The era of "CAC-only" access at the DoD is officially evolving

For years, the Common Access Card has been the gold standard, but it’s often a roadblock in tactical environments or for new recruits. New DoD policy memos just changed the game by formalizing Expanded Authentication.

The Critical Shifts:

  • Beyond the Card: The DoD is authorizing phishing-resistant alternatives like FIDO2 passkeys and biometric tokens for Unclassified and Secret networks.

  • Closing the Gap: New guidance clears the path for recruits, foreign partners, and tactical “edge” operators to access systems before or without a physical CAC.

  • Zero Trust in Action: This moves the department away from “perimeter security” toward a modern, identity-centric model that works anywhere.

This isn’t just a tech upgrade, it’s about faster missions. The DoD is removing credential friction to ensure secure access quickly.

DoD memo’s use cases clarify mission impact of new policies on PKI credentials, expanded authentication | Federal News Network