Establishing secure connection…Loading editor…Preparing document…

Legal CJIS Security Addendum

This template is fully customizable. Edit the text, fill out the fields, and send it for signature. Give it a try!

LEGAL CJIS SECURITY ADDENDUM

This CJIS Security Addendum (the "Addendum") is entered into as of Effective Date: between Agency Name: having principal address at ("Agency"), and Contractor Name: having principal address at ("Contractor"). This Addendum supplements the Underlying Agreement identified as Contract Number: .

RECITALS

WHEREAS, Agency possesses access to Criminal Justice Information ("CJI") protected under federal and state law and governed by CJIS security requirements; and

WHEREAS, Contractor will, in the course of performing services under the Underlying Agreement, have access to, host, process, transmit or store CJI and will be required to meet CJIS security obligations; and

WHEREAS, the parties desire to set forth the additional security, reporting, compliance and flow-down obligations required to protect CJI;

NOW THEREFORE

In consideration of the mutual covenants contained herein and in the Underlying Agreement, the parties agree as follows:

1. DEFINITIONS

"CJI" means Criminal Justice Information as defined by applicable CJIS policy and includes, without limitation, identification data, biometric data, and criminal history record information. "Authorized Personnel" means individuals approved by Agency to access CJI and who have successfully completed required background checks and training. "Covered Systems" means Contractor systems, devices, networks, cloud services and premises that store, process or transmit CJI.

2. SCOPE AND PERMITTED USE

Contractor shall access, use and disclose CJI only as necessary to perform Contractor's obligations under the Underlying Agreement and solely in accordance with applicable CJIS security requirements. Contractor shall not use CJI for any investigation, administrative or operational purpose not expressly authorized by Agency.

3. PERSONNEL SECURITY AND BACKGROUND CHECKS

Contractor shall ensure that all Authorized Personnel who will have access to CJI undergo and pass the fingerprint-based background checks required by CJIS policy prior to any access to CJI. Contractor shall not permit access to CJI by any individual who has not been approved by Agency. Contractor shall immediately remove access and notify Agency if any Authorized Personnel no longer meet clearance requirements.

List of Authorized Personnel or roles requiring access (attach additional sheet if necessary):

4. SECURITY CONTROLS

Contractor shall implement and maintain administrative, technical and physical safeguards that meet or exceed CJIS security requirements, including but not limited to: multi-factor authentication for all remote access to Covered Systems, strong encryption standards for CJI at rest and in transit, role-based access control, least-privilege principles, and continuous logging and monitoring of access to CJI.

Contractor confirms that CJI will be encrypted at rest using algorithm: and encrypted in transit using: .

5. INCIDENT REPORTING AND RESPONSE

Contractor shall notify Agency of any actual or suspected security incident, unauthorized access, or data breach involving CJI within hours of discovery. Notification shall include a description of the incident, affected systems, CJI types involved, corrective actions taken and a remediation plan. Contractor shall preserve all evidence and logs and cooperate fully with Agency and any law enforcement or oversight entity.

Incident contact name: Phone: Email:

6. AUDIT, INSPECTION AND RECORDS

Agency or its designees shall have the right to audit, inspect and monitor Contractor's compliance with this Addendum, including on-site inspections of Covered Systems and review of logs, procedures and background check records. Contractor shall maintain records of all access to CJI and related security events for at least years and shall provide such records upon request.

7. SUBCONTRACTORS AND THIRD PARTIES

Contractor shall not engage any subcontractor to access or process CJI without prior written approval by Agency. All subcontractors shall be bound in writing to the same CJIS security obligations set forth in this Addendum. Contractor shall remain fully liable for the acts and omissions of its subcontractors.

8. TRAINING

Contractor shall ensure that all Authorized Personnel complete CJIS-specific security training prior to access to CJI and annually thereafter. Contractor shall provide training records upon Agency request and certify completion for each individual.

9. DATA RETURN AND DESTRUCTION

Upon expiration or termination of the Underlying Agreement or at Agency request, Contractor shall, at Agency's election, return all CJI to Agency and securely erase or destroy all copies from Contractor systems within days and certify in writing that destruction has been completed, including destruction of backups and residual data.

10. LIABILITY AND INDEMNIFICATION

Contractor shall indemnify, defend and hold harmless Agency from and against any loss, liability, claim, damage, cost or expense arising out of Contractor's breach of this Addendum, unauthorized disclosure of CJI, or Contractor's failure to comply with applicable CJIS security requirements, including reasonable attorneys' fees and regulatory fines to the extent caused by Contractor's acts or omissions.

11. TERMINATION

Agency may immediately suspend Contractor's access to CJI or terminate the Underlying Agreement for material noncompliance with this Addendum. Suspension or termination does not relieve Contractor of obligations to return, destroy or otherwise protect CJI and to cooperate with incident response and audits.

12. NOTICES

All notices required under this Addendum shall be in writing and delivered to the designated notices contact for each party.

13. GOVERNING LAW; VENUE

This Addendum shall be governed by and construed in accordance with the laws of the state of , without regard to its conflict of law principles. Venue for any action arising out of this Addendum shall be in the state or federal courts located within that state.

14. ENTIRE AGREEMENT; SEVERABILITY; AMENDMENT; WAIVER; COUNTERPARTS

This Addendum, together with the Underlying Agreement, constitutes the entire agreement of the parties with respect to CJI protections and supersedes any prior commitments. If any provision of this Addendum is held invalid or unenforceable, the remainder shall remain in full force and effect. This Addendum may be amended only by a written instrument executed by authorized representatives of both parties. No failure or delay by a party in exercising any right shall operate as a waiver.

15. SURVIVAL

The obligations of Contractor with respect to CJI, including but not limited to those in Sections 3, 4, 5, 6, 9 and 10, shall survive termination or expiration of the Underlying Agreement.

CERTIFICATION

Contractor certifies that it understands and will comply with the CJIS security requirements applicable to the Contractor's access to CJI, that it will implement the controls described in this Addendum, and that the statements and representations made herein are true and correct to the best of Contractor's knowledge.

ADDITIONAL SECURITY REPRESENTATIONS

Contractor represents that the Covered Systems are hosted in the following environment (check all that apply):

On-premises infrastructure under Contractor control
Dedicated cloud environment (single-tenant)
Shared/virtualized cloud environment (describe compensating controls below)

ACKNOWLEDGMENT

The undersigned certify that they are authorized to execute this Addendum on behalf of their respective parties and that execution of this Addendum binds their respective party to the terms herein.

Agency:

By:

Date:

Contractor:

By:

Date:

Enter text✕

What the Legal CJIS Security Addendum Is and Who It Affects

A Legal CJIS Security Addendum documents security obligations for any non‑criminal‑justice entity that receives, processes, stores, or transmits Criminal Justice Information (CJI). It supplements primary contracts by allocating responsibilities for access controls, background checks, incident reporting, and auditability consistent with the FBI CJIS Security Policy. The addendum clarifies technical and administrative safeguards, signer authority, and continuity requirements so parties can demonstrate compliance during audits and investigations. signNow is a secure, compliant, and cost-effective eSignature solution used across industries in the United States.

Why a CJIS Security Addendum Matters for Compliance

A CJIS Security Addendum aligns contractual obligations with the FBI CJIS Security Policy and helps establish lawful controls over access to CJI. It supports enforceability of authentication, audit, and retention requirements and complements federal e‑signature statutes (ESIGN, 15 U.S.C. ch. 96) and state UETA frameworks.

Why a CJIS Security Addendum Matters for Compliance

Who Typically Prepares and Signs This Addendum

Agencies, contractors, and vendors that touch Criminal Justice Information use the addendum to document responsibilities before access is granted.

  • Law enforcement agencies and CJIS offices — establish baseline controls and onboarding requirements for external partners.
  • Cloud service providers and vendors — accept specific technical controls, background check obligations, and incident reporting duties.
  • Legal, security, and procurement teams — review language for enforceability, insurance, and audit evidence before execution.

Assign clearly named signatories and designated security contacts to reduce execution delays and ensure audit readiness.

Typical Security and Compliance Elements to Specify

Encryption: TLS 1.2/1.3 in transit
Data at Rest: AES-256 encrypted storage
Audit Trail: Immutable logs, timestamps
HIPAA / BAA: BAA required if PHI present
Authentication: MFA / two-factor recommended
Certifications: SOC 2 Type II, ISO 27001

Step-by-Step: Executing a CJIS Security Addendum

Complete the addendum in the following order to ensure legal clarity and audit readiness.

  • 01
    Prepare: Populate fields and attach required exhibits
  • 02
    Authorize: Confirm signer authority and corporate approvals
  • 03
    Authenticate: Use MFA or identity proofing for signers
  • 04
    Record: Save signed copy and retain audit trail

Digital Workflow Settings to Configure Before Sending

Standardize workflow settings so each execution includes required controls and audit metadata.

Field Configuration
Signer Authentication Email + SMS code or KBA where required
Document Template Use a locked template with required fields
Audit Trail Retention Retain logs for minimum legal period
Automated Routing Route to security contact after signature

Typical Routing and Submission Flow

A predictable routing flow reduces signer confusion and preserves chain of custody for CJI access authorizations.

  • Prepare Addendum: Attach exhibits and fill required fields
  • Add Signers: Specify authorized individuals and order
  • Authenticate Signers: Require MFA or identity proofing
  • Archive and Audit: Store signed copy with audit metadata

Technical Capabilities to Check in Your eSignature Platform

Ensure the platform supports the security and evidence requirements the addendum mandates before sending for signature.

  • Supported Formats: PDF, DOCX, fillable forms
  • Integrations: Salesforce, NetSuite, Microsoft 365
  • Auth Options: Email, SMS, KBA, SSO

Prefer platforms that produce tamper-evident signed PDFs, detailed audit trails, and enterprise controls such as SSO and administrative role separation.

Common Timing Considerations and Deadlines

Document execution triggers several timebound obligations; track effective date, background checks, and periodic audits to remain compliant.

Effective Date:

Agreement operations begin on the signed effective date

Execution Window:

Complete signatures within any stated timeframe (commonly 30 days)

Background Check Frequency:

Initial check pre-access, periodic rechecks per agency policy

Audit Frequency:

Annual or as specified by CJIS authority

Change Notification:

Notify CJIS contact within stated days of material change

Common Preparation and Execution Pitfalls

  • Incomplete signer authority details: failing to name an authorized officer delays approval and may require reexecution.
  • Ambiguous access levels: generic phrases like 'access as needed' invite audit findings and overbroad privileges.
  • Missing security exhibits: omitting technical control exhibits prevents verification of encryption and logging capabilities.
  • Weak signer authentication: relying on email-only verification may not meet agency identity proofing requirements.

Consequences of Noncompliance or Improper Execution

Access Revocation: Contract termination and loss of CJI access
Criminal Liability: Potential state or federal prosecution
Civil Damages: Third-party claims and indemnity exposure
Contract Fines: Monetary penalties per agreement terms
Audit Findings: Corrective action and remediation costs
Breach Costs: Notification, forensic, and regulatory fines

eSignature Pricing and Feature Snapshot for CJIS Addenda

Compare common vendor starting prices and a few compliance-relevant features when selecting an eSignature platform for CJIS addendum workflows.

signNow DocuSign Adobe Sign PandaDoc HelloSign
Starting Price $8/user/mo $15/user/mo $14/user/mo $19/user/mo $15/user/mo
Free Trial 7-day free trial Varies by plan Varies by plan Varies by plan Varies by plan
Bulk Send Yes Yes Yes Yes Varies
Audit Trail Yes Yes Yes Yes Yes
HIPAA Compliant Yes Varies by plan Varies by plan Varies by plan Varies by plan
Envelope Cap No cap 100 envelopes/user/year Varies Varies Varies

Illustrative Use Cases for a CJIS Security Addendum

Real-world scenarios show how the addendum fits into onboarding and vendor management processes.

State Agency Integration

An agency requires external vendors to sign a CJIS addendum before CJI access is granted.

  • The vendor integrates identity proofing into onboarding.
  • The signed addenda and immutable audit logs enable the agency to demonstrate controls during an annual CJIS audit and simplify suspension of access when personnel changes occur.

Contractor Access Agreement

A contractor needs query access for vendor vetting services.

  • Background checks and authentication are mandated.
  • The contractor signs the addendum, implements MFA and restricted access, and retains certificate logs to show compliance when the client requests evidence.

Frequently Asked Questions About the CJIS Security Addendum

Answers to common questions about validity, signatures, retention, and compliance for CJIS addenda.


Need help? Contact support

be ready to get more
Join over 28 million airSlate SignNow users