Common Access Card
The Common Access Card (CAC) is the standard identification card issued by the U.S. Department of Defense (DoD) to active duty uniformed Service personnel, Selected Reserve members, and other authorized DoD populations. About the size of a credit card, it is a 'smart' card that stores digital credentials on an embedded chip and is used to verify identity and enable secure access to systems and facilities.
The CAC is a DoD-issued smart card that carries an embedded integrated circuit chip storing Public Key Infrastructure (PKI) credentials, which support functions such as user authentication, digital signature, and encryption. It generally serves as the standard identification credential for active duty uniformed Service personnel, Selected Reserve members, and other authorized DoD personnel, and is commonly used to enable multi-factor authentication and controlled access to DoD information systems and facilities. Specific card contents, issuance eligibility, and technical profiles are governed by DoD policy and applicable federal identity standards; readers should verify current requirements against authoritative DoD and NIST sources, and note that issuance and applicability may differ for other populations and non-DoD environments.
Why it matters
The Common Access Card is a foundational element of the DoD's approach to identity and access management. Because it stores PKI credentials on an embedded chip rather than relying solely on a memorized password, the CAC supports hardware-backed multi-factor authentication, generally combining something the user has (the card) with something the user knows (a PIN). For compliance officers and information system security managers operating within DoD environments, the CAC is often the practical mechanism by which identity assurance and access control requirements are satisfied for personnel accessing DoD information systems and facilities.
It is important to distinguish authentication from authorization: possessing a valid CAC verifies who a user is, but it does not by itself determine what systems, data, or facilities that user is permitted to access. Access decisions remain governed by role, need-to-know, system-specific authorization, and applicable DoD policy. Treating the card as a blanket entry pass rather than one component of a layered identity and access management program is a common misunderstanding that auditors and ISSMs should be prepared to correct.
Who it's relevant to
Inside CAC
Common questions
Answers to the questions practitioners most commonly ask about CAC.