CAC

Identité
{# Answer-first lead — frontend-gold-standard §1.1. Expects `lead` (plain text, already resolved by apps.content.leads). Rendered directly under the h1 so the self-contained answer is the first prose a reader, a SERP snippet, or an AI extractor meets. No curated-data gate: the view always supplies either curated content_summary or a computed fallback. #}

Common Access Card -- the US Department of Defense smart card for identification, authentication, and digital signing. It is also written Common Access Card. The term belongs to the Identité section of the smart card glossary.

Embed This Widget

Theme


      
    

Widget powered by . Free, no account required.

Also known as: Common Access Card

CAC -- Common Access Card

The Common Access Card (CAC) is the standard identification smart card issued by the United States Department of Defense to active-duty military personnel, reserve members, civilian employees, and eligible contractors. Serving as both a physical identification badge and a cryptographic credential, the CAC provides authenticated access to DoD buildings, computer networks, and secure communication systems.

Card Contents

Each CAC contains a dual-interface module with multiple X.509 certificates and RSA 2048-bit key pairs for identity authentication, digital signing, and email encryption. The chip stores the cardholder's personal data, an electronic photograph, and two fingerprint biometric templates for identity verification. The cards EEPROM holds multiple applets including a PIV-compatible applet (for interoperability with federal civilian systems) and a legacy CAC applet that supports the DoD's existing PKI infrastructure.

Security and Certification

CAC cards must meet stringent security requirements. The smart card chips are certified to Common Criteria EAL 5+ or higher, and cryptographic modules carry FIPS 140 Level 2 validation. All cryptographic operations -- key generation, signing, and decryption -- occur within the cards secure element, ensuring private keys never leave the chip boundary. The DoD's PKI hierarchy issues certificates through the DoD Root CA and subordinate CAs, with certificate revocation checking enforced through OCSP or CRL distribution points embedded in each certificate.

Lifecycle and Deployment

The DoD issues approximately 3.5 million CAC cards annually through the Defense Manpower Data Center (DMDC). Cards are personalized at RAPIDS (Real-time Automated Personnel Identification System) sites, where electrical personalization loads cryptographic keys and certificates while graphical personalization prints the cardholder photo, name, rank, and agency affiliation. Each card has a three-year lifecycle, after which re-issuance is required. The CAC middleware (ActivClient or similar) enables integration with Windows smart card login, email clients (S/MIME), and web browsers for CAC-authenticated access to DoD portals.

{# FAQ block + FAQPage JSON-LD. Expects `faq_items` = [{"question", "answer"}]. Native
/ (frontend-gold-standard §1.7): the answer text is in the initial HTML and stays reachable with JavaScript disabled, so crawlers and AI extractors read answer-shaped chunks without depending on Alpine. #}

Frequently Asked Questions

What is the smart card glossary and who is it for?

The smart card glossary is a comprehensive reference of technical terms, acronyms, and concepts used in smart card technology. It covers protocols (APDU, T=0, T=1), security (Common Criteria, EAL, HSM), hardware (SE, EEPROM, contact pad), and applications (EMV, ePassport, eSIM). It serves developers, product managers, and engineers.

Are the glossary definitions available in other languages?

Yes. SmartCardFYI provides glossary definitions in 15 languages including English, Korean, Japanese, Chinese, Spanish, Portuguese, Hindi, Arabic, French, Russian, German, Turkish, Vietnamese, Indonesian, and Thai.