2026 CJIS Certification
Benchmark Report
Table of Contents
ToggleAggregate Anonymized Insights from Lazarus Alliance
CJIS Security Policy Assessments
Reporting Period: January 2025 – June 2026 • Published August 2026 • Version 1.0
Assessments
Duration
(22 of 28)
Evidence (24 of 28)
Lazarus Alliance, Inc.
CJIS Security Policy Assessment & Advisory
A2LA-Accredited FedRAMP 3PAO • Authorized CMMC C3PAO (CPN 10251) • PCI DSS QSA • Veteran-Owned Small Business
Title: 2026 CJIS Certification Benchmark Report
Version: 1.0 (August 2026)
Dataset: N = 28 completed CJIS Security Policy assessments and technical validations performed by Lazarus Alliance between January 2025 and June 2026. All organizational identifiers, ORI numbers, and proprietary details removed.
Publisher: Lazarus Alliance, Inc., Scottsdale, Arizona
License: © 2026 Lazarus Alliance, Inc. All rights reserved. Aggregate statistics may be cited with attribution.
1. Purpose & Methodology
This benchmark report aggregates anonymized findings from N = 28 CJIS Security Policy assessments performed by Lazarus Alliance between January 2025 and June 2026. The population includes local law enforcement agencies, state criminal justice agencies, and private contractors / cloud service providers supporting CJI environments. Figures represent observed patterns and are intended to provide realistic expectations for scope, duration, evidence quality, and common control gaps under the FBI CJIS Security Policy.
Scope of Data: Completed technical assessments and policy compliance validations only (pure readiness workshops excluded). Both on-premises and cloud / hybrid CJI environments are included. Percentages use N = 28 unless otherwise noted. Policy version context is primarily CJIS Security Policy v5.9.x and successor guidance applicable during the reporting period.
Disclaimer: These benchmarks are observational and do not constitute guarantees of future performance, certification outcomes, or timelines. Individual results vary based on agency size, system architecture, personnel security practices, and state CSA requirements. Lazarus Alliance maintains independence and does not replace the role of the state Compact Officer, CSA, or FBI CJIS Division.
2. Executive Summary – Key Benchmarks
| Metric | Observed Value | Notes |
|---|---|---|
| Sample size | N = 28 | Completed CJIS Security Policy assessments |
| Average in-scope systems / endpoints | ~42 systems / ~185 endpoints | Wide range by agency size |
| Median formal assessment duration | 22 business days | Kickoff to draft findings package |
| Assessments with ≥1 finding / CAP item | 79% (22 of 28) | Median 3 items when present |
| Percentage requiring additional evidence | 86% (24 of 28) | At least one clarification cycle |
| Local agency vs state / multi-jurisdiction | 64% / 36% | N = 28 |
| Average evidence volume | ~1,280 discrete artifacts | Range approximately 450 – 3,600 |
Findings / CAP Presence (N = 28)
Agency Profile
3. Average Scope Size
Scope size is a primary driver of assessment effort:
- Average in-scope systems / applications: approximately 42
- Average endpoints (workstations, MDCs, servers, network devices): ~185
- Median CJI user population: ~95 personnel
- Smallest observed scope: focused records-management / CAD enclave
- Largest observed scopes: multi-agency shared services and statewide systems
Agencies that clearly documented the CJI boundary, data flows, and advanced authentication requirements consistently experienced more efficient assessments and fewer residual findings related to residual enterprise systems.
4. Median Assessment Duration
Formal assessment duration is measured from assessment kickoff (accepted evidence package) through delivery of the draft findings / assessment report.
- Median formal assessment duration: 22 business days
- 25th percentile: ~14 business days (smaller local agencies, mature packages)
- 75th percentile: ~32 business days
- Longer engagements typically involved multi-site or shared-service environments, incomplete personnel security evidence, or significant mid-assessment evidence remediation
Note: State CSA review cycles, Compact Officer coordination, and FBI-related processes are outside this formal assessment duration metric.
5. Common Failed Objectives / Findings
The following CJIS Security Policy areas most frequently generated residual findings across the N = 28 assessments (an assessment may appear in more than one category):
| Rank | Area | Count | % of N = 28 | Primary Issue |
|---|---|---|---|---|
| 1 | Advanced Authentication / MFA | 18 | 64% | Incomplete MFA for remote or privileged CJI access |
| 2 | Personnel Security (screening, training) | 16 | 57% | Incomplete fingerprint-based checks, training records, or reinvestigation cadence |
| 3 | Audit Logging & Review | 15 | 54% | Incomplete event coverage, retention, or documented review |
| 4 | Media Protection & Sanitization | 12 | 43% | Weak evidence of sanitization / destruction for CJI media |
| 5 | Configuration Management / Baselines | 11 | 39% | Missing or outdated baselines; change control gaps |
| 6 | Boundary Protection / Encryption | 10 | 36% | CJI in transit / at rest encryption or external connection control |
| 7 | Physical Protection | 8 | 29% | Visitor control, server room access, or MDC physical safeguards |
Advanced Authentication / MFA (64% of assessments)
Multifactor authentication incomplete for remote access, privileged accounts, or mobile devices accessing CJI. Advanced authentication requirements remain among the most frequently cited residual findings.
Personnel Security (57%)
Fingerprint-based background checks, security awareness training, and reinvestigation schedules not fully evidenced for all personnel with unescorted CJI access.
Audit Logging & Review (54%)
Required audit events incomplete; logs not retained for the required period; review cadence not documented or evidenced.
6. Evidence Deficiencies
Common evidence weaknesses that drove clarification requests:
- Screenshots without system identifiers, dates, or configuration context
- Personnel security files incomplete or not available for sampling
- Training records missing for contractors or part-time personnel
- Media sanitization certificates or destruction logs absent
- Encryption implementation statements without technical validation evidence
- Policy documents not tailored to the actual CJI environment
- Mobile / MDC configuration and physical control evidence incomplete
Agencies using structured evidence repositories mapped to CJIS Security Policy areas required fewer clarification cycles.
7. Corrective Action / Finding Frequency
- 79% (22 of 28) of assessments resulted in at least one residual finding or CAP item
- Median number of items when present: 3
- Most common categories: advanced authentication, personnel security, audit logging, media protection
Findings and corrective action plans are a normal outcome. Agencies that treated CAP close-out as a managed project (owner, due date, evidence package) achieved timely remediation more reliably than those that deferred documentation.
8. Local Agency vs State / Multi-Jurisdiction Environments
- 64% (18 of 28) — local law enforcement or single-agency environments
- 36% (10 of 28) — state, regional, or multi-jurisdiction / shared-service environments
Local agency assessments generally showed lower average duration and evidence volume when the CJI boundary was well defined. State and shared-service environments more frequently encountered issues with consistent policy application, multi-site logging, personnel security across agencies, and inheritance from statewide systems.
9. Average Evidence Volume & Additional Evidence Requests
- Average discrete artifacts submitted: ~1,280
- Observed range: approximately 450 to 3,600 artifacts
- 86% (24 of 28) required at least one round of additional evidence after initial package review
- Most frequent additional requests: personnel security samples, MFA coverage proof, log samples, media sanitization records, mobile device configuration evidence
10. Most Misunderstood Requirements
- Advanced Authentication scope — under-interpreting which access paths to CJI require MFA (remote, privileged, mobile)
- Personnel security for contractors and vendors — assuming agency employee screening covers all personnel with CJI access
- Audit event content and review — logging some events without required content, retention, or documented review
- Media protection for MDCs and removable media — incomplete sanitization evidence or physical control of mobile devices
- Encryption in transit and at rest — policy statements without technical validation or FIPS-validated module evidence where required
- Cloud / shared responsibility — incomplete documentation of what the CSP vs. agency implements for CJI
- Physical protection of workstations and server rooms — visitor logs, access control, and MDC storage practices under-documented
11. Key Insights for Agencies and Vendors
- 1. Define the CJI boundary early. Clear data-flow diagrams and advanced authentication inventory reduce findings.
- 2. Treat personnel security as operational evidence, not only a policy — screening and training records must be sampleable.
- 3. Prioritize MFA, logging, and media protection. These areas accounted for a disproportionate share of residual findings.
- 4. Map evidence to CJIS Security Policy areas before assessment. 86% of assessments still needed additional evidence.
- 5. Expect findings. 79% of assessments had at least one residual item — plan CAP close-out deliberately.
- 6. Cloud and shared services require explicit responsibility matrices aligned to CJI protection requirements.
12. Authors, Reviewers & How to Cite
Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.
CJIS assessment and advisory leadership; A2LA-accredited FedRAMP 3PAO; Authorized CMMC C3PAO; PCI DSS QSA firm principal. 26+ years in proactive cybersecurity, audit, and compliance.
Technical Review
CJIS Assessment Team, Lazarus Alliance.
How to Cite This Report
Peters, M. D. (2026). 2026 CJIS Certification Benchmark Report: Aggregate Anonymized Insights from Lazarus Alliance CJIS Security Policy Assessments (Version 1.0). Lazarus Alliance, Inc. https://lazarusalliance.com
Recommended short citation: Lazarus Alliance (2026). 2026 CJIS Certification Benchmark Report (N=28).
13. About & Contact
Lazarus Alliance provides CJIS Security Policy assessment and advisory services, is an A2LA-accredited FedRAMP 3PAO, an authorized CMMC C3PAO (CPN 10251), a PCI DSS QSA, and a veteran-owned small business headquartered in Scottsdale, Arizona.
Lazarus Alliance, Inc.
27743 N. 70th Street, Suite 100, Scottsdale, AZ 85266
1-888-896-7580 • [email protected]
https://lazarusalliance.com
© 2026 Lazarus Alliance, Inc. All rights reserved. Proactive Cybersecurity®, Cybervisor®, and IT Audit Machine® are trademarks of Lazarus Alliance or its affiliates. Aggregate data is anonymized; individual assessment outcomes remain confidential. CJIS is a program of the FBI; this report is independent and does not represent FBI or state CSA positions.
Scottsdale, Arizona • 1-888-896-7580 • lazarusalliance.com
Additional Analysis
- How long does a CJIS assessment take?
- 7 Most Common CJIS Assessment Findings
- How much evidence does a CJIS assessment require?
About Lazarus Alliance
To learn more about how Lazarus Alliance can help, contact us.
-
- FedRAMP
- GovRAMP
- NIST 800-53
- DFARS NIST 800-171
- CMMC
- SOC 1 & SOC 2
- C5
- HIPAA, HITECH, & Meaningful Use
- PCI DSS RoC & SAQ
- IRS 1075 & 4812
- CJIS
- LA DMF
- ISO 27001, ISO 27002, ISO 27005, ISO 27017, ISO 27018, ISO 27701, ISO 22301, ISO 17020, ISO 17021, ISO 17025, ISO 17065, ISO 9001, & ISO 90003
- And dozens more!
