CJIS 2027 deadline pushes identity past MFA
The FBI's updated CJIS Security Policy tells agencies to think about identity governance as an operational problem, not a compliance checklist, and the October 2027 deadline means the clock on that shift starts now.
TL;DR
The FBI's Criminal Justice Information Services Division has updated its Security Policy with an October 2027 compliance deadline, and public safety agencies are being told to move beyond multifactor authentication toward consistent identity governance, third-party access controls, and centralized accountability. The warning comes from an industry practitioner, not the Bureau itself, but the operational picture is familiar: officers accessing up to 10 systems per shift, cumbersome authentication that users circumvent, and agencies that treat compliance as a last-minute audit exercise rather than a security foundation.

The piece that ran on Federal News Network last week is explicitly a vendor perspective, Nick Stohlman is vice president of CJIS Strategy at Imprivata, which sells identity and access management tools into the public safety market. That doesn't make it wrong. It does mean the reader should understand what's being described is the sales argument agencies will hear between now and October 2027, not a formal FBI implementation guide.
What Stohlman gets right is the collision. Public safety personnel (officers, dispatchers, investigators) routinely access up to 10 separate systems in a single shift. Each manual authentication event is friction. Friction that accumulates over a shift gets worked around, and workarounds become the real access control. The FBI's updated CJIS Security Policy, according to the piece, now pushes agencies past checkbox MFA toward identity governance that spans legacy RMS and CAD systems, modern applications, shared workstations, mobile devices, and contractor access.
What's actually in the policy is harder to pin down
The FBI hasn't published granular penalty structures or a detailed breakdown of which identity governance controls are newly mandated versus inherited from prior CJIS policy versions. The CJIS Advisory Policy Board met in April 2026, per the Federal Register, but the specific text of the updated policy hasn't surfaced publicly in a form that allows line-by-line comparison. A 2019 DOJ CJIN Audit Policy document describes sanctions for noncompliance (up to suspension of system access) but that's the existing enforcement framework, not something new.
The open question for state CISOs and municipal IT directors is whether the updated policy actually requires specific identity governance capabilities or whether the "must think beyond multifactor authentication" framing reflects the vendor community's interpretation of where the requirements are headed. The distinction matters: if the policy mandates centralized identity management and third-party access auditing, the implementation runway is real and the cost is significant. If it doesn't, agencies that buy the full stack in 2026 are acting on sales pressure, not compliance requirements.
The operational argument is the actual news
Whether or not the policy text requires it, the operational logic Stohlman lays out is the argument that'll reach city councils and county procurement offices. The pitch: authentication that creates friction will be circumvented, and the FBI's policy direction (read through the latest updates) is implicitly recognizing that user experience is a security control. Agencies that wait until the final year will be shopping for audit-passing band-aids. Those that start now, the argument goes, get a foundation that survives not just the 2027 deadline but future CJIS revisions.
That's a vendor framing. But it's also a framing state and municipal CISOs should pay attention to, because it's the one their budget authorities will hear repeated for the next twelve months.
Published ·Deep Fathom