DD Form 2875 – System Authorization Access Request (SAAR)

DD Form 2875 (System Authorization Access Request or SAAR) is the standard Department of Defense form used to request, authorize, and document access to DoD information systems, applications, networks, and data. It validates the trustworthiness of the requester (military members, DoD civilians, and contractors) and records the justification, need-to-know, access type, and security clearance or investigation details.

The current official edition is dated 05/06/2022 (May 2022). The form is managed under OMB Control Number 0704-0630. For form issues or questions, contact the Defense Information Systems Agency (DISA) at [email protected]. The official download is available from the Washington Headquarters Services (WHS) Executive Services Directorate forms site.

Purpose of the DD Form 2875 SAAR

The form supports national security by ensuring only properly vetted individuals receive system access consistent with their clearance, investigation status, and job requirements. It draws authority from Executive Order 10450 (Security Requirements for Government Employment) and related statutes such as the Computer Fraud and Abuse Act.

Key data captured includes identity information, organization and role details, IA (information assurance)/Cyber Awareness training certification, access justification, type of access (Authorized or Privileged), classification level needed, supervisor endorsement, and Security Manager validation of background investigation or continuous evaluation status.

Disclosure is voluntary, but incomplete information can delay or prevent access. The estimated public reporting burden is about 5 minutes per response.

Who Must Complete a DD Form 2875?

Anyone requiring initial access, modification of existing access, or deactivation of accounts on most DoD systems typically needs a SAAR. This includes:

  • Active-duty, Reserve, and National Guard personnel
  • DoD civilian employees
  • Contractors supporting DoD (who must also provide company name, contract number, and expiration date)

Many systems still require a completed and digitally signed DD 2875 (often with a current DoD Cyber Awareness Challenge certificate). Some components, such as certain Army systems, have moved toward automated platforms (for example, Army Account Validation System or enterprise service management tools) and may limit or replace paper/PDF versions for NIPR/SIPR access. Always follow the specific guidance of the system owner or your component.

Official Form Details and Download

  • Form Number: DD 2875
  • Title: System Authorization Access Request (SAAR)
  • Edition Date: 05/06/2022 (previous editions are obsolete)
  • OMB Number: 0704-0630
  • Official SourceWHS ESD DD Forms page and the PDF at the associated Portals link.
  • Contact for Issues: DISA ([email protected])

Download only from official .mil sources. Use Adobe Acrobat (or compatible software that supports CAC digital signatures). Handwritten forms are frequently rejected. Digital signatures via Common Access Card (CAC) are strongly preferred or required by most organizations.

How to Complete DD Form 2875? Overview of the Four Parts

Completion order is important: User → Supervisor/Sponsor → Security Manager → Account preparation staff. Dates are typically entered in YYYYMMDD format. Forms older than 30–60 days (depending on the receiving organization) are often rejected.

Header / Type of Request
Select Initial (new access), Modification (changes to existing access), or Deactivate. Enter the System Name and Location as directed by the specific system or help desk. Enter User ID (often the DoD ID/EDIPI from the back of the CAC) if known or required.

Part I – Completed by the Requester
Provide legal name (Last, First, Middle Initial), organization, office symbol/department, phone (DSN preferred), official email, job title and grade/rank (or “CONT” for contractors), official mailing address, citizenship, and designation (Military, Civilian, or Contractor). Certify completion of current annual Cyber Awareness training and enter the date. Digitally sign and date. The signature acknowledges responsibility for passwords and system access.

Part II – Supervisor / Government Sponsor Endorsement
The supervisor (or government sponsor for contractors) provides a brief, specific justification for access (job duties and systems/roles needed). Select Type of Access Required (Authorized for normal user access; Privileged for elevated rights that can change system configuration). Indicate the classification level needed (Unclassified is most common; Classified or other as applicable). Verify need-to-know. For contractors, complete the access expiration / contract details block. The supervisor digitally signs and dates. Additional blocks may cover Information Owner or ISSO endorsement depending on local process.

Part III – Security Manager Validation
The cognizant Security Manager verifies the type and date of the background investigation, Continuous Evaluation (CE) status/enrollment if applicable, and the access/clearance level granted. The Security Manager signs and dates to confirm the individual meets security requirements for the requested access.

Part IV – Account Preparation
Completed by authorized IT/system staff after approval. This section records the specific account details (system account code, domain, server, application, files, datasets, processing dates, and who processed or revalidated the account).

Optional Block 21 (or equivalent) is used for additional system-specific information, roles, or continuation of justification.

Common Requirements and Best Practices

  • Current DoD Cyber Awareness Challenge (or equivalent IA training) certificate is almost always required and must be within the last 12 months.
  • Digital CAC signatures are preferred; wet signatures or scanned copies are often rejected.
  • Forms must generally be submitted within 30–60 days of the signature dates.
  • Contractors must include accurate contract details and may need additional documents (user agreement, NDA, or rules of behavior).
  • Some systems require supplementary forms or specific wording in the justification block.
  • Keep a copy of the completed, signed form. Originals with signatures in Parts I–III are typically retained for one year after account termination.

Tips for a Successful Submission (U.S. DoD Audience)

  1. Download the current May 2022 version only from official sources.
  2. Read the system-specific instructions first—many organizations provide pre-filled or locked templates or detailed checklists.
  3. Use only official government email addresses.
  4. Ensure all required blocks are complete and accurate before routing for signatures.
  5. Attach the Cyber Awareness certificate and any other required training or agreements.
  6. Route in the correct sequence and allow processing time.
  7. For Army users, check current guidance on automated SAAR processes, as traditional PDF use has been restricted for many NIPR/SIPR systems.
  8. Contact the system help desk or your ISSO/Security Manager early if you have questions.

Frequently Asked Questions

Is the May 2022 version still current?
Yes. Official WHS listings continue to show the 05/06/2022 edition. Local overprints or system-specific versions exist, but the base form remains the 2022 edition.

Do all DoD systems still require a paper or PDF DD 2875?
No. Some components have transitioned to automated account validation and service management platforms. Always follow the instructions provided by the specific system owner.

What if I am a contractor?
Complete all applicable blocks, including company name, contract number, and expiration. Your government sponsor or COR typically handles the supervisory endorsement. Accounts usually expire with the contract unless renewed.

Where do I get help if the form is rejected?
Contact the receiving system’s help desk or your unit ISSO/Security Manager. Common rejection reasons include outdated training, missing signatures, incorrect version, incomplete justification, or expired dates.

Conclusion and Official Resources

DD Form 2875 remains a foundational tool for controlling access to DoD systems and protecting national security information. Using the current official version, completing it accurately with digital signatures, and following component-specific guidance will minimize delays.

Primary official resources:

Always verify the latest instructions with your local security office or the system owner, as processes can vary by component and evolve over time.

Leave a Comment