If your CAC reader is not working on Windows 11, do not assume the Windows update broke the reader. First determine which layer is failing: the USB reader, Windows smart-card services, the certificates on the card, or the specific website. The checks below move from low-risk hardware tests to certificate and site diagnostics.
This guide applies to current Windows 11 releases, including computers that were originally upgraded through 22H2. The “22H2” wording remains in this page’s address because people still find it through that search, but there is no reliable basis for blaming every CAC failure on that release or on a particular Intel or AMD chipset-driver version.
Fast diagnosis:
- Reader missing from Device Manager: troubleshoot the USB port, hub, reader or reader driver.
- Reader appears, but
certutil -scinfocannot see a card: check card insertion, the Smart Card service and another known-good card or reader. - Certificates appear, but one website fails: the reader is probably working; investigate certificate selection, browser state, trust or site authorization.
- Managed government computer: document the symptom and contact your organization’s help desk before changing drivers or middleware.
1. Protect the card and computer first
Keep normal Windows security updates enabled. Do not download anonymous “CAC drivers,” disable antivirus software, edit the registry, remove certificate containers or install old chipset packages as a first response. Those steps can introduce a security problem without fixing the actual failure.
Never share your CAC PIN, certificate details, screenshots containing personal information or card identifiers. Do not repeatedly enter a PIN after a failed attempt; follow your issuing organization’s process if the card becomes locked. On a government-furnished device, use only software and support channels approved by your organization.
2. Check the physical reader
- Remove the CAC and unplug the reader.
- Reconnect the reader directly to the computer, preferably without a dock or unpowered USB hub.
- Insert the card fully and note whether the reader’s indicator changes.
- Try another USB port. If possible, test one variable at a time: the same reader with another known-good CAC, or the same CAC with another approved reader.
A light only proves that the reader receives power. It does not prove that Windows can communicate with the card. If the reader fails on multiple computers, the reader may be defective. If the same CAC fails in multiple known-good readers, contact the card-issuing or local support office rather than modifying Windows.
3. Confirm that Windows detects the reader
Right-click Start, open Device Manager, and expand Smart card readers. The reader should normally appear by its manufacturer or model. Also check Other devices for an unknown device or warning symbol.
- Reader is listed without a warning: continue to the certificate test. Device Manager alone cannot prove that the CAC certificates are usable.
- Reader has an error: open Properties and record the exact status and error code. Use Update driver to let Windows search, or obtain the correct driver only from Windows Update, your computer/reader manufacturer, or your organization.
- Reader is absent: use Action → Scan for hardware changes, reconnect it directly, and test another port. A reader that remains absent is a hardware/USB issue, not a browser-certificate problem.
Microsoft documents Windows smart-card readers as Plug and Play devices and explains that Windows can obtain compatible smart-card components through its discovery and update process. A reader vendor may still require a model-specific driver, but motherboard-chipset downgrades should not be the default CAC fix.
4. Check the Windows Smart Card service
Press Windows+R, enter services.msc, and find Smart Card. If it is stopped, choose Start. Do not change organization-managed service policies; if the service is disabled or cannot start on a managed device, capture the displayed error and contact IT.
You can then remove and reinsert the card. If Windows reacts to the insertion but the intended site still fails, continue to the certificate check instead of repeatedly reinstalling the reader.
5. Ask Windows whether it can see the CAC certificates
Open Command Prompt and run:
certutil -scinfo
Microsoft lists this command as the standard way to display smart-card information and available certificates. A PIN is not required merely to list them; Microsoft says you can press Esc if prompted. Read the output—do not use certificate-deletion options.
- No reader found: return to the USB, Device Manager and Smart Card service checks.
- Reader found, no card: reseat the CAC and test a known-good card/reader combination.
- Certificates are listed: the hardware path and card communication are working. Move to browser, trust and site-specific checks.
- Certificate or provider error: save the exact error text for your help desk. The reader driver may be fine while card middleware, a minidriver or certificate provisioning needs attention.
6. Separate a reader failure from a website failure
Close all browser windows, remove the CAC, reopen the browser and then insert the card before visiting the official site again. If a certificate picker appears, select the certificate type required by that service. Authentication, signing and encryption certificates are not interchangeable.
Test a second official CAC-enabled service that you are authorized to use. If one works and another does not, the reader itself is not the likely cause. The failing service may require a different certificate, an approved network or VPN, current account authorization, or help from that service’s support team.
Do not use a random third-party “CAC test” website. A test should be an official service you already have permission to access. Never approve an unexpected signing request.
7. Verify DoD trust and approved middleware
Windows 11 includes native smart-card capabilities, but the complete configuration depends on the card, organization and application. The DoD Cyber Exchange describes middleware as the component that allows certificates stored on a CAC to interface with public-key-enabled applications and publishes current end-user configuration resources.
Use your component’s instructions for middleware. Do not assume that ActivClient is required for every personal Windows 11 computer, and do not install a consumer download on a managed workstation. If an official site reports an untrusted issuer rather than failing to detect the card, use the current DoD Cyber Exchange getting-started material or your organization’s approved installer for DoD root and intermediate certificates.
8. What to do after a Windows update
If the problem began immediately after an update, record the update name, Windows build, reader model, Device Manager status and certutil -scinfo result. Then install any newer normal Windows and approved manufacturer updates and restart once. A timing correlation does not establish that Windows changed the USB authentication protocol or that a particular driver number is defective.
On a personal computer, Windows’ built-in update history and Device Manager can help support identify what changed. On a managed computer, report the evidence to IT; administrators can correlate it with deployment rings and logs. Do not pause security updates for weeks or force an unverified older chipset driver simply because the failure followed an update.
9. Escalate with useful evidence
Contact your local help desk, component PKI/PKE contact, card-issuing office, reader manufacturer or the affected service’s support team as appropriate. Provide:
- Windows edition and build from Settings → System → About;
- reader manufacturer and exact model;
- Device Manager category, status and error code;
- whether the reader works in another USB port or computer;
- whether another known-good card works in that reader;
- the non-sensitive result or exact error from
certutil -scinfo; - whether all CAC sites fail or only one;
- the update or software change immediately preceding the problem.
Do not include your PIN, private keys, full certificate serial numbers or unnecessary personal information.
Frequently asked questions
Did Windows 11 22H2 break all CAC readers?
No. Individual devices can fail after an update, but that timing alone does not prove a universal Windows 11 22H2 USB or CAC defect. Diagnose the reader, service, card certificates and target site separately.
Should I roll back my Intel or AMD chipset driver?
Not as a general troubleshooting step. Use Windows Update or an approved driver from the computer or reader manufacturer. On a managed device, let IT evaluate any rollback using the exact hardware ID and error evidence.
Do I need ActivClient on Windows 11?
It depends on the organization, card and application. Follow your component’s approved configuration rather than installing middleware based on a generic article.
Why can Windows see my CAC but a website cannot?
If certutil -scinfo lists the certificates, the remaining issue may be certificate selection, browser state, trust, network requirements or authorization at that service. Test another authorized official service and contact the failing service’s support team with the exact message.
Official references
- Microsoft Learn: Smart Card Troubleshooting
- Microsoft Learn: certutil command reference
- Microsoft Learn: Smart Card Reader Devices Design Guide
- Microsoft Learn: Smart Card Discovery Process
- DoD Cyber Exchange: PKI/PKE End Users
New to the hardware? Start with our beginner CAC reader setup and home-use guide before choosing middleware or changing drivers.
Subscribe for Updates
Get the latest cac readers.com updates delivered to your inbox.
We respect your privacy. Unsubscribe anytime.