Establishing secure connection…Loading editor…Preparing document…

Legal CJIS Addendum

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

LEGAL CJIS ADDENDUM

This CJIS Addendum ("Addendum") is made effective as of Effective Date: by and between Requesting Agency: and Contractor: (each a Party and collectively the Parties).

RECITALS

WHEREAS, Requesting Agency maintains access to criminal justice information and systems subject to the Criminal Justice Information Services security requirements ("CJI"); and

WHEREAS, Contractor will, in the performance of services under the underlying agreement identified as Underlying Agreement Title: dated , have access to, process, transmit or store CJI on behalf of Requesting Agency; and

WHEREAS, the Parties desire to supplement the underlying agreement to ensure that Contractor's access to and handling of CJI complies with applicable CJIS security obligations and to allocate responsibilities for protection of CJI.

NOW, THEREFORE

In consideration of the mutual covenants set forth herein and other good and valuable consideration, the Parties agree as follows:

1. DEFINITIONS

1.1 "CJI" means Criminal Justice Information provided by, or on behalf of, Requesting Agency and any information derived therefrom, including but not limited to biometric data, identity history, offense history, and investigative records. 1.2 "Authorized User" means any individual authorized by Contractor and approved by Requesting Agency to access CJI. 1.3 Terms defined in the underlying agreement have the same meanings when used in this Addendum unless otherwise defined herein.

2. CJIS SECURITY COMPLIANCE

Contractor shall comply with all applicable CJIS security requirements as adopted by Requesting Agency and shall implement administrative, technical and physical safeguards that are no less protective than those required by the CJIS Security Policy. Contractor shall promptly adopt changes to its controls necessary to maintain compliance when Requesting Agency reasonably determines updates are required.

3. PERSONNEL SECURITY

Contractor shall ensure that all Authorized Users and any subcontractor personnel who may access CJI undergo and successfully complete background checks and suitability determinations meeting CJIS requirements prior to access. Contractor shall maintain records of such vetting and make them available to Requesting Agency upon request. Any individual who does not meet Requesting Agency's eligibility standards shall be denied access to CJI.

4. TRAINING AND AWARENESS

Contractor shall provide initial CJIS security awareness and role-based training to Authorized Users before granting access to CJI and shall require annual refresher training thereafter. Contractor shall maintain training records and provide written certification of completion for designated personnel within ten (10) business days of Requesting Agency's request.

5. ACCESS CONTROLS AND AUTHORIZATION

Contractor shall enforce least-privilege access to CJI, employ unique user identifiers, and implement strong authentication consistent with Requesting Agency requirements. Contractor shall maintain an access log and will promptly remove access for users who no longer require it or who are terminated. Remote access to CJI shall be permitted only under encryption and authentication controls approved by Requesting Agency.

6. DATA HANDLING, STORAGE AND TRANSMISSION

Contractor shall store and transmit CJI only on systems and media that meet Requesting Agency's security requirements. CJI shall be encrypted at rest and in transit using cryptographic methods approved by Requesting Agency. Contractor shall not copy, alter, distribute, publish or disclose CJI except as necessary to perform the services set forth in the underlying agreement and in strict accordance with law and Requesting Agency direction.

Contractor shall label or otherwise mark CJI media in accordance with Requesting Agency policy and shall prohibit the use of personally owned devices for the storage or processing of CJI unless expressly authorized in writing by Requesting Agency.

7. INCIDENT REPORTING AND RESPONSE

Contractor shall notify Requesting Agency immediately upon discovery of any suspected or actual unauthorized access, disclosure, loss or misuse of CJI and shall provide a preliminary notification within two (2) hours of discovery by telephone to the designated Requesting Agency contact and a written follow-up within twenty-four (24) hours. Notification shall include a description of the incident, CJI categories affected, steps taken to contain the incident and planned remediation actions.

Contractor shall cooperate fully with Requesting Agency investigations, take reasonable steps to mitigate harm, and preserve and provide logs, forensic images and other evidence as requested.

8. AUDIT, INSPECTION AND RECORDS

Contractor shall permit Requesting Agency, its auditors and authorized oversight entities to inspect and audit Contractor facilities, systems, processes and records relating to CJI protection upon reasonable notice and during normal business hours. Contractor shall promptly remediate any deficiencies identified in an audit and shall provide written evidence of remediation within the timeframes directed by Requesting Agency.

9. SUBCONTRACTORS

Contractor shall not engage subcontractors to access CJI without the prior written consent of Requesting Agency. Contractor shall ensure that any approved subcontractor executes a written agreement imposing on the subcontractor the same duties and obligations imposed on Contractor by this Addendum. Contractor remains fully responsible for subcontractor performance and compliance.

10. RETURN OR DESTRUCTION OF CJI

Upon termination or expiration of the underlying agreement or upon Requesting Agency's request, Contractor shall promptly return to Requesting Agency or securely destroy all CJI and certify in writing within thirty (30) calendar days that such return or destruction has been completed. Destruction must render CJI irrecoverable in accordance with industry standards for secure media sanitization.

11. LIABILITY AND INDEMNIFICATION

Contractor shall be liable for and shall indemnify, defend and hold harmless Requesting Agency from and against any claims, damages, losses, fines or penalties arising out of Contractor's breach of this Addendum or Contractor's negligence or willful misconduct in connection with the access to, handling, or protection of CJI. The Parties' liability obligations under this Addendum are in addition to any remedies available under the underlying agreement.

12. TERM AND TERMINATION

This Addendum shall commence on the Effective Date and remain in force for the duration of the Parties' obligations under the underlying agreement or until earlier terminated in accordance with this Addendum. Requesting Agency may immediately suspend or terminate Contractor's access to CJI for any material breach of this Addendum or for failure to comply with CJIS security requirements.

13. NOTICES

All notices required or permitted under this Addendum shall be in writing and delivered to the addresses set forth below, by hand, courier, or certified mail, or by electronic mail where the Parties have agreed in writing to that method.

14. AMENDMENTS, WAIVER AND SEVERABILITY

No amendment of this Addendum shall be effective unless in writing and signed by both Parties. Failure to enforce any provision shall not be deemed a waiver. If any provision of this Addendum is held invalid or unenforceable, the remaining provisions shall remain in full force and effect.

15. GOVERNING LAW

This Addendum shall be governed by and construed in accordance with the laws of the State of , without regard to its conflicts of law principles.

16. ENTIRE AGREEMENT

This Addendum, together with the underlying agreement, constitutes the entire agreement between the Parties with respect to the handling and protection of CJI and supersedes all prior or contemporaneous agreements, understandings and representations relating to the same subject matter.

17. COUNTERPARTS AND ELECTRONIC SIGNATURES

This Addendum may be executed in counterparts, each of which shall be deemed an original and all of which together shall constitute one instrument. Signatures delivered by electronic means shall be deemed originals for all purposes.

ADDITIONAL INFORMATION

Requesting Agency:

By:

Date:

Contractor:

By:

Date:

Enter text✕

What the Legal CJIS Addendum Is and When It Applies

A Legal CJIS Addendum is a written attachment to a master services agreement that documents how a vendor or partner will access, handle, store, and transmit Criminal Justice Information (CJI). It sets technical, personnel, and audit requirements aligned with the FBI CJIS Security Policy and establishes responsibilities for incident reporting, background checks, and access controls. Agencies and contractors use the addendum to demonstrate that data handling practices meet CJIS minimums before providing access to law enforcement data or systems. The document complements existing contracts and is often required before provisioning credentials or network connectivity.

Why a CJIS Addendum Matters for Compliance and Risk Management

A CJIS Addendum consolidates security obligations, clarifies each party’s responsibilities, and reduces legal and operational risk by documenting required controls such as background screening, encryption, audit logging, and breach notification procedures.

Why a CJIS Addendum Matters for Compliance and Risk Management

Who Typically Completes or Signs a CJIS Addendum

Agencies, vendors, and third parties that access criminal justice systems must complete a CJIS Addendum before access is granted.

  • State or local law enforcement IT teams responsible for granting access and ensuring policy compliance.
  • Vendors and cloud providers who store, process, or transmit CJI on behalf of an agency.
  • Legal counsel and compliance officers who review contractual and regulatory obligations.

The addendum is a contractual prerequisite for system credentials, network connections, and any production access to CJI.

Common Signatory Roles

Agency IT Director

An Agency IT Director signs to accept technical responsibilities and to confirm that access will follow CJIS Security Policy controls. The director ensures monitoring, incident response coordination, and proof of personnel background checks before granting credentials.

Vendor Authorized Officer

A vendor’s authorized officer attests that the company will implement required safeguards, perform employee vetting, and cooperate with audits. This signature binds the vendor contractually to the agency’s CJIS obligations and reporting timelines.

Security and Compliance Elements to Include

Encryption: TLS 1.2/1.3 and AES-256 at rest
Access Control: Role-based access lists and MFA
Background Checks: FBI fingerprint-based or state equivalent
Audit Logging: Immutable logs with timestamps
Incident Response: Timely notification and remediation
Data Segregation: Logical separation of CJI from other data

Key Risks and Contractual Consequences

Unauthorized Disclosure: Criminal and civil exposure
Access Revocation: Immediate suspension of credentials
Contract Termination: Breach-based termination rights
Regulatory Fines: State or federal penalties possible
Litigation: Potential third-party claims
Reputational Harm: Loss of future contracts

Common Preparation Errors to Avoid

  • Leaving personnel vetting obligations vague or unspecific, which delays agency approval and credential issuance.
  • Failing to include specific encryption algorithms or key management responsibilities, leading to technical rejection during security review.
  • Omitting audit log retention periods and access procedures, creating gaps for forensic response and compliance evidence.
  • Using generic breach-notification timelines instead of the agency’s required reporting window, which can trigger contractual penalties.

How Agencies and Vendors Use CJIS Addenda in Practice

Real-world examples illustrate how addenda resolve technical questions and accelerate secure onboarding.

Optica Ventures — Onboarding

A government partner required full background checks before network access.

  • Vendor completed fingerprint-based checks and provided certificates of completion.
  • The documented process allowed secure provisioning within two weeks while meeting agency audit expectations and avoiding repeated rework.

Martin Properties — Field Access

A contractor needed mobile access to law-enforcement-supplied data.

  • The addendum specified device controls and encryption standards.
  • With agreed controls in place, the contractor received monitored, role-limited access without changing the core contract.

Step-by-Step: Completing a Legal CJIS Addendum

Follow these sequential steps to prepare, review, and finalize a CJIS Addendum for agency or vendor use.

  • 01
    Gather Parties: List legal names and contacts for agency and vendor.
  • 02
    Define Scope: Specify systems, data types, and access levels.
  • 03
    List Controls: Document encryption, MFA, background check, and logging controls.
  • 04
    Sign and Archive: Obtain authorized signatures and store records securely.

Typical Workflow From Draft to Access

This flow shows how the addendum moves from draft to operational access when both parties comply with CJIS expectations.

  • Drafting: Agency or vendor prepares a draft addendum.
  • Technical Review: Security teams confirm controls and gaps.
  • Legal Review: Counsel confirms contractual obligations and liability.
  • Execution: Authorized signatories sign and access is provisioned.

Core Sections Every Professional CJIS Addendum Should Contain

A complete addendum organizes legal, technical, and operational obligations so both parties can verify compliance and auditability.

Parties and Definitions

Clearly identify the agency, vendor, and any subcontractors; define Criminal Justice Information (CJI) and scope to avoid ambiguity in access or data categories.

Security Controls

List required controls including encryption standards, multi-factor authentication, endpoint management, vulnerability management, and patching timelines so technical teams can validate configuration.

Personnel Vetting

Specify background check type, frequency, and recordkeeping obligations for staff with access; include requirements for training and revocation upon termination.

Audit and Logging

Define audit log content, retention periods, access procedures, and who can request logs during an investigation or audit to meet CJIS auditability.

Incident Notification

Establish breach reporting timelines, required notices, remediation steps, and responsibilities for forensic support to meet agency investigation needs.

Subcontractors and Transfers

Require vendor flow-downs to subcontractors, approval processes for third-party access, and contractual assurances that subcontractors meet the same CJIS obligations.

Digital Workflow Settings for an Online CJIS Addendum

Configure your e-signature workflow to preserve auditability and meet authentication requirements.

Field Configuration
Authentication Method Email+SMS or stronger KBA/SSO where required
Document Format Use PDF/A with embedded audit trail
Bulk Execution Enable role-based bulk send for mass onboarding
Audit Retention Retain completion certificates and logs per policy

Platform Capabilities to Support CJIS Compliance

Ensure the e-signature platform supports strong authentication, tamper-evident audit trails, and secure storage before executing the addendum.

  • Integrations: Salesforce, NetSuite, Microsoft 365
  • Formats: PDF, DOCX, HTML compatibility
  • Security: AES-256 at rest, TLS in transit

Typical Timelines and Response Expectations

Set and document timelines for background checks, incident notifications, audit responses, and periodic reviews to align with agency expectations.

Background Check Completion:

Often required within 30 days prior to access

Incident Notification Window:

Immediate initial notice; full report within agency timeframe

Audit Response Time:

Provide logs and evidence within 30 days commonly

Annual Review:

Security controls reviewed at least yearly

Access Revalidation:

Revalidate privileged access on a defined cadence

eSignature Pricing and Feature Comparison For CJIS Addendum Execution

Compare core pricing and compliance features that affect how you execute and manage CJIS Addenda; signNow is listed first per platform comparison conventions.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial No free trial No free trial Yes, limited Yes, limited
Bulk Send Yes Yes Yes Yes No
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Yes Yes No No
Envelope Cap No cap 100 envelopes/user/year Varies Varies Varies

Frequently Asked Questions About the Legal CJIS Addendum

Answers to frequent questions about validity, signatures, and practical execution of CJIS Addenda.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users