The form's banner has a marking drop-down. A completed SAAR contains personal data, so most organizations mark it CUI.
DD 2875: System Authorization Access Request (SAAR)
The MAY 2022 SAAR as printed: Part I requester data, Part II supervisor/owner/ISSO endorsement, Part III security manager validation, Part IV account setup.
Every block on the DD Form 2875
Laid out block for block like the official SYSTEM AUTHORIZATION ACCESS REQUEST (SAAR) (MAY 2022 edition), with the instruction for each block. Name, rank, and unit prefill from your service profile.
- Type of request
- Part i (To be completed by Requester)
- Part ii - endorsement of access by information owner, user supervisor or government sponsor
- Part iii - security manager validates the background investigation or clearance information
- Part iv - completion by authorized staff preparing account information
Type of request
- Classification marking
- Type of Request
- User ID
For a modification or deactivation, the existing user ID.
- Date (YYYYMMDD)
- System Name (Platform or Applications)
The exact system or application name the account office uses.
- Location (Physical Location of System)
Part i (To be completed by Requester)
- 1Name (Last, First, Middle Initial)
- 2Organization
- 3Office Symbol/Department
- 4Phone (DSN or Commercial)
- 5Official E-mail Address
- 6Job Title and Grade/Rank
Civilians: title and grade (Systems Analyst, GS-12). Military: rank and Service. Contractors: "CTR".
- 7Official Mailing Address
- 8Citizenship
- 9Designation of Person
- 10IA Training and Awareness Certification Requirements: I have completed the Annual Cyber Awareness Training. Date (YYYYMMDD)
The completion date on your current DoD Cyber Awareness Challenge certificate. It must be within the last 12 months.
- 11User Signature
Sign with your CAC. By signing you accept responsibility for your password and your use of the system.
- 12Date
Part ii - endorsement of access by information owner, user supervisor or government sponsor
- 13Justification for Access
A short statement of why the account is needed. For a modification, say what's changing and why. Contractors: company name, contract number, and expiration date go in block 16a.
- 14Type of Access Requested
Authorized: normal user access. Privileged: can change system configuration, parameters, or settings (admins).
- 15User Requires Access To
- Classified category / Other (specify)
- 16Verification of Need to Know: I certify that this user requires access as requested.
- 16aAccess Expiration Date (Contractors must specify Company Name, Contract Number, Expiration Date. Use Block 21 if needed.)
Required if access is needed for less than a year.
- 17Supervisor's Name (Print Name)
- 17aSupervisor's Email Address
- 17bPhone Number
- 17cSupervisor's Organization/Department
- 17dSupervisor Signature
- 17eDate
- 18Information Owner/OPR Phone Number
- 18aInformation Owner/OPR Signature
- 18bDate
- 19ISSO Organization/Department
- 19aPhone Number
- 19bISSO or Appointee Signature
- 19cDate
- 20Name (Last, First, Middle Initial)
Auto-filled from block 1 on the fillable PDF.
- 21Optional Information
Anything else the account office needs: contract details that didn't fit in 16a, specific roles or groups, a mirror account to copy.
Part iii - security manager validates the background investigation or clearance information
- 22Type of Investigation
- 22aInvestigation Date
- 22bContinuous Vetting (CV) Enrollment Date
Blank if not enrolled in continuous vetting.
- 22cAccess Level
- 23Verified By (Printed Name)
- 24Phone Number
- 25Security Manager Signature
- 26Verification Date
Part iv - completion by authorized staff preparing account information
- Account information
Completed by the staff who build the account. Site-specific.
- Date Processed
- Processed By (Print name and sign)
- Date
- Date Revalidated
- Revalidated By (Print name and sign)
- Date
How to fill out the DD Form 2875
The DoD-wide request for an account on a network or information system. It proves you're trained, that someone with authority says you need the access, and that your investigation supports it. When: Before you get a network account at a new unit, access to a new application (e.g., GCSS, DTS roles, a SharePoint admin role), a change in privilege level, or when you leave (deactivate).
Step by step
- Top: mark Initial, Modification, or Deactivate, and name the system and its location.
- Part I: your name, organization, office symbol, DSN or commercial phone, official email, job title and grade, and mailing address. Mark citizenship and designation.
- Block 10: complete the annual Cyber Awareness Challenge first and enter the completion date. Sign block 11 digitally with your CAC.
- Part II (your supervisor): justification, authorized vs. privileged access, classification level, need-to-know certification, expiration date, and the supervisor's block 17.
- The information owner/OPR (18) and ISSO (19) sign next. The security manager validates your investigation in Part III.
- Part IV is completed by the account administrator.
What a strong one looks like
- Write the justification as a duty requirement: the system, the role, and the task you can't do without it.
- Privileged access usually needs a separate privileged-user agreement and the right DoDM 8140.03 qualification. Ask your ISSO before you submit.
- Contractors must list company name, contract number, and contract expiration in block 16a.
- Keep the signed PDF. Many units ask for it again at annual revalidation.
Common mistakes
- An expired Cyber Awareness certificate. The ISSO will reject the form.
- Signing with a wet signature when the system owner requires digital signatures (or the reverse).
- Asking for privileged access when authorized access does the job.
- Leaving block 16a blank for access that should expire (contractors, temporary duty).