August 3, 2026

Why “mostly CJIS compliant” is a risky place for public safety agencies to be

Two female lawyers in business suits meet at wooden desk, shaking hands over contract paper.

For public safety agencies, being “mostly compliant” still means some CJIS requirements haven’t been met. New survey data shows where some agencies are struggling and what needs attention before October 2027.

Public safety agencies aren’t treating Criminal Justice Information Services (CJIS) Security Policy compliance casually.

In a survey of 336 public safety professionals, 79% said CJIS compliance is a top or high priority. Yet only 32% said their agencies are fully compliant. Another 59% said they’re mostly compliant.

That gap between priority and completion is the real story.

Most agencies know what’s at stake. They also know the deadline. What they’re struggling with is finishing the work across all systems and users, since they don’t all operate the same way.

That’s what makes “mostly compliant” a difficult position. It may mean the agency has finished much of the work. It also means some CJIS requirements are still unmet, and the remaining work may involve the parts of the environment that are hardest to change.

MFA shows how much work may remain

Only 38% of respondents said multifactor authentication (MFA) was fully implemented for all applicable users and devices. Another 39% said MFA covered most users or devices, but not all. That’s a meaningful difference.

CJIS compliance doesn’t depend on whether MFA is broadly available. It depends on whether MFA is in place where the policy requires it.

The survey results also show why full coverage is difficult for many agencies. Respondents cited challenges in MFA implementation and enforcement, shared devices, consistent policy application, privileged access, and third-party access.

These aren’t separate problems. They all represent significant friction within the same access environment.

An agency may have MFA working well for one group of users and still need a different approach for shared workstations, mobile users, administrators, or vendors. That creates more processes to manage and more places where a requirement may not be applied consistently. And every deviation represents an opportunity to fall farther away from full compliance.

Agencies are dealing with practical limits

The report also explains why agencies haven’t finished. Among respondents who weren’t fully compliant, 47% cited competing priorities. The same percentage cited aging infrastructure and legacy systems. Limited IT or security staff affected 44%, while 40% pointed to the complexity of CJIS requirements. Budget constraints were cited by 34%.

Agencies already rank CJIS compliance as a high priority. But the true challenge is completing the work, despite the obstacles, while supporting daily operations and working with limited staff and budgets.

That changes what useful guidance should look like. Telling agencies that compliance matters doesn’t help. A better approach is to map out a feasible path to compliance.

Before that, however, agencies need a clear view of what remains unfinished. They can’t fix problems if they don’t have a full picture of what needs fixing. They need to take the time to provide an honest audit of how CJIS-ready they are, asking themselves:

  • Which users still fall outside the required MFA process?
  • Which shared devices don’t support individual accountability?
  • Which older applications can’t produce the records the agency needs?
  • Which vendor or privileged accounts still follow a separate process?

Those are specific questions. They also give agencies something they can act on. Visibility into that information is a useful starting point toward achieving comprehensive, thorough CJIS compliance.

October 2027 is closer than it looks

The October 1, 2027, deadline gives agencies time, but not much room for delay. Now is the time to take an honest look at how much more work is needed to achieve full CJIS compliance.

Identifying the necessary changes and implementing them requires communication, time, and a plan of action. Legacy systems take time to address. Shared-device workflows need to be tested with the people who use them. Vendor access involves coordination between multiple teams. MFA projects can stall when one method doesn’t work across every required workflow.

All of that work gets harder when it’s left until the deadline.

Agencies that describe themselves as mostly compliant should use that label as a prompt for a more detailed review. “Mostly” needs to become a defined list of:

  • Open requirements
  • Affected systems
  • Responsible owners
  • Completion dates

The survey findings show that many agencies face the same categories of difficulty: incomplete MFA, shared access, mobile workflows, legacy systems, and limited resources. Overcoming those hurdles is key to meeting the deadline.

Progress matters, but completion matters more

“Mostly compliant” isn’t a failure. It reflects real work and real progress. But it isn’t the finish line.

Before October 2027, agencies need to move from a broad assessment of readiness to a precise understanding of what’s still open.

The most useful question isn’t, “How close are we?” It’s, “What requirements haven’t we met yet, and what will it take to close them?”

See where public safety agencies stand on their path to CJIS compliance in the full survey “CJIS compliance in focus: The identity security challenges facing public safety agencies.”

You are currently browsing

Product availability varies by region. Would you like to choose a different region?

No thank you, I'd like to continue