By NHI Mgmt Group Editorial TeamBased on Imprivata: “Imprivata Research Finds that Only 32% of Public Safety Agencies are Fully Compliant with Criminal Justice Information Services Requirements” (June 30, 2026)

TL;DR: 79% of public safety professionals rate CJIS compliance as a top or high priority, yet only 32% say their agencies are fully compliant, according to Imprivata and Lexipol's survey of 336 public safety professionals. Compliance programmes fail when identity controls slow operations instead of reducing friction, with 95% reporting access or security friction and 47% citing competing priorities and aging infrastructure as barriers.


At a glance

What this is: This research shows that public safety agencies largely understand CJIS compliance requirements, but identity and access friction, legacy systems, and staffing constraints are preventing many from reaching full compliance.

Why it matters: For IAM and PAM teams, this is a reminder that compliance programmes fail when secure access is too slow or inconsistent for operational use, especially in time-sensitive public safety environments.

By the numbers:

  • 79% of public safety professionals say CJIS compliance is a top or high cybersecurity priority.
  • Only 32% report their agencies are fully compliant today.
  • 95% of respondents report experiencing some form of access or security friction when accessing critical systems.
  • Among agencies that are not fully compliant, 47% cite competing agency priorities and 47% cite aging infrastructure and legacy systems as barriers.

Context

CJIS compliance is the governance problem of proving that access to criminal justice data is controlled, accountable, and fast enough for operational use. In public safety, identity security is not a background control because officers, dispatchers, and investigators need reliable access across shared devices, mobile workflows, and legacy systems.

The gap in this research is familiar to IAM leaders: organisations may recognise the policy requirement, but implementation breaks down when authentication, reporting, and access governance add friction. That makes CJIS a useful case study in how identity controls fail when they are designed around compliance checklists rather than mission delivery.

For agencies, the core issue is not whether CJIS matters. It is whether the current identity stack can verify access conditions, maintain auditability, and still support time-sensitive work without repeated logins or inconsistent controls.


Key questions

Q: What breaks when CJIS controls add too much access friction?

A: When CJIS controls slow mission work, users look for shortcuts such as repeated logins, shared access, or inconsistent enforcement. That weakens accountability and makes compliance harder to sustain. The practical test is whether the access path still works under operational pressure without forcing personnel to trade security for speed.

Q: Why do legacy systems make CJIS compliance harder?

A: Legacy systems often lack modern identity integration, consistent logging, and automated deprovisioning. That makes it difficult to prove that access is still valid and monitored across shared devices, records systems, and vendor support paths. The compliance problem is not only technical debt, but evidence debt.

Q: How can public safety agencies tell whether identity controls are actually working?

A: Identity controls are working when personnel can access critical systems quickly and every access event is still traceable for audit and review. Warning signs include repeated logins, slow authentication, and inconsistent controls across shared or mobile environments. If those symptoms persist, the programme is managing policy on paper rather than operational trust.

Q: How should public safety agencies balance CJIS compliance with fast operational access?

A: They should design identity controls around critical workflows, not around idealised user journeys. That means reducing repeated logins, using stronger but lower-friction authentication where appropriate, and reserving elevated access for tightly governed privileged paths. The goal is to preserve accountability without slowing emergency response or investigative work.


Technical breakdown

Why CJIS compliance depends on identity assurance

CJIS compliance requires agencies to know who is accessing criminal justice information, from where, and under what conditions. That creates an identity assurance problem, not just an access policy problem. When agencies rely on shared workstations, mobile users, and fragmented legacy systems, they often cannot enforce consistent authentication or produce reliable evidence for audits. The result is a gap between policy intent and operational control, especially where users move between environments with different trust levels.

Practical implication: map CJIS access paths to identity assurance points so every critical system has a traceable authentication and reporting control.

How access friction undermines security outcomes

The article shows that nearly all respondents experience some form of access or security friction, including multiple logins and slow authentication. That matters because users under pressure will work around controls that interrupt time-sensitive tasks. In mission-critical environments, friction becomes a security risk when it encourages shared credentials, bypass behaviour, or inconsistent enforcement. Security controls only help if personnel can still do their jobs quickly and predictably.

Practical implication: reduce login burden and authentication delays before they become workarounds that weaken compliance and accountability.

Why legacy infrastructure makes modern IAM harder

Legacy systems, aging infrastructure, and limited IT staff create a structural mismatch for modern identity governance. CJIS programmes depend on current inventories, consistent policy enforcement, and the ability to prove control over access events. When older platforms cannot support centralised authentication, device context, or reliable logging, agencies inherit an uneven control surface that is harder to secure and harder to evidence. That is why compliance often stalls even when leadership support is present.

Practical implication: identify which legacy platforms block central identity controls and treat them as compliance dependencies, not isolated technical debt.


NHI Mgmt Group analysis

CJIS compliance fails when identity security is treated as a gate instead of an operating condition: public safety teams cannot trade away speed for control and still expect consistent compliance. The article shows that access friction, legacy systems, and staffing constraints are all part of the same governance problem. When identity controls interrupt mission work, users do not become more secure, they become more likely to route around the control.

Access friction is a compliance defect, not a user-experience complaint: multiple logins and slow authentication are evidence that the control model is misaligned with operational reality. In public safety, that misalignment directly affects whether identity controls are followed, reported on, and sustained. The implication is that compliance programmes should be measured by usable control adoption, not policy existence alone.

Legacy infrastructure creates CJIS governance drag across the whole access lifecycle: once authentication, logging, and reporting are fragmented, agencies cannot easily prove who accessed what, when, and under which conditions. That is a lifecycle governance problem, not a point-in-time configuration issue. The practical conclusion is that compliance architecture must account for systems that cannot natively participate in modern identity assurance.

Identity-centric security is becoming the compliance layer for operational agencies: the more public safety work depends on shared devices, mobile users, and time-sensitive response, the more access governance must be centralised and observable. This is where PAM, authentication policy, and reporting converge. Agencies that separate compliance from operational access design will keep seeing the same gap between intent and execution.

Friction-aware governance is the named concept this research surfaces: secure access in public safety must remain reliable enough for mission use while still producing evidence for CJIS. That concept matters because compliance programmes break when the access path becomes harder to use than the work it protects. Practitioners should treat friction-aware design as a governing principle, not a usability preference.

What this signals

Public safety agencies should treat CJIS as an identity operations problem as much as a compliance one. The survey results show that access friction, not just policy knowledge, is what prevents programmes from maturing into a durable control model.

Friction-aware access governance: CJIS programmes need control designs that preserve speed, auditability, and accountability at the same time. If personnel cannot use the system under pressure, compliance will be bypassed in practice even when it exists on paper.

The forward-looking question for IAM and PAM teams is whether their control stack can handle shared devices, mobile users, and legacy applications without multiplying login burden. Agencies that cannot answer that now will keep seeing the same gap between priority and compliance.


For practitioners

  • Map CJIS controls to actual access workflows Document how officers, dispatchers, analysts, and administrators authenticate across shared devices, mobile endpoints, and legacy applications. Use that map to identify where logging, authentication, or reporting breaks down before compliance evidence is collected.
  • Reduce authentication friction in mission-critical workflows Replace repeated logins and inconsistent prompts with a controlled access pattern that preserves accountability without slowing urgent tasks. The objective is to remove the incentive for workarounds while keeping every access event attributable.
  • Prioritise legacy systems that block centralised governance Inventory aging platforms that cannot support current identity controls, then classify them by their impact on CJIS evidence, access enforcement, and user productivity. Treat those systems as compliance blockers, not just infrastructure debt.
  • Align PAM with the most sensitive CJIS workflows Focus privileged access controls on administrative and high-risk operational paths first, especially where shared access or elevated rights are still used. The goal is to narrow standing privilege where auditability matters most.

Key takeaways

  • The article shows a classic governance gap: public safety leaders understand CJIS requirements, but the identity layer still creates too much operational drag to achieve full compliance.
  • Survey evidence points to a control environment under strain, with widespread friction, legacy constraints, and staffing pressure limiting the effectiveness of access governance.
  • Agencies should treat usability, authentication design, and privileged access together, because compliance will not hold if the mission team cannot use the control in real conditions.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST CSF 2.0, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsCJIS compliance here depends on controlling who can access critical systems and under what conditions.
Recommendation — Apply PR.AA-05 to centralise entitlement control and evidence access conditions across CJIS systems.
CIS Controls v8CIS-5 — Account ManagementRepeated logins, shared access, and staff constraints make account governance central to the article.
Recommendation — Use CIS-5 to tighten account lifecycle governance and eliminate unmanaged access paths in public safety workflows.
NIST SP 800-53 Rev 5IA-5 — Authenticator ManagementThe article centres on authentication friction and the need for reliable identity controls.
Recommendation — Apply IA-5 to manage authenticators in ways that preserve both security and operational speed.
OWASP Non-Human Identity Top 10NHI-10 — Human Use of NHIShared devices and workarounds show how people may misuse access patterns when controls are too slow.
Recommendation — Use NHI-10 to stop staff from reusing or sharing access patterns that undermine CJIS accountability.

Key terms

  • CJIS compliance: CJIS compliance is the operational discipline of protecting criminal justice information through controlled access, logging, and audit-ready procedures. In practice, it spans identity verification, device context, third-party access, and ongoing monitoring, so the programme remains effective after deployment rather than only at certification time.
  • Access Friction: Access friction is the delay, inconsistency, or effort a person experiences when trying to reach a system or task. It becomes a governance issue when it is high enough to encourage shortcuts, exceptions, or support-heavy workarounds that weaken the intended control model.
  • Identity-centric security blueprint: An identity-centric security blueprint is a governance model that treats identity lifecycle, authentication, and privilege as the primary control layer for protecting operations. In OT, it aligns security with how production actually works, so resilience decisions are made around who or what can act, not just where traffic flows.
  • Privilege Access Management: Privilege Access Management is the discipline of controlling and monitoring elevated access to critical systems and data. It governs how privileged accounts, credentials, sessions, and commands are issued, used, recorded, and revoked, so administrative power is limited, traceable, and aligned to policy, risk, and operational need.

Deepen your knowledge

NHI governance, identity lifecycle, and privileged access management are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are responsible for identity security strategy or governance in your organisation, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on July 1, 2026.
Updated on October 8, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org