Parties and Definitions
Clearly identify the agency, vendor, and any subcontractors; define Criminal Justice Information (CJI) and scope to avoid ambiguity in access or data categories.
A CJIS Addendum consolidates security obligations, clarifies each party’s responsibilities, and reduces legal and operational risk by documenting required controls such as background screening, encryption, audit logging, and breach notification procedures.
Agencies, vendors, and third parties that access criminal justice systems must complete a CJIS Addendum before access is granted.
The addendum is a contractual prerequisite for system credentials, network connections, and any production access to CJI.
An Agency IT Director signs to accept technical responsibilities and to confirm that access will follow CJIS Security Policy controls. The director ensures monitoring, incident response coordination, and proof of personnel background checks before granting credentials.
A vendor’s authorized officer attests that the company will implement required safeguards, perform employee vetting, and cooperate with audits. This signature binds the vendor contractually to the agency’s CJIS obligations and reporting timelines.
A government partner required full background checks before network access.
A contractor needed mobile access to law-enforcement-supplied data.
Clearly identify the agency, vendor, and any subcontractors; define Criminal Justice Information (CJI) and scope to avoid ambiguity in access or data categories.
List required controls including encryption standards, multi-factor authentication, endpoint management, vulnerability management, and patching timelines so technical teams can validate configuration.
Specify background check type, frequency, and recordkeeping obligations for staff with access; include requirements for training and revocation upon termination.
Define audit log content, retention periods, access procedures, and who can request logs during an investigation or audit to meet CJIS auditability.
Establish breach reporting timelines, required notices, remediation steps, and responsibilities for forensic support to meet agency investigation needs.
Require vendor flow-downs to subcontractors, approval processes for third-party access, and contractual assurances that subcontractors meet the same CJIS obligations.
| Field | Configuration |
|---|---|
| Authentication Method | Email+SMS or stronger KBA/SSO where required |
| Document Format | Use PDF/A with embedded audit trail |
| Bulk Execution | Enable role-based bulk send for mass onboarding |
| Audit Retention | Retain completion certificates and logs per policy |
Ensure the e-signature platform supports strong authentication, tamper-evident audit trails, and secure storage before executing the addendum.
Often required within 30 days prior to access
Immediate initial notice; full report within agency timeframe
Provide logs and evidence within 30 days commonly
Security controls reviewed at least yearly
Revalidate privileged access on a defined cadence
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | No free trial | No free trial | Yes, limited | Yes, limited |
| Bulk Send | Yes | Yes | Yes | Yes | No |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Yes | Yes | No | No |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |