CACHelp

Set up CAC on Windows 10 / 11

Get your CAC reader recognized and your DoD certificates installed on Windows in about 15 minutes.

~15 min · 5 steps

Stuck on a specific error? Describe it to the AI assistant for a tailored fix — or check our error code reference.

Steps

  1. 1

    Plug in your CAC reader

    Plug your USB CAC reader into a port directly on your PC (not through a hub). Windows ships with built-in drivers for most modern readers — wait ~30 seconds for the device to install. Open Device Manager and confirm your reader appears under 'Smart card readers'. If it shows a yellow exclamation, see Troubleshooting > unrecognized reader.

  2. 2

    Install DoD certificates

    Download the InstallRoot tool from DISA's PKI page (cyber.mil → PKI/PKE → Tools). Run InstallRoot, choose 'Install DoD Certificates' for the Current User store, and let it complete. This is what 99% of '403.7' / 'certificate required' errors are about.

  3. 3

    Install ActivClient (if your agency requires it)

    Most users on Windows 10/11 do NOT need ActivClient — the built-in Microsoft smart card driver works. You only need ActivClient if your agency mandates it (some Army/Navy environments) or if you're activating PIV. If unsure, skip this step and only install ActivClient if a specific app fails.

  4. 4

    Insert your CAC and test

    Insert your CAC chip-first, gold contacts up. Navigate to a .mil site that requires CAC auth (e.g., webmail.apps.mil). When prompted, select the right certificate: EMAIL for webmail, IDENTITY/AUTH for general sign-on, SIGNATURE for PDF signing.

  5. 5

    Set your clock and timezone

    Half of 'Error 117' / 'Error 310' reports are a clock that's off by more than 5 minutes. Settings → Time & language → Date & time → 'Set time automatically' and 'Set time zone automatically' both ON.

Common problems

Reader not detected

Try a different USB port. Open Device Manager → right-click 'Smart card readers' → Scan for hardware changes.

Wrong cert selected (403.7)

Close all browsers. Open a new browser, navigate to the site, and pick the certificate matching what the site is for (EMAIL/IDENTITY/SIGNATURE).

Edge / Chrome won't prompt for cert

Open Settings → Privacy → Clear browsing data → SSL state. Restart browser.