7 Most Common CJIS Assessment Findings | Lazarus Alliance

7 Most Common CJIS
Assessment Findings

Ranked Residual Findings from Lazarus Alliance CJIS Assessments

Based on N = 28 completed assessments  •  January 2025 – June 2026  •  Updated August 2026

Across N = 28 completed CJIS Security Policy assessments, 79% (22 of 28) had at least one residual finding. When findings were present, the median number was 3. Rankings below reflect frequency (an assessment may appear in more than one category):

RankAreaCount% of N = 28
1Advanced Authentication / MFA1864%
2Personnel Security1657%
3Audit Logging & Review1554%
4Media Protection & Sanitization1243%
5Configuration Management / Baselines1139%
6Boundary Protection / Encryption1036%
7Physical Protection829%

Most common CJIS assessment finding: Advanced Authentication / MFA — present in 64% (18 of 28) of assessments.

Finding Frequency by Area (N = 28)

#1

Advanced Authentication / MFA (64%)

Primary issue: Incomplete MFA for remote access, privileged accounts, or mobile devices accessing CJI.

Remediation focus: Inventory every CJI access path; enforce advanced authentication consistently; retain configuration evidence.

#2

Personnel Security (57%)

Primary issue: Incomplete fingerprint-based checks, training records, or reinvestigation cadence for personnel with unescorted CJI access (including contractors).

Remediation focus: Maintain sampleable screening and training files for all CJI-access personnel.

#3

Audit Logging & Review (54%)

Primary issue: Incomplete event coverage, retention gaps, or undocumented review cadence.

Remediation focus: Map required events to log sources; evidence review; retain for required period.

#4

Media Protection & Sanitization (43%)

Primary issue: Weak evidence of sanitization/destruction for CJI media; incomplete MDC media controls.

Remediation focus: Document sanitization procedures and retain destruction certificates.

#5

Configuration Management / Baselines (39%)

Primary issue: Missing or outdated baselines; change control gaps for CJI systems.

Remediation focus: Maintain version-controlled baselines and change evidence.

#6

Boundary Protection / Encryption (36%)

Primary issue: CJI in transit/at rest encryption incomplete; external connection control weak.

Remediation focus: Validate encryption implementation; document external connections.

#7

Physical Protection (29%)

Primary issue: Visitor control, server room access, or MDC physical safeguards under-documented.

Remediation focus: Evidence physical access controls and mobile device storage practices.

Related Benchmark Metrics (N = 28)

  • Median formal assessment duration: 22 business days
  • Required additional evidence: 86% (24 of 28)
  • Local vs state/multi-jurisdiction: 64% / 36%

Full context: 2026 CJIS Certification Benchmark Report (Lazarus Alliance).

Authors & How to Cite

Lead Author
Michael D. Peters, CEO & Founder, Lazarus Alliance, Inc.

How to Cite
Peters, M. D. (2026). 7 Most Common CJIS Assessment Findings. Lazarus Alliance, Inc. Data drawn from the 2026 CJIS Certification Benchmark Report (N = 28).

About Lazarus Alliance

Lazarus Alliance provides CJIS Security Policy assessment and advisory services and is headquartered in Scottsdale, Arizona.

Lazarus Alliance, Inc.
1-888-896-7580  •  lazarusalliance.com

© 2026 Lazarus Alliance, Inc. All rights reserved. Findings are observational aggregates and do not predict individual outcomes.

Data Source

This analysis is based on the 2026 CJIS Assessment Benchmark Report, Lazarus Alliance's aggregate analysis of 28 completed formal CJIS 3PAO assessments conducted between January 2025 and June 2026.

Additional Analysis

  1. How long does a CJIS assessment take?
  2. How much evidence does a CJIS assessment require?

Talk with one of our experts

Our Lazarus Alliance Cybervisor™ teams have experience performing thousands of assessments for organizations providing services to clients around the world.

We're here to answer any questions you may have.

Download our company brochure.