TL;DR: 79% of public safety professionals rate CJIS compliance as a top or high priority, yet only 32% say their agencies are fully compliant, according to Imprivata and Lexipol's survey of 336 public safety professionals. Compliance programmes fail when identity controls slow operations instead of reducing friction, with 95% reporting access or security friction and 47% citing competing priorities and aging infrastructure as barriers.
Editorial analysis by NHI Mgmt Group, based on content published by Imprivata: “Imprivata Research Finds that Only 32% of Public Safety Agencies are Fully Compliant with Criminal Justice Information Services Requirements”.
By the numbers:
- 79% of public safety professionals say CJIS compliance is a top or high cybersecurity priority.
- Only 32% report their agencies are fully compliant today.
- 95% of respondents report experiencing some form of access or security friction when accessing critical systems.
Key questions
Q: What breaks when CJIS controls add too much access friction?
A: When CJIS controls slow mission work, users look for shortcuts such as repeated logins, shared access, or inconsistent enforcement.
Q: Why do legacy systems make CJIS compliance harder?
A: Legacy systems often lack modern identity integration, consistent logging, and automated deprovisioning.
Q: How can public safety agencies tell whether identity controls are actually working?
A: Identity controls are working when personnel can access critical systems quickly and every access event is still traceable for audit and review.
Practitioner guidance
- Map CJIS controls to actual access workflows Document how officers, dispatchers, analysts, and administrators authenticate across shared devices, mobile endpoints, and legacy applications.
- Reduce authentication friction in mission-critical workflows Replace repeated logins and inconsistent prompts with a controlled access pattern that preserves accountability without slowing urgent tasks.
- Prioritise legacy systems that block centralised governance Inventory aging platforms that cannot support current identity controls, then classify them by their impact on CJIS evidence, access enforcement, and user productivity.
Bottom line: The article shows a classic governance gap: public safety leaders understand CJIS requirements, but the identity layer still creates too much operational drag to achieve full compliance.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
CJIS compliance fails when identity security is treated as a gate instead of an operating condition: public safety teams cannot trade away speed for control and still expect consistent compliance. The article shows that access friction, legacy systems, and staffing constraints are all part of the same governance problem. When identity controls interrupt mission work, users do not become more secure, they become more likely to route around the control.
A question worth separating out:
Q: How should public safety agencies balance CJIS compliance with fast operational access?
A: They should design identity controls around critical workflows, not around idealised user journeys. That means reducing repeated logins, using stronger but lower-friction authentication where appropriate, and reserving elevated access for tightly governed privileged paths. The goal is to preserve accountability without slowing emergency response or investigative work.
👉 Read our full editorial: CJIS compliance gaps show identity security friction in public safety