CAC Security Best Practices: Protect Your Card and Identity

Quick answer: Protect a Common Access Card (CAC) as both a controlled government ID and a cryptographic security token. Keep it in your possession, remove it whenever you leave a workstation, never share or write down the PIN, do not let commercial entities copy it, insert it only into appropriately protected authorized systems, and report loss or suspected compromise immediately.

A CAC strengthens authentication, but it cannot make an unapproved computer, fake portal, exposed workspace or careless process safe. Card protection, endpoint security, certificate validation, account authorization and incident reporting are separate layers.

CAC security checklist

Control Safe behavior Warning sign
Possession Remove and take the card whenever you leave the workstation. A card remains unattended in a reader or is surrendered as collateral.
PIN Memorize it and enter it only for an action you initiated. Someone asks for it by phone, email, chat or remote-support session.
Computer Use an authorized, supported and appropriately protected system. A public kiosk, unknown reader or unapproved personal device requests the card.
Website Verify the approved hostname and expected certificate prompt. An unsolicited link produces repeated or unusual PIN/certificate prompts.
Images/copies Use an appropriate alternative ID for commercial transactions. A business wants to scan, photograph or retain the CAC.
Incident Report loss, theft, tampering or unexplained use immediately. Someone offers paid remote “reactivation” or asks for card images.

1. Maintain physical possession

The DoD Cyber Awareness Challenge 2026 card-protection reference describes the CAC/PIV card as a controlled item. It directs users to maintain possession, remove and take it whenever they leave a workstation, and never surrender or exchange it for building access such as a visitor pass.

Do not leave the CAC inserted while stepping away, even if the screen is locked. Follow your organization’s rules for storage, transport and shielded sleeves. If a card leaves your control or shows signs of alteration, contact the security point of contact rather than testing it across multiple systems.

2. Protect the PIN

The PIN unlocks protected operations on the chip. Do not disclose it to a supervisor, help-desk technician, coworker, family member or application developer. Legitimate support may ask you to enter the PIN locally during a test; it should not ask you to read it aloud, type it into chat or store it with the card.

Enter the PIN only after confirming that you initiated the action and recognize the application. Cancel unexpected or repeated prompts. If the PIN is forgotten or locked, official CAC guidance says reset requires identity verification at an issuance/credential PIN reset site; there is no ordinary remote PIN reset.

3. Use the card only on authorized, protected systems

DoD awareness guidance says not to use a CAC/PKI token on publicly accessible computers such as kiosks, internet cafés or public libraries, or on systems lacking current security protections. Authorization matters too: a computer detecting the card does not mean the device is approved for DoD work.

Use supported operating systems, current security updates and organization-approved readers, middleware, VPN clients and browser configurations. Do not disable certificate validation, revocation checks, endpoint protection or browser warnings to make a login succeed. If a reader works on one approved device but not another, diagnose the device configuration rather than weakening controls.

4. Verify websites before presenting credentials

Phishing pages can imitate DoD portals and trigger certificate or PIN interactions. Navigate through a known bookmark, official site or organization-provided address. Check the exact hostname, not just a familiar logo or words somewhere in the URL. Treat shortened links and “urgent certificate update” messages as untrusted until verified through a known channel.

A legitimate TLS padlock does not prove a site is authorized to receive your credential. If the certificate choices, number of prompts or workflow differ from normal, stop and record the hostname, timestamp and error for the help desk.

5. Prevent copying and unnecessary disclosure

The Cyber Awareness Challenge advises avoiding the CAC as photo identification for commercial verification and not allowing commercial entities to photocopy or duplicate it. Use the appropriate driver’s license, passport or other accepted document instead. Do not post a CAC photo on social media or send front/back images through personal email or messaging.

Protect information visible on the card during video calls, photographs and public travel. Do not use the card as a badge holder for unrelated events where it could be photographed or handled by others.

6. Remove the card when the task is complete

Leave a PKI token inserted only while actively using it for a required task. Removing the card helps end some authenticated sessions and prevents another person from initiating chip operations, but it may not close every application or browser session. Sign out and close protected applications according to organizational procedure, then lock or shut down the device as policy requires.

7. Handle travel and remote work separately

Before travel, use the traveling-with-your-CAC checklist for destination approvals, physical custody, public networks and incident reporting. For remote work, use the secure DoD home-office checklist. Neither travel orders nor CAC possession automatically authorizes use of personal equipment or access from every location.

8. Report loss, theft or compromise immediately

If the card is lost, stolen or misplaced, notify the designated security office or sponsor immediately. DoD CAC management guidance requires documentation confirming that a lost or stolen card was reported; the documentation is stored in DEERS as part of replacement. Credentials suspected of unauthorized use can be revoked, including the PKI certificates.

Also report suspected PIN disclosure, card duplication, tampering, unexplained authentication prompts or account activity associated with the card. Do not delay reporting while trying to prove the incident yourself, and do not erase a possibly compromised device unless directed.

9. Keep lifecycle events from becoming security incidents

Check the printed expiration date and renew while the credential is still valid. DoD says CACs can be brought in for renewal up to 90 days before expiration. Use the CAC expiration and renewal checklist to distinguish physical card expiration from a stale or expired certificate error.

Return the CAC when separation, resignation, termination of contract/affiliation or another lifecycle event ends the need for it. A CAC remains U.S. Government property; keeping an invalid card as a souvenir is not an approved disposal method.

Frequently asked questions

Can a help-desk technician ask for my CAC PIN?

No one should ask you to disclose the PIN. You may be instructed to enter it locally for a test you initiated, but do not read it aloud or send it electronically.

Is it safe to leave the CAC inserted if I lock the computer?

DoD awareness guidance says to remove and take the card when leaving the workstation. Locking the screen is still important, but it does not replace physical control of the token.

Can a business photocopy my CAC?

DoD awareness guidance says not to allow commercial entities to photocopy or duplicate the CAC. Offer an appropriate alternative identity document.

Does a CAC protect me from phishing?

No. Certificate-based authentication can strengthen identity assurance, but a fake portal, malicious endpoint or deceptive support request can still create risk. Verify the destination and context before using the card.

Official references

Official CAC protection guidance was checked in August 2026. Organization-specific security policy and reporting procedures take precedence.

For an already blocked credential, follow the CAC PIN lockout and biometric-reset guide; do not disclose the PIN or use an at-home unlock claim.

For shutdown, sleep, VPN, browser and remote-session behavior, use the CAC removal and end-of-session checklist; card removal alone does not close every session.

Mike Thompson

Mike Thompson

Author & Expert

Jason Michael, a U.S. Air Force C-17 pilot, is the editor of CAC Setup.com. Articles covering military life, benefits, and service-member topics are researched, fact-checked, and reviewed before publication. Read our editorial standards or send a correction at the editorial policy page.

75 Articles
View All Posts

Stay in the loop

Get the latest cac setup.com updates delivered to your inbox.