By EJN Labs · 29 Jul 2026 · 8 min read
CJSM does not publish a blanket rule that every connected organisation must run an annual penetration test. What you sign up to is an obligation to keep any system that touches CJSM secure, and Ministry of Justice contracts and supplier terms frequently turn that into a demand for independent testing evidence. A typical scoped test takes 4 to 6 days, around £4,800 to £8,400.
Does CJSM require penetration testing?
No. CJSM does not hand every user a clause requiring an annual penetration test. Joining the Criminal Justice Secure eMail service makes you responsible for the security of the systems and devices that connect to it, and any formal testing requirement comes from your justice-sector contracts instead.
The service runs within the Ministry of Justice and HMCTS ecosystem. Whether the responsibility you accept on joining becomes a mandated test depends on who you are and what your contracts with justice-sector bodies actually say.
We see two failure modes: organisations that assume CJSM alone forces a test and burn budget on the wrong scope, and organisations that assume no explicit clause means no obligation, then cannot produce independent evidence when a justice-sector contract comes up for renewal.
Why this matters for criminal justice organisations
CJSM matters because criminal justice material is some of the most sensitive data moved between UK organisations. Case files, witness details, pre-charge correspondence and disclosure bundles all pass through the service, and its user base is broad, reaching well beyond police forces and the courts.
That user base takes in the CPS and probation services alongside defence solicitors, chambers and expert witnesses, plus the vendors and managed service providers who support them.
That breadth is why the security burden sits with members. The secure channel only protects data in transit between CJSM accounts. Once a message lands in your mailbox or syncs to a case management system, its protection depends entirely on your controls. An attacker who compromises a defence firm’s email or a supplier’s remote access gateway gets criminal justice data without touching the CJSM infrastructure itself.
The contractual driver: where testing obligations actually come from
Three sources of obligation stack on top of each other:
- CJSM connection terms. Joining the service means committing to keep connected systems and accounts secure, control who can access them, and report security incidents. This is a duty of care over your estate, not a specification of which assurance activities you must run.
- Contracts with justice-sector bodies. This is where explicit penetration testing requirements usually live. If you supply software, hosting or casework services to the Ministry of Justice, HMCTS, a police force or the CPS, the contract or its security schedule frequently requires independent testing of in-scope systems, often from an accredited firm, with findings remediated. That is a condition of the contract, not a recommendation.
- UK GDPR and professional duties. Criminal offence data carries heightened protection under UK data protection law. Independent testing is one of the clearest ways to evidence that your technical measures are appropriate for the data you hold.
So the accurate position is this: CJSM membership makes you accountable for everything that touches the service, and the moment a justice-sector contract specifies testing, it stops being optional. A small practice with no such contract is not forced to test by CJSM alone, but testing remains the standard way to prove the duty of care you have accepted. Law firms face a similar layered picture, covered in our guide to penetration testing for law firms.
What to test in a CJSM-connected estate
Testing the CJSM service itself is neither possible nor the point; that is the Ministry of Justice’s responsibility. What you scope is everything on your side of the connection that criminal justice data reaches. Four areas dominate:
Email platform and account security
Most members reach CJSM through the webmail portal or a connected mail platform, usually Microsoft 365. We test authentication hardening, MFA coverage and bypass paths, forwarding rules, and whether a phished credential exposes the mailbox history of case correspondence.
Case management and casework applications
CJSM messages rarely stay in email. They get filed into case management systems, document stores and client portals. Testing here focuses on access control between cases and between user roles, since a horizontal access flaw in a casework system exposes exactly the material CJSM was designed to protect. Our API penetration testing service covers the integration layer where casework platforms exchange data.
External perimeter and remote access
Duty solicitor schemes and hybrid working mean case material is routinely accessed from outside the office. We map and test the internet-facing estate: VPN endpoints, remote desktop gateways and anything else an attacker can reach without credentials. See our external infrastructure penetration testing service for how this is run.
Supplier and hosting environments
If you host justice-sector data as a supplier, the cloud environment holding it belongs in scope: identity configuration, segregation between customers, and storage permissions. This is usually the part a security schedule cares most about.
How an engagement runs
A CJSM-driven engagement scopes from the data flow, not the asset list. We map where criminal justice material enters your systems, where it is stored and who can reach it, then agree a scope covering those paths, with any high-risk finding flagged the day it is found.
The report serves two audiences, remediation detail for your IT team or MSP and an executive summary you can hand to a contracting authority, an insurer or the ICO. Retesting of fixed findings is included, and if you are preparing for your first test our penetration testing checklist covers what to have ready.
What it costs and how scope drives the price
Penetration testing in the UK is priced on tester days. Our day rate ranges from £1,200 to £1,400, and the number of days is driven by scope: how many external services, how large the application, how many user roles. Typical ranges look like this:
| Scope | Typical effort | Typical cost |
|---|---|---|
| External perimeter plus email and remote access review | 2 to 4 days | £2,400 to £5,600 |
| Case management web application, multiple roles | 4 to 6 days | £4,800 to £8,400 |
| Combined external, application and cloud supplier estate | 6 to 9 days | £7,200 to £12,600 |
These are typical UK ranges rather than a quote. A small practice using CJSM webmail sits at the bottom of the table; a supplier hosting casework data for multiple justice-sector customers sits at the top. For what drives pricing, see our breakdown of penetration testing cost in the UK, or get an exact figure through our quote form.
How EJN Labs approaches CJSM-connected estates
EJN Labs is a CREST-accredited UK penetration testing firm, and all testing is delivered by UK-based testers, which matters when the data in scope is criminal justice material that should not leave the jurisdiction even during a security test. We hold Cyber Essentials Plus and ISO 27001 ourselves, so your data is managed under the same class of controls your contracting authorities ask of you.
Before quoting we ask how you connect to the service, which systems case material lands in, who accesses it remotely, and whether a specific contract is driving the request. That last question shapes the report: evidence for a supplier assurance process needs different framing from a first test for a defence practice. Our CREST penetration testing service page explains the methodology and deliverables in full.
Frequently Asked Questions
Does CJSM itself mandate a penetration test?
No. No single published CJSM rule forces every member to run a penetration test. Connection terms make you responsible for keeping connected systems secure and controlling access, while explicit testing requirements come from contracts with justice-sector bodies rather than from the service itself.
The Ministry of Justice and HMCTS are the bodies whose contracts carry those requirements, and independent testing of in-scope systems is a common and often mandatory condition for their suppliers.
What does a penetration test for a CJSM-connected organisation cost?
UK penetration testing is priced on tester days at £1,200 to £1,400 per day. An external perimeter plus email and remote access review typically takes 2 to 4 days, £2,400 to £5,600. A case management application test runs 4 to 6 days, £4,800 to £8,400. A combined supplier estate runs 6 to 9 days, £7,200 to £12,600.
Can EJN Labs test the CJSM service itself?
No, and neither can any commercial firm you engage. The CJSM platform is operated within the Ministry of Justice ecosystem and its assurance is handled there. What we test is your side of the connection: the mail platform, case management systems, remote access routes and hosting environments where criminal justice data lands after it leaves the secure channel.
We are a software supplier to a police force. What evidence will they expect?
Expect the security schedule to ask for independent testing of the systems that process force data, usually from an accredited firm, with a report showing findings and remediation. Non-central-government buyers commonly specify a CREST-accredited firm. A test of the application, its APIs and the hosting environment, plus a retest letter confirming fixes, normally satisfies this.
How often should a CJSM-connected organisation test?
Test annually where no contract states a frequency, with an additional test after significant change such as a new case management system, a migration to the cloud or a major change to remote access. That is the working norm for CJSM-connected organisations.
Suppliers should check their security schedule first, since justice-sector contracts often set the testing frequency explicitly.
Get testing evidence your justice-sector contracts will accept
Whether you are a defence practice or a supplier facing a security schedule, the fastest route is a scoped test of the systems your criminal justice data actually touches. Tell us how you connect to CJSM through our CREST penetration testing quote form and we will return a fixed scope and price.




Leave a Reply