This article was accepted into the corpus but its outbound wikilinks were never NER-processed — typical at the deepest BFS hop or when the run's entity cap was reached. No expansion funnel to show.
| CAC (Common Access Card) | |
|---|---|
| Name | Common Access Card |
| Caption | United States Department of Defense identification card |
| Introduced | 2000s |
| Issuer | United States Department of Defense |
| Type | Smart card, identification, authentication |
CAC (Common Access Card) is a United States Department of Defense identification card that serves as a personal identity verification token for uniformed personnel and civilian employees. It supports public key infrastructure authentication, physical access control, and encrypted communications across multiple DoD systems and federal networks. The card is used by personnel in contexts involving the Department of the Navy, Department of the Army, Department of the Air Force, Department of Homeland Security, and Department of Veterans Affairs for access to classified and unclassified resources.
The CAC functions as a multi-application smart card issued by the Defense Manpower Data Center and managed by the Defense Enrollment Eligibility Reporting System while interfacing with the National Institute of Standards and Technology standards and the Federal Information Processing Standards for cryptographic modules. It contains certificates compliant with the DoD Public Key Infrastructure and leverages technology specifications from companies such as Entrust and ActivIdentity while interoperating with Common Criteria validation processes and Federal PKI policies. Agencies like the Office of Personnel Management, General Services Administration, and National Security Agency reference CAC usage in identity, credential, and access management programs.
Development of the CAC began during modernization initiatives inspired by secure credential projects from the Defense Information Systems Agency, influenced by smart card deployments in the Government of the United Kingdom, Government of Canada, and NATO allied partners. Procurement and lifecycle management involved contractors including Lockheed Martin, General Dynamics, and Northrop Grumman and reflected lessons from earlier credential efforts such as the Personal Identity Verification program, the Department of State electronic passport program, and industry standards promoted by ISO and ANSI. Policy milestones trace to Presidential directives, Congressional oversight hearings, and issuances from the Office of Management and Budget and the Under Secretary of Defense for Acquisition and Sustainment.
The card incorporates an embedded integrated circuit chip, printed security features inspired by techniques used in passport production for the United Kingdom, France, Germany, Japan, and Australia, and a photograph and barcode data consistent with Department of Defense identity guidelines. Cryptographic keys and X.509 certificates are stored on the chip alongside certificate revocation capabilities that reference Certificate Authorities such as the Federal PKI and DoD Root CA while relying on FIPS 140-2 validated hardware from vendors like Gemalto and HID Global. Anti-tamper, holographic laminates, and laser-engraved identifiers borrow from banknote and secure ID practices used by the European Central Bank, Bank of England, and Swiss National Bank to deter counterfeiting.
The CAC enables multifactor authentication for logon to Windows domains and enterprise systems used by the Naval Sea Systems Command, Air Force Materiel Command, and Army Cyber Command, and it supports secure email through S/MIME for users in the Defense Health Agency, National Aeronautics and Space Administration collaborations, and interagency exchanges with the Department of State. It is used for physical access at installations like Fort Bragg, Naval Station Norfolk, and Joint Base Andrews via readers supplied by companies such as HID Global and Johnson Controls, and for transaction signing in logistics systems managed by the Defense Logistics Agency and the Federal Aviation Administration in certain joint programs.
Enrollment procedures take place at RAPIDS (Real-Time Automated Personnel Identification System) stations administered by the Defense Manpower Data Center and follow identity proofing guidance promulgated by the Office of Personnel Management, Homeland Security Presidential Directives, and NIST. Sponsors from unit commands such as U.S. Army Forces Command, U.S. Fleet Forces Command, and U.S. Air Forces in Europe verify eligibility, and issuance requires fingerprint capture, electronic signature, and issuance records archived by the Defense Finance and Accounting Service and personnel systems used by the Office of the Secretary of Defense.
CAC certificates and middleware integrate with third-party applications certified under Federal Information Processing Standards and interoperate with enterprise single sign-on solutions deployed at commands like U.S. Central Command, U.S. European Command, and U.S. Indo-Pacific Command. Cross-certification arrangements support use with partner systems from NATO, the United Kingdom Ministry of Defence, the Canadian Armed Forces, and coalition partners such as Australia and New Zealand, while standards bodies including ISO, IETF, and IEEE inform card interface and reader specifications.
Privacy and security measures reference guidance from the National Institute of Standards and Technology, the Privacy Act overseen by the Office of Personnel Management, and audit regimes conducted by the Government Accountability Office and DoD Inspector General to mitigate risks of credential theft and insider misuse highlighted in cases investigated by the Department of Justice and FBI cyber divisions. Countermeasures include certificate revocation, two-factor authentication mandates, physical security controls used at installations like the Pentagon, and continuous monitoring systems developed in collaboration with vendors such as Splunk, Palo Alto Networks, and CrowdStrike to detect anomalous use and enforce compliance.