Purpose and Scope
Define the exact data types, systems, and purposes for which criminal justice information may be accessed and processed; limit use to authorized functions only and list exclusions.
A CJIS Agreement confirms who can access criminal justice data, how that data must be protected, and the penalties for misuse. It is a core control for legal and operational compliance.
Coordination across legal, IT, and compliance teams ensures accurate scope, required attachments, and timely approval before access is granted.
Typically a records custodian, chief information officer, or designated official who has the authority to grant system access and sign on behalf of the agency. This person confirms security controls, approves background checks, and accepts contractual responsibilities for data protection.
A senior representative (CEO, COO, or general counsel) authorized to accept contractual obligations for a vendor or contractor. This signer certifies that the vendor will meet technical safeguards, personnel screening, audit reporting, and any state-specific CJIS requirements.
Define the exact data types, systems, and purposes for which criminal justice information may be accessed and processed; limit use to authorized functions only and list exclusions.
Specify background-screening requirements, frequency of rechecks, disqualifying criteria, and who bears the cost and scheduling of required checks.
List encryption standards, network segmentation, multifactor authentication, logging and monitoring obligations, and retention requirements for audio/video recordings if applicable.
Describe audit trail contents, reporting cadence, retention of logs, and agency rights to inspect or audit vendor systems and compliance evidence.
Define incident notification timelines, responsibilities for containment and remediation, and regulatory reporting obligations including law enforcement notification.
State grounds for suspension or termination of access, remedies for noncompliance, and procedures for secure return or destruction of data after contract end.
| Field | Configuration |
|---|---|
| Signer Order | Set role-based, sequential signing for agency then vendor |
| Authentication | Enable email verification plus SMS or SSO where available |
| Attachments | Require SOC reports, security plans, and BAA as mandatory uploads |
| Retention | Set automatic archival and exportable audit trail retention |
Choose a platform that supports strong audit trails, secure storage, and exportable logs for agency audits and regulatory review.
Allow 5–10 business days for legal and compliance review
Standard checks complete in 7–21 days depending on scope
Provisioning and configuration typically 3–10 business days
Report breaches per agreement timelines, often within 72 hours
Provide requested artifacts within 10–30 business days
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Yes, trial available | Yes, trial available | Yes, limited trial | Yes, limited trial |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No envelope cap | 100 envelopes/user/year | Varies by plan | Varies by plan | Varies by plan |