proactively is significantly less expensive than addressing them after an audit or security breach.

Protect Vendor Contracts
A single failed CJIS assessment can jeopardize critical contracts and cost far more than the engagement itself.

Strengthen Audit Readiness
Establish a defensible compliance baseline that protects leadership and helps your organization perform with confidence during scheduled CSA audits.
Frequently Asked Questions
Do you need access to CJI to conduct the assessment?
No. We do not require access to Criminal Justice Information at any point during a standard engagement. Everything we need comes from the infrastructure, systems, processes, and documentation that store, process, or transmit CJI — not the data itself. You can engage us with complete confidence that no actual CJI will be accessed, reviewed, or handled. In rare instances where accessing CJI is necessary for sensitive consultative engagements, we will execute the required CJIS Security Addendum documentation to authorize such access in full compliance with FBI CJIS Security Policy requirements.
How long does the engagement take?
Most gap assessments are completed within three to four weeks, depending on environment complexity and the availability of key personnel for interviews and documentation review.
What will you need from our team?
Access to key personnel — typically your IT director, CJIS Systems Officer, and relevant vendor contacts — for structured interviews, along with network diagrams, system inventories, vendor agreements, and existing policy documentation. We work around your operational schedule and minimize disruption to daily operations.
We already passed our last CSA audit. Do we still need this?
Yes. CSA audits are point-in-time assessments. New technology deployments, vendor onboarding, personnel changes, and policy updates can all create gaps between audit cycles. The question is not whether you passed last time — it is whether you would pass today.
What happens after the gap assessment?
You receive a complete findings package and a prioritized remediation roadmap. CJIS Academy can support remediation planning, documentation development, training, and audit preparation — or you can execute internally. There is no obligation to continue beyond the assessment.
Is this the same as a CSA audit?
No. A CSA audit is conducted by your state CJIS Systems Agency and produces formal findings with mandatory remediation timelines. This assessment is an independent, confidential engagement that prepares you for that audit — or surfaces issues before one occurs.



