CJIS Gap Analysis for Small Agencies: What It Actually Involves
Search "CJIS gap analysis" and almost everything that comes back is a consulting firm offering to run one for you - a scoped engagement, a report, an invoice. That's a legitimate way to get one done. It's also not the only way, and for a small agency without room in the budget for a consulting engagement, it's worth understanding what a gap analysis actually is before deciding you need to pay someone else to do it.
What a gap analysis actually is
A CJIS gap analysis is a structured comparison: here's what the CJIS Security Policy v6.0 requires across its 20 policy areas, and here's what your agency currently has in place. The distance between those two lists is the "gap" - the specific controls that are missing, partial, or undocumented.
That's it. It's not a proprietary methodology. Consulting firms package it with expertise, a report format, and someone else's time - which is genuinely valuable if your agency has neither the time nor the internal familiarity with the policy to do it themselves. But the underlying process is something any agency can run internally, repeatedly, if the controls are already organized in a way that makes comparison possible.
Why a one-time gap analysis has a shelf life
A consulting-delivered gap analysis is usually a snapshot: accurate on the day it's delivered, and slowly less accurate after that as staff change, systems get reconfigured, and evidence expires. For a framework the size of CJIS v6.0 - 1,300+ subcontrols - drift between a snapshot and current reality happens faster than most agencies expect.
The alternative isn't "never pay for expertise." It's treating the gap analysis as something that runs continuously rather than something that happens once a year before an audit. If every control has a current status, evidence, and an owner, the gap between "required" and "implemented" is visible on any given day - not just on the day a consultant delivered a PDF.
Running one internally
A workable internal gap analysis process for a small agency:
- Inventory your CJIS-connected systems - RMS, CAD, mobile data terminals, any cloud service touching CJI.
- Walk the 20 policy areas and mark each control as implemented, partial, or not started. Be honest about "partial" - a policy that exists but isn't followed, or a technical control that's configured but not verified, both count as partial.
- Attach evidence to what's actually done - a screenshot, a signed policy, a configuration export. "We do this" without evidence isn't a completed control from an auditor's perspective.
- Revisit it on a schedule, not just before an audit. Evidence expires, staff change, and configurations drift - a gap analysis done in January can be meaningfully wrong by October.
This is the same process a consulting engagement runs - the difference is whether it happens once, delivered by someone else, or continuously, owned internally.
Where software fits in
This is the actual value case for compliance software over a one-time consulting engagement: not that software is smarter than a human assessor, but that it keeps the comparison current instead of letting it decay between engagements. ComplianceLattice's gap analysis dashboard shows compliance posture across all 20 CJIS v6.0 policy areas with drill-down into individual controls, updated as your agency's actual status changes - not as a report generated once and filed away.
If your agency is deciding between a consulting-led gap analysis and a software-led one, the honest answer is that they're not mutually exclusive. A consultant's judgment is still valuable for interpreting ambiguous requirements or handling a first-time audit. What software changes is whether the gap you're looking at is from six months ago or from this morning.