All branches · Duty & Accountability · DD Form 2875, MAY 2022 edition

DD 2875: System Authorization Access Request (SAAR)

The MAY 2022 SAAR as printed: Part I requester data, Part II supervisor/owner/ISSO endorsement, Part III security manager validation, Part IV account setup.

Every block on the DD Form 2875

Laid out block for block like the official SYSTEM AUTHORIZATION ACCESS REQUEST (SAAR) (MAY 2022 edition), with the instruction for each block. Name, rank, and unit prefill from your service profile.

Type of request

  • Classification marking

    The form's banner has a marking drop-down. A completed SAAR contains personal data, so most organizations mark it CUI.

  • Type of Request
  • User ID

    For a modification or deactivation, the existing user ID.

  • Date (YYYYMMDD)
  • System Name (Platform or Applications)

    The exact system or application name the account office uses.

  • Location (Physical Location of System)

Part i (To be completed by Requester)

  • 1
    Name (Last, First, Middle Initial)
  • 2
    Organization
  • 3
    Office Symbol/Department
  • 4
    Phone (DSN or Commercial)
  • 5
    Official E-mail Address
  • 6
    Job Title and Grade/Rank

    Civilians: title and grade (Systems Analyst, GS-12). Military: rank and Service. Contractors: "CTR".

  • 7
    Official Mailing Address
  • 8
    Citizenship
  • 9
    Designation of Person
  • 10
    IA Training and Awareness Certification Requirements: I have completed the Annual Cyber Awareness Training. Date (YYYYMMDD)

    The completion date on your current DoD Cyber Awareness Challenge certificate. It must be within the last 12 months.

  • 11
    User Signature

    Sign with your CAC. By signing you accept responsibility for your password and your use of the system.

  • 12
    Date

Part ii - endorsement of access by information owner, user supervisor or government sponsor

  • 13
    Justification for Access

    A short statement of why the account is needed. For a modification, say what's changing and why. Contractors: company name, contract number, and expiration date go in block 16a.

  • 14
    Type of Access Requested

    Authorized: normal user access. Privileged: can change system configuration, parameters, or settings (admins).

  • 15
    User Requires Access To
  • Classified category / Other (specify)
  • 16
    Verification of Need to Know: I certify that this user requires access as requested.
  • 16a
    Access Expiration Date (Contractors must specify Company Name, Contract Number, Expiration Date. Use Block 21 if needed.)

    Required if access is needed for less than a year.

  • 17
    Supervisor's Name (Print Name)
  • 17a
    Supervisor's Email Address
  • 17b
    Phone Number
  • 17c
    Supervisor's Organization/Department
  • 17d
    Supervisor Signature
  • 17e
    Date
  • 18
    Information Owner/OPR Phone Number
  • 18a
    Information Owner/OPR Signature
  • 18b
    Date
  • 19
    ISSO Organization/Department
  • 19a
    Phone Number
  • 19b
    ISSO or Appointee Signature
  • 19c
    Date
  • 20
    Name (Last, First, Middle Initial)

    Auto-filled from block 1 on the fillable PDF.

  • 21
    Optional Information

    Anything else the account office needs: contract details that didn't fit in 16a, specific roles or groups, a mirror account to copy.

Part iii - security manager validates the background investigation or clearance information

  • 22
    Type of Investigation
  • 22a
    Investigation Date
  • 22b
    Continuous Vetting (CV) Enrollment Date

    Blank if not enrolled in continuous vetting.

  • 22c
    Access Level
  • 23
    Verified By (Printed Name)
  • 24
    Phone Number
  • 25
    Security Manager Signature
  • 26
    Verification Date

Part iv - completion by authorized staff preparing account information

  • Account information

    Completed by the staff who build the account. Site-specific.

  • Date Processed
  • Processed By (Print name and sign)
  • Date
  • Date Revalidated
  • Revalidated By (Print name and sign)
  • Date
Draft / worksheet aid. Prepare it here, then transcribe into Your organization's account-request workflow: the digitally signed SAAR routed to the supervisor, information owner, ISSO, and security manager, or an eSAAR portal where one is fielded. This is not an official submission. Check it against the current official DD Form 2875 before use.

How to fill out the DD Form 2875

The DoD-wide request for an account on a network or information system. It proves you're trained, that someone with authority says you need the access, and that your investigation supports it. When: Before you get a network account at a new unit, access to a new application (e.g., GCSS, DTS roles, a SharePoint admin role), a change in privilege level, or when you leave (deactivate).

Step by step

  1. Top: mark Initial, Modification, or Deactivate, and name the system and its location.
  2. Part I: your name, organization, office symbol, DSN or commercial phone, official email, job title and grade, and mailing address. Mark citizenship and designation.
  3. Block 10: complete the annual Cyber Awareness Challenge first and enter the completion date. Sign block 11 digitally with your CAC.
  4. Part II (your supervisor): justification, authorized vs. privileged access, classification level, need-to-know certification, expiration date, and the supervisor's block 17.
  5. The information owner/OPR (18) and ISSO (19) sign next. The security manager validates your investigation in Part III.
  6. Part IV is completed by the account administrator.

What a strong one looks like

  • Write the justification as a duty requirement: the system, the role, and the task you can't do without it.
  • Privileged access usually needs a separate privileged-user agreement and the right DoDM 8140.03 qualification. Ask your ISSO before you submit.
  • Contractors must list company name, contract number, and contract expiration in block 16a.
  • Keep the signed PDF. Many units ask for it again at annual revalidation.

Common mistakes

  • An expired Cyber Awareness certificate. The ISSO will reject the form.
  • Signing with a wet signature when the system owner requires digital signatures (or the reverse).
  • Asking for privileged access when authorized access does the job.
  • Leaving block 16a blank for access that should expire (contractors, temporary duty).
References: DoDI 8500.01, Cybersecurity; DoDM 8140.03, Cyberspace Workforce Qualification and Management Program; DoDI 5200.48, Controlled Unclassified Information (CUI); AR 25-2, Army Cybersecurity; Your system's access control / account management SOP Checked against the official source: Sep 2026 Official blank form
Fill, save & export this worksheetPrefilled from your profile · autosaves to your account · export to PDF. Free to preview, Pro to save & export.
Open it in the toolkit