Skip to main content
Category: Identity & Access Management

Common Access Card

Also known as: CAC, smart card, DoD smart card
Simply put

The Common Access Card (CAC) is the standard identification card issued by the U.S. Department of Defense (DoD) to active duty uniformed Service personnel, Selected Reserve members, and other authorized DoD populations. About the size of a credit card, it is a 'smart' card that stores digital credentials on an embedded chip and is used to verify identity and enable secure access to systems and facilities.

Formal definition

The CAC is a DoD-issued smart card that carries an embedded integrated circuit chip storing Public Key Infrastructure (PKI) credentials, which support functions such as user authentication, digital signature, and encryption. It generally serves as the standard identification credential for active duty uniformed Service personnel, Selected Reserve members, and other authorized DoD personnel, and is commonly used to enable multi-factor authentication and controlled access to DoD information systems and facilities. Specific card contents, issuance eligibility, and technical profiles are governed by DoD policy and applicable federal identity standards; readers should verify current requirements against authoritative DoD and NIST sources, and note that issuance and applicability may differ for other populations and non-DoD environments.

Why it matters

The Common Access Card is a foundational element of the DoD's approach to identity and access management. Because it stores PKI credentials on an embedded chip rather than relying solely on a memorized password, the CAC supports hardware-backed multi-factor authentication, generally combining something the user has (the card) with something the user knows (a PIN). For compliance officers and information system security managers operating within DoD environments, the CAC is often the practical mechanism by which identity assurance and access control requirements are satisfied for personnel accessing DoD information systems and facilities.

It is important to distinguish authentication from authorization: possessing a valid CAC verifies who a user is, but it does not by itself determine what systems, data, or facilities that user is permitted to access. Access decisions remain governed by role, need-to-know, system-specific authorization, and applicable DoD policy. Treating the card as a blanket entry pass rather than one component of a layered identity and access management program is a common misunderstanding that auditors and ISSMs should be prepared to correct.

Who it's relevant to

Information System Security Managers (ISSMs) and system administrators
ISSMs and administrators responsible for DoD information systems typically rely on the CAC as the standard credential for enforcing user authentication and controlled access. They should confirm that CAC-based authentication is implemented consistent with current DoD policy and applicable federal identity standards, and should treat the card as one control within a broader identity and access management architecture rather than a complete access solution.
Compliance officers and auditors in DoD environments
For those assessing DoD systems, the CAC is often evidence of how identity assurance and multi-factor authentication requirements are met. Auditors should verify that CAC usage is documented against current authoritative requirements and should distinguish authentication (identity verification via the card) from authorization decisions, which are governed separately by role and need-to-know.
Active duty personnel, Selected Reserve members, and other authorized DoD populations
The CAC is the standard identification credential issued to active duty uniformed Service personnel, Selected Reserve members, and other authorized DoD populations. Eligibility for issuance is governed by DoD policy, and cardholders should confirm current requirements through official DoD channels, recognizing that issuance criteria may differ across populations.
Government contractors and non-DoD stakeholders
Contractors and personnel in non-DoD environments should be aware that CAC issuance and applicability may differ from DoD populations, and that identity credential requirements outside the DoD are governed by their own applicable policies and standards. Do not assume DoD CAC practices automatically transfer to federal civilian or other environments; confirm requirements against the governing authority for the relevant environment.

Inside CAC

Smart Card Platform
The CAC is a smart card that stores digital credentials on an embedded integrated circuit chip, serving as the physical token for personnel authentication.
PKI Certificates
The card generally carries public key infrastructure (PKI) certificates used for identity authentication, digital signing, and email encryption, enabling cryptographic verification of the holder's identity.
Identity Credential
It functions as the primary identity credential for eligible DoD personnel, including active duty military, selected reserve, DoD civilian employees, and eligible contractors, though eligibility categories should be verified against current DoD policy.
Physical and Logical Access Function
The CAC is commonly used for both physical access to facilities and logical access to DoD information systems and networks, supporting multifactor authentication when combined with a PIN.
Issuing Authority
The CAC is issued and administered under DoD authority as the department's implementation of a Personal Identity Verification (PIV) credential; readers should confirm the specific issuing processes and governing directives against current official DoD sources.

Common questions

Answers to the questions practitioners most commonly ask about CAC.

Does possessing a Common Access Card (CAC) by itself grant a user access to a system or facility?
No. A CAC is an identity credential, not an authorization decision. Possession of a valid CAC generally establishes that the holder has been identity-proofed and issued a DoD credential, but access to any specific system, application, or facility still depends on separate authorization, provisioning, and access control decisions made by the relevant system or facility owner. Authentication (proving who you are with the CAC) should not be confused with authorization (what you are permitted to do). Confirm the specific access requirements against the governing system security documentation and organizational policy.
Is a CAC the same thing as a Personal Identity Verification (PIV) card?
They are related but not identical. The CAC is the DoD implementation of a smart-card identity credential and is often described as PIV-compliant, aligning with the federal personal identity verification approach established for federal employees and contractors. However, the CAC serves the DoD population and carries DoD-specific uses, while PIV cards are issued more broadly across federal civilian agencies. Treating them as interchangeable can lead to errors in cross-agency access assumptions. Verify credential acceptance and interoperability requirements against the applicable agency guidance and the current authoritative issuances.
How is a CAC typically used for logical access to DoD information systems?
In most DoD implementations, the CAC is used as a hardware-based authenticator for multifactor authentication, combining something the user has (the card) with something the user knows (a PIN). It generally supports certificate-based authentication and can be used for functions such as network logon, digital signature, and email encryption where those capabilities are enabled. Actual configuration, supported use cases, and middleware requirements depend on the system and organizational implementation, which should be confirmed against current system documentation.
What should a user do if a CAC is lost, stolen, or damaged?
Report the loss or compromise promptly in accordance with organizational security procedures so the associated certificates can be revoked and the credential deactivated, and obtain a replacement through the appropriate issuance process. Timely revocation is important because a CAC can serve as an authenticator; delaying reporting can leave a window of potential misuse. Specific reporting timelines, points of contact, and reissuance steps are governed by organizational policy and applicable DoD issuances, which should be verified locally.
Does CAC-based authentication satisfy an organization's multifactor authentication requirements?
CAC-based authentication is commonly relied upon to help meet multifactor authentication expectations because it pairs a hardware credential with a PIN. However, whether it satisfies a particular requirement depends on how the relevant control baseline is stated and tailored for the system, the system's categorization, and any agency-specific interpretation. Compliance with an authentication requirement should be assessed against the applicable control set and organizational tailoring rather than assumed, and verified against the current authoritative text.
What is required to use a CAC on a workstation for certificate-based operations?
Using a CAC for logical access generally requires a compatible card reader, appropriate middleware or operating system support for the card, and the relevant trust configuration so that the credential's certificates are recognized and validated. The specific hardware, software, and configuration depend on the environment and organizational standards. Because these requirements vary by implementation and change over time, confirm the supported configuration against current organizational and DoD guidance rather than relying on generalized assumptions.

Common misconceptions

A CAC by itself provides multifactor authentication.
The card is a single factor (something you have). Multifactor authentication is generally achieved only when the CAC is combined with a PIN (something you know), so possession of the card alone does not satisfy MFA requirements.
Possessing a CAC automatically grants access to any DoD system or facility.
The CAC establishes identity, but access to a given system or facility still depends on separate authorization, provisioning, and need-to-know or need-to-access determinations. Authentication is not the same as authorization.
A CAC is equivalent to a security clearance.
The CAC is an identity credential and does not by itself convey a clearance or eligibility to access classified information. Clearance eligibility is determined through separate personnel security processes.

Best practices

Enforce PIN protection on the CAC so that it is used as part of a multifactor authentication scheme rather than relying on card possession alone.
Treat identity authentication via CAC as distinct from authorization, and maintain separate access provisioning and periodic access reviews for systems and facilities.
Establish prompt reporting and revocation procedures for lost, stolen, or compromised cards so associated PKI certificates can be revoked in a timely manner.
Do not conflate CAC issuance with clearance eligibility; verify personnel security determinations through the appropriate separate processes.
Verify current eligibility categories, issuance procedures, and governing DoD directives against official DoD sources, as policies and implementation details may change over time.