CMMC Readiness: How to Prepare and Incorporate a Zero Trust Strategy for Your CMMC Scope | Wednesday @ 1:00PM ET

Contact Us
Services
Services
Crypto and Digital Trust
Crypto and Digital Trust
Schellman Training
Schellman Training
Sustainability Services
Sustainability Services
AI Governance
AI Governance
About Us
About Us
Leadership Team
Leadership Team
Corporate Social Responsibility
Corporate Social Responsibility
Careers
Careers
Strategic Partnerships
Strategic Partnerships

Why GovRAMP Is a Strategic First Step Toward CJIS Compliance

Federal Assessments

Published: Oct 5, 2026

If your organization sells cloud-based solutions to state and local police departments, courts, or other criminal justice agencies, you're already familiar with the expectation that Criminal Justice Information Services (CJIS) compliance is essential.

The challenge we regularly see with organizations implementing CJIS requirements is figuring out exactly what "compliant" looks like in CJIS terms, which can feel like a moving target. The CJIS Security Policy is detailed and exacting for good reason as it protects some of the most sensitive data that the government handles. That same rigor has historically made it hard for vendors and agencies to know, with confidence, whether a given cloud solution measures up.

So how does a cloud-based service provider meet the needs of criminal justice agencies? The answer is in the question and it’s already been solved. GovRAMP tailored its extensive NIST 800-53 based framework and incorporated the CJIS Security Policy overlay — and GovRAMP has already shown it's committed to keeping that framework current as CJIS evolves.

In this article, we’ll detail how GovRAMP can help cloud-based service providers meet compliance with CJIS, what’s in the GovRAMP CJIS-aligned overlay and how it eases adoption, what to do after your assessment, and more.

GovRAMP’s CJIS-Aligned Overlay: From CJIS 5.9.5 to CJIS 6.0

GovRAMP officially launched its first CJIS-Aligned Overlay in January 2025, built directly with advisors from the FBI's CJIS Division and shaped by input from state and local government stakeholders, industry leaders, and GovRAMP's own member community. That initial version bridged CJIS Security Policy 5.9.5 with GovRAMP's Moderate Impact Level baseline, which gives agencies and vendors a shared reference point for evaluating a cloud product's CJIS conformance.

GovRAMP was clear from the start that this wasn't going to be a one-time effort and further updates would follow as CJIS policy evolved. When the FBI released CJIS Security Policy 6.0, GovRAMP updated the overlay to match, carrying it through technical review and board adoption in late 2025.

Moreover, GovRAMP is already working on updates to conform to the next version of the CJIS Security Policy v6.1. The GovRAMP CJIS task force will reconvene soon to review proposed updates and once approved, it will be published. The FBI CJIS division is a part of this process.

That kind of follow-through matters because it ensures organizations building toward this overlay aren't chasing a standard that goes stale the moment CJIS policy changes.

What's in the CJIS-Aligned GovRAMP Overlay Today

The current version of the overlay, aligned with CJIS Policy 6.0, includes:

  • All GovRAMP Moderate Baseline controls as the foundation with nothing stripped out or replaced, only strengthened.
  • 16 additional CJIS-specific controls that aren't part of GovRAMP's Moderate Baseline on their own.
  • 68 new parameters covering areas where CJIS spells out details that GovRAMP's baseline doesn't.
  • 105 modified parameters where CJIS sets a stricter bar than the standard GovRAMP requirement.

Note: 123 controls blend requirements from both frameworks into a single, unified requirement.

Here’s a helpful visual of how the GovRAMP overlay melds together the frameworks:

In the example above, you can trace the GovRAMP parameter in red across to the underlined final parameter, which is the highest watermark for PE-8(a) and PE-8(b). The CJIS parameter in yellow is the highest benchmark for PE-8(c) since GovRAMP doesn’t provide a PE-8(c) parameter. The final column, Overlay Parameter, is the overall requirement to meet the GovRAMP and CJIS Overlay PE-8 control.

In another example, PE-8(3) is not selected by GovRAMP, but it is in scope for CJIS. The final column, Overlay Parameter, is the overall requirement to meet the GovRAMP and CJIS Overlay PE-8(3) control.

Why The CJIS-Aligned GovRAMP Overlay Matters for Ease of Adoption

This is the part that should get the attention of any organization currently wrestling with CJIS conformance:

It makes public CJIS-Aligned status: GovRAMP includes a specific designation on their public marketplace listing call the Authorized Product List (APL). This allows easy marketability and easy communication to new agency business.

It consolidates instead of duplicates. Instead of separately tracking CJIS requirements and GovRAMP requirements, the overlay merges them into one framework. That means one assessment path, one set of documentation, and far less redundant effort.

It removes guesswork. Each overlay control maps back to the current CJIS Security Policy, so there's a clear, traceable answer for how each requirement is being met rather than an approximation based on an outdated version.

It gives agencies confidence at the procurement stage. For government buyers, the overlay provides a reliable signal about a product's likelihood of CJIS conformance, which simplifies what has historically been a slow, uncertain evaluation process.

It's built to keep pace with CJIS, not lag behind it. The move from 5.9.5 to 6.0 was the strategic plan all along, and it shows that GovRAMP treats the overlay as a living framework rather than a static checklist that quietly falls out of date.

A Defined Path to Implementation of the CJIS-Aligned Overlay

GovRAMP's CJIS-Aligned Task Force continues to work with stakeholders to support real-world implementation of the overlay, and has laid out a clear path for organizations to follow: 

  1. Review the overlay documentation and understand what's included, added, or modified. 
  2. Map the overlay's controls against your existing security framework to spot gaps. 
  3. Run an internal readiness assessment before bringing in outside validation. 
  4. Engage a third-party independent assessor to formally assess alignment and pursue GovRAMP Authorization, which is something that can be done during an initial assessment, an annual assessment, or mid-cycle for organizations already GovRAMP-authorized. 

Note: It’s also possible to add the CJIS overlay as part of the continuous monitoring cycle during your annual third-party assessment. In this scenario, the assessor would assess according to the higher CJIS standard for all controls already in scope that year and for all controls impacted by the entire CJIS overlay.

What Happens After Your GovRAMP Assessment? 

Once an independent assessor completes the assessment covering the GovRAMP and CJIS scope of controls, the service provider must work with the GovRAMP PMO for onboarding if not already completed. The Service Provider will notify the PMO and upload the package to the GovRAMP repository to begin the review process.

Note: There are no additional fees for the review of CJIS conformance. 

The GovRAMP Approvals Committee handles all reviews of CJIS conformance. Their review will proceed as usual with documentation review, boundary walkthroughs, and SAR/RET review looking for the typical critical areas (e.g., Configuration Settings (CM-6) and conformance to STIG benchmarks (when available), boundary and external services scrutiny, scanning (RA-5), cryptography (SC-13), and overall finding counts). 

The Security Assessment Report (SAR) and Risk Exposure Table (RET) should note any findings applicable to the GovRAMP baseline, CJIS baseline, or both. The CJIS reviewers will scrutinize any CJIS findings and rank them by CJIS Priority Levels 1-4, with Priority 1 issues reviewed closely. It’s possible that before a favorable determination of CJIS alignment is given, the CJIS reviewers may prefer risk mitigation or remediation of Priority 1 issues. 

After approval, the “CJIS Aligned” designation will be added to the Service Provider’s marketplace listing on GovRAMP’s Authorized Provider List (APL). To maintain the CJIS Aligned designation, all annual assessments must cover typical annual assessment scope but continue to use the CJIS Aligned Overlay. 

How to Move Forward with CJIS Compliance on Your Roadmap 

If your organization needs to demonstrate CJIS compliance — whether you're a cloud provider trying to win government contracts, or an agency trying to vet potential vendors — the CJIS-Aligned Overlay gives you a practical, well-supported place to start. It's built on a widely recognized baseline, developed with direct input from CJIS itself, and now proven to track CJIS's own policy updates rather than sit still while the underlying requirements move on. 

Rather than treating CJIS conformance as a separate, parallel undertaking, organizations can approach it as a natural extension of the GovRAMP process they may already know — one that's demonstrably kept current. That alone is worth taking seriously if CJIS compliance is anywhere on your roadmap. 

Want to explore the overlay yourself? GovRAMP's CJIS-Aligned Task Force is the best place to review the controls, understand the mapping to the current CJIS Security Policy, and start planning your organization's path toward conformance. 

Schellman can also help. Our extensive experience as the #1 FedRAMP Independent Assessor on the Marketplace and our GovRAMP expertise can offer prospective cloud service providers key insights from technical details to building a compliance-ready roadmap.

We are also well experienced in handling CJIS compliance assessments for a good number of our clients. If you have questions about your organization’s current standing, how to add CJIS compliance to your roadmap, or how to implement the CJIS-aligned overlay, contact us today to begin the conversation.

About Jon Coffelt

Jon Coffelt is a Director with Schellman based in Northern Virginia. Jon specializes in Federal Assessments (FedRAMP, NIST, CJIS, etc.) and is the practice lead for GovRAMP. Jon’s primary focus is account/client management, project management, assessment, and assurance for commercial organizations across various industries. Prior to joining Schellman in 2017, Jon worked at multiple assessment firms and was in program management for a FedRAMP Cloud Service Provider (CSP).

About Nick Blackbird

Nicholas Blackbird is a Senior Manager with Schellman. Prior to joining Schellman in February 2021, Nicholas worked as a cyber security consultant for a management and information technology firm, specializing in developing cyber security authorization packages and conducting FISMA based assessments for federal systems. Nicholas has over 15 years of experience comprised of serving clients in various industries. Nicholas is now focused primarily on federal assessments for organizations across various industries.