Browse Definitions:

common access card (CAC)

1. A common access card (CAC) is a Unites States Department of Defense (DoD) smart card for multifactor authentication. CACs are issued as standard identification for active-duty military personnel, reserve personnel, civilian employees, non-DoD government employees, state employees of the National Guard and eligible contractor personnel. In addition to its use as an ID card, a CAC is required for access to government buildings and computer networks.  

A CAC is about the size of a standard debit card and has an embedded microchip that enables the encryption and cryptographic signing of email and use of public key infrastructure (PKI) authentication tools. The microchip contains a digital image of the cardholder’s face, two digital fingerprints, organizational affiliation, Social Security number, agency, card expiration date, and PKI certificate.  

When a CAC is inserted into a smart card reader and the associated PIN has been entered, software in the reader uses standard Internet protocols to compare the information on the card's chip with data on a government server and either grant or deny access.  While a CAC is being used to access a computer system, the card stays in the reader for the duration of the session. When the card is removed from the reader, the session ends and the system remains inaccessible until the next user is validated.

There are currently four kinds of  DoD CAC cards:

  • Geneva Conventions Identification Card - issued to active duty/reserve armed forces and uniform service members. 
  • Geneva Convention Accompany Forces Card - issued to emergency-essential civilian personnel.
  • ID and Privilege Common Access Card - issued to civilians residing on military installations.
  • ID card for DOD/Government Agency identification - issued to civilian employees and contractors.

The DoD began issuing CACs in October 2006 in compliance with Homeland Security Presidential Directive 12/HSPD-12.  

See also:  FIPS, personal identity verification (PIV) cards

2. In general, a common access card is any corporate card issued to an employee that provides the employee access to buildings, company data or facilities such as elevators, bathrooms or copy rooms. 

Learn more about common access cards:

The Department of Defense website has more information about CACs.

Smart cards can be vulnerable to differential power analysis (DPA) attacks.

Common access cards are a new feature for Oracle Database Lite..

This was last updated in November 2010

Join the conversation


Send me notifications when other members comment.

By submitting you agree to receive email from TechTarget and its partners. If you reside outside of the United States, you consent to having your personal data transferred to and processed in the United States. Privacy

Please create a username to comment.

What are the Cryptographic Solutions for CAC?

Would the chip on a CAC be capable of holding data, much like a USB or a memory card?


Dateiendungen und Dateiformate

Gesponsert von:


  • risk map (risk heat map)

    A risk map, also known as a risk heat map, is a data visualization tool for communicating specific risks an organization faces. A...

  • internal audit (IA)

    An internal audit (IA) is an organizational initiative to monitor and analyze its own business operations in order to determine ...

  • pure risk (absolute risk)

    Pure risk, also called absolute risk, is a category of threat that is beyond human control and has only one possible outcome if ...


  • federated identity management (FIM)

    Federated identity management (FIM) is an arrangement that can be made among multiple enterprises to let subscribers use the same...

  • cross-site scripting (XSS)

    Cross-site scripting (XSS) is a type of injection security attack in which an attacker injects data, such as a malicious script, ...

  • firewall

    In computing, a firewall is software or firmware that enforces a set of rules about what data packets will be allowed to enter or...




  • all-flash array (AFA)

    An all-flash array (AFA), also known as a solid-state storage disk system, is an external storage array that uses only flash ...

  • volume manager

    A volume manager is software within an operating system (OS) that controls capacity allocation for storage arrays.

  • external storage device

    An external storage device, also referred to as auxiliary storage and secondary storage, is a device that contains all the ...


  • hybrid hard disk drive (HDD)

    A hybrid hard disk drive is an electromechanical spinning hard disk that contains some amount of NAND Flash memory.