

CJIS Readiness & Gap Assessment
Find Every Gap Before a Law Enforcement Client — or a CSA Auditor — Does.
Winning law enforcement contracts requires more than a signed CJIS Security Addendum. It requires a documented, verified, and independently assessed compliance posture. The gap assessment is where that posture is built — and where most vendors discover that what they assumed about their compliance is not what the FBI CJIS Security Policy actually requires.
WHO THIS SERVICE IS FOR
Criminal justice technology vendors, cloud and hosting providers, managed service providers, telecommunications companies, background screening companies, cybersecurity firms, software developers, financial institutions, healthcare organizations, and universities — any private sector organization that processes, stores, or transmits Criminal Justice Information.
THE PROBLEM YOU'RE FACING
Most vendors have never had an independent expert assess their compliance posture against the FBI CJIS Security Policy. They rely on internal assumptions, vendor-provided checklists, or the fact that nobody has challenged them yet. That changes the moment a law enforcement client asks for a formal compliance review — or an RFP requires documented evidence they cannot produce.
A CJIS Readiness & Gap Assessment provides an objective evaluation of your current environment, policies, procedures, vendor relationships, personnel security controls, and technical safeguards.
Rather than guessing where your compliance risks exist, you'll receive a clear understanding of which requirements apply to your organization, where gaps are present, and how those gaps could impact customer relationships, contract opportunities, and operational risk.
Sound Familiar?
Unvalidated Security Addendum Obligations: You have signed a CJIS Security Addendum but never formally assessed whether you are meeting its requirements (and you have no System Security Plan!)
Customer Compliance Documentation Request: A law enforcement client has asked for evidence of your CJIS compliance posture and you don't know where to start
Government Contract Readiness Assessment: You are preparing to bid on a law enforcement contract requiring demonstrated CJIS compliance
Compliance Impact of Organizational Growth: Your organization has grown — new staff, new systems, new subcontractors — and nobody has assessed the compliance impact
Undocumented Compliance Gaps: You know gaps exist but have never had them formally identified, documented, and prioritized
OUR METHODOLOGY
Our Assessment Process Is Designed to Identify Every Applicable Requirement, Document Every Gap, and Deliver a Clear Path to Compliance.

PHASE 1:
CJI Environment Scoping
Every system, user, subcontractor, and data flow touching CJI in your environment is mapped and documented. Most vendors have never done this — and the results are almost always more expansive than expected.

PHASE 3:
Gap Documentation & Risk Rating
Every finding is documented with the specific requirement not being met, the root cause, the severity rating, and the direct policy citation. No ambiguity. An honest picture of where you stand.

PHASE 2:
Control Family Assessment
All 18 FBI CJIS Security Policy control families are evaluated against your actual configuration and operational practices — not a theoretical baseline.

PHASE 4:
Remediation Roadmap & Findings Briefing
A prioritized remediation roadmap is delivered — built for execution. Findings are presented in plain language with risk context, including which gaps must be closed before a consulting attestation letter can be issued.

Most vendors I assess have never had anyone go through their environment control by control and tell them honestly where their gaps are. The gap assessment is the foundation everything else is built on — and the starting point for every consulting attestation letter I issue.
— Charles Denyer, Founder & CEO, CJIS Academy | CJIS Practice Lead

CJIS READINESS & GAP ASSESSMENT PACKAGE
Every Gap Assessment Engagement Produces a Complete, Audit-Ready Deliverable Package.

All deliverables are formatted and evidenced in the manner that state CSA auditors and CJIS Systems Officers expect to see.
WHAT YOU RECEIVE
Comprehensive Gap Assessment Report: All findings across all 18 CJIS control families with severity ratings, root cause analysis, and direct policy citations
CJI Environment Map: A documented inventory of every system, user, subcontractor, and data flow touching CJI in your environment
Personnel Security Review: Background screening status, need-to-know authorization, and access scope verified for every individual with CJI access
Prioritized Remediation Roadmap: A sequenced action plan built for operational execution
Attestation Readiness Assessment: A clear statement of what gaps must be closed before a CJIS Academy consulting attestation letter can be issued
WHY THIS ENGAGEMENT PAYS FOR ITSELF
The Cost of Identifying Compliance Gaps is Always Less Than the Cost of Explaining Them to a Customer, Auditor, or Procurement Team After They've Already Been Found.

Know Exactly Where you Stand
Know where you stand before a law enforcement client or procurement officer asks.

Protect Existing Contracts
Identify and close gaps before a client-initiated compliance review finds them first.

Build the Foundation for Attestation
The gap assessment is the required first step toward a CJIS Academy consulting attestation letter.

Accelerate Procurement Timelines
Vendors with a documented, assessed compliance posture move through law enforcement procurement faster.
Frequently Asked Questions
Do you need access to CJI to conduct this assessment?
No. All assessment work is conducted against your infrastructure, systems, and documentation — not the data itself. In rare instances where CJI access is necessary, we will execute the required CJIS Security Addendum documentation to authorize it in full compliance with FBI CJIS Security Policy requirements.
We are a software developer. Does this assessment apply to us?
Yes — if your application touches CJI at any point. The assessment is scoped to your specific role and the requirements applicable to your organization's relationship to Criminal Justice Information.
Is the gap assessment required before a consulting attestation letter can be issued?
Yes. The attestation letter is issued on the basis of a formal compliance assessment. The gap assessment is that assessment.
How long does this engagement take?
Two to four weeks for most vendor engagements, depending on environment complexity and the availability of key personnel.


