Legal CJIS Security Addendum
What the Legal CJIS Security Addendum Is and Who It Affects
Why a CJIS Security Addendum Matters for Compliance
A CJIS Security Addendum aligns contractual obligations with the FBI CJIS Security Policy and helps establish lawful controls over access to CJI. It supports enforceability of authentication, audit, and retention requirements and complements federal e‑signature statutes (ESIGN, 15 U.S.C. ch. 96) and state UETA frameworks.
Who Typically Prepares and Signs This Addendum
Agencies, contractors, and vendors that touch Criminal Justice Information use the addendum to document responsibilities before access is granted.
- Law enforcement agencies and CJIS offices — establish baseline controls and onboarding requirements for external partners.
- Cloud service providers and vendors — accept specific technical controls, background check obligations, and incident reporting duties.
- Legal, security, and procurement teams — review language for enforceability, insurance, and audit evidence before execution.
Assign clearly named signatories and designated security contacts to reduce execution delays and ensure audit readiness.
Step-by-Step: Executing a CJIS Security Addendum
-
01Prepare: Populate fields and attach required exhibits
-
02Authorize: Confirm signer authority and corporate approvals
-
03Authenticate: Use MFA or identity proofing for signers
-
04Record: Save signed copy and retain audit trail
Digital Workflow Settings to Configure Before Sending
| Field | Configuration |
|---|---|
| Signer Authentication | Email + SMS code or KBA where required |
| Document Template | Use a locked template with required fields |
| Audit Trail Retention | Retain logs for minimum legal period |
| Automated Routing | Route to security contact after signature |
Typical Routing and Submission Flow
-
Prepare Addendum: Attach exhibits and fill required fields
-
Add Signers: Specify authorized individuals and order
-
Authenticate Signers: Require MFA or identity proofing
-
Archive and Audit: Store signed copy with audit metadata
Technical Capabilities to Check in Your eSignature Platform
Ensure the platform supports the security and evidence requirements the addendum mandates before sending for signature.
- Supported Formats: PDF, DOCX, fillable forms
- Integrations: Salesforce, NetSuite, Microsoft 365
- Auth Options: Email, SMS, KBA, SSO
Prefer platforms that produce tamper-evident signed PDFs, detailed audit trails, and enterprise controls such as SSO and administrative role separation.
Common Timing Considerations and Deadlines
Effective Date:
Agreement operations begin on the signed effective date
Execution Window:
Complete signatures within any stated timeframe (commonly 30 days)
Background Check Frequency:
Initial check pre-access, periodic rechecks per agency policy
Audit Frequency:
Annual or as specified by CJIS authority
Change Notification:
Notify CJIS contact within stated days of material change
Common Preparation and Execution Pitfalls
- Incomplete signer authority details: failing to name an authorized officer delays approval and may require reexecution.
- Ambiguous access levels: generic phrases like 'access as needed' invite audit findings and overbroad privileges.
- Missing security exhibits: omitting technical control exhibits prevents verification of encryption and logging capabilities.
- Weak signer authentication: relying on email-only verification may not meet agency identity proofing requirements.
Consequences of Noncompliance or Improper Execution
eSignature Pricing and Feature Snapshot for CJIS Addenda
| signNow | DocuSign | Adobe Sign | PandaDoc | HelloSign | |
|---|---|---|---|---|---|
| Starting Price | $8/user/mo | $15/user/mo | $14/user/mo | $19/user/mo | $15/user/mo |
| Free Trial | 7-day free trial | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Bulk Send | Yes | Yes | Yes | Yes | Varies |
| Audit Trail | Yes | Yes | Yes | Yes | Yes |
| HIPAA Compliant | Yes | Varies by plan | Varies by plan | Varies by plan | Varies by plan |
| Envelope Cap | No cap | 100 envelopes/user/year | Varies | Varies | Varies |
Illustrative Use Cases for a CJIS Security Addendum
State Agency Integration
An agency requires external vendors to sign a CJIS addendum before CJI access is granted.
- The vendor integrates identity proofing into onboarding.
- The signed addenda and immutable audit logs enable the agency to demonstrate controls during an annual CJIS audit and simplify suspension of access when personnel changes occur.
Contractor Access Agreement
A contractor needs query access for vendor vetting services.
- Background checks and authentication are mandated.
- The contractor signs the addendum, implements MFA and restricted access, and retains certificate logs to show compliance when the client requests evidence.
Frequently Asked Questions About the CJIS Security Addendum
-
Are electronic signatures legally valid?
Yes. Electronic signatures are legally binding under the federal ESIGN Act (15 U.S.C. ch. 96) and state UETA implementations when intent, consent, attribution, and record retention are satisfied.
-
What authentication level is required?
Agencies typically require strong identity proofing such as multi-factor authentication, government ID verification, or KBA where specified by the CJIS authority; email-only verification may be insufficient.
-
Who must sign the addendum?
An authorized officer of the vendor and an agency representative with delegated authority should sign. Naming titles and ensuring signatory authority avoids reexecution delays.
-
How long should records be kept?
Retain signed addenda and audit logs for the period required by applicable laws and agency policy; commonly a minimum of three years with longer retention for HIPAA or state rules.
-
Is remote notarization acceptable?
Remote Online Notarization (RON) depends on state acceptance and agency policy. Verify the state’s RON status and the CJIS authority’s acceptance before relying on remote notarization.
-
How can a signed addendum be revoked?
Revocation procedures should be stated in the addendum. Common steps include written notice, removal of access, and documented confirmation of revocation; follow agency reporting requirements for personnel changes.