PAM 25-2-13 — Army Identity, Credential, And Access Management And Public Key Infrastructure Implementing Instructions

PAM 25-2-13 governs Army identity, credential, access management, and public key infrastructure standards and procedures.

Search PAM 25-2-13

  • Publication number: PAM 25-2-13
  • Title: ARMY IDENTITY, CREDENTIAL, AND ACCESS MANAGEMENT AND PUBLIC KEY INFRASTRUCTURE IMPLEMENTING INSTRUCTIONS
  • Date: 04/27/2023
  • Proponent: G-6
  • Status: ACTIVE

View PAM 25-2-13 on armypubs.army.mil

Related publications


PAM 25-2-13 covers electronic identity authentication, authorization, PKI credentials, token issuance, and access controls. It addresses exceptions, alternate multi-factor authentication, external PKI trust, and registration authorities.

Applies to: This pamphlet institutes identity, credential, and access management (ICAM) and public key infrastructure (PKI) standards and procedures for all information technology (IT) capabilities used in and by the Army.

Topics covered

  • Identity authentication
  • Authorization and access privileges
  • Public key infrastructure credentials
  • Alternate multi-factor authentication
  • PKI policy exceptions
  • Token issuance and revocation
  • Registration Authorities and Local Registration Authorities
  • External PKI trust

Questions and answers

What credentials do Army systems use for user identification and authentication?

Per DoDI 8520.03, all Army systems will use PKI credentials as the primary means of user ID and authentication. (paragraph 3-3)

Which networks use CAC and SIPR tokens for access?

The CAC is issued to support NIPRNet access, while a separate SIPR token is used on the SIPRNet. (paragraph 3-3)

What types of subscribers can receive SIPRNet and NIPRNet PKI certificates?

The SIPRNet and NIPRNet PKIs support issuing certificates to three types of subscribers: name, role, and system or device (also called a NPE). (paragraph 4-1)

How long are Army or DoD policy exceptions limited?

Exceptions to Army or DoD policy for users or systems unable to comply with SIPRNet or NIPRNet token use or PKE requirements are limited to 12 months (1 year) but may be renewed. (paragraph 8-2)

When must policy exceptions be requested?

Exceptions must be requested and received prior to system deployment and use. (paragraph 8-1)

Ask Reggie.Bot a question about PAM 25-2-13