How to Fill Out and Submit IA Form 3066: Acceptable Use Policy

Army Form 3066 is the Acceptable Use Policy (AUP) agreement you sign to get an account on Department of the Army information systems, including NIPRNet and SIPRNet. To complete it, you gather your identifiers, finish the DoD Cyber Awareness Challenge, fill in the PDF, sign it digitally with your Common Access Card (CAC), and route it to your unit’s Information Assurance Officer (IAO) for approval. AR 25-2 requires a signed AUP on file before any soldier, DA civilian, or contractor is given network access.1U.S. Army Corps of Engineers. Acceptable Use Policy

What to Have Ready Before You Open the Form

Mismatched data between the form and your personnel records is the most common reason an IAO kicks a request back. Pull the following before you start:

  • Full legal name and rank or grade, spelled and formatted exactly as they appear in your official records. Civilians use pay grade (for example, GS-9); contractors use their company title.
  • Your ten-digit DoD ID number from the back of your CAC. A single transposed digit prevents the system from matching your signed agreement to your network profile.
  • Organization and office symbol, taken from your assignment orders or unit roster. The office symbol must match what your unit has registered with network administrators.
  • Which network you need — NIPRNet, SIPRNet, or both. SIPRNet requires an active Secret clearance or higher, validated separately by your security manager.
  • A duty phone number and an organizational email address if you already have one.

Contractors need two extra items: your company’s Commercial and Government Entity (CAGE) code, assigned when the company registered in SAM.gov,2Defense Logistics Agency. CAGE Code – Commercial and Government Entity Code and your contract number with its expiration date. Your account is tied to the life of the contract.

Finish the Cyber Awareness Challenge First

The IAO will not process your AUP without a current completion certificate from the DoD Cyber Awareness Challenge. The training covers threat identification, phishing, social engineering, physical security, and data handling. AR 25-2 requires it before initial network access, with periodic refresher training after that.1U.S. Army Corps of Engineers. Acceptable Use Policy The course lives on the DoD Cyber Exchange at cyber.mil3Cyber Exchange. Cyber Awareness Challenge and takes about an hour. A Knowledge Check option lets you skip sections by correctly answering questions from the previous version, so renewals move faster.4Center for Development of Security Excellence. Cyber Awareness Challenge DS-IA106.06 Save the completion certificate. The IAO needs to see it, and you will want a personal copy for later audits.

Filling Out the Form

Form 3066 is a PDF you complete on-screen. Your unit’s IAO or help desk can send you the current version, and many units host it on internal intranet portals. Work through it block by block.

Personal and organizational information. Name, rank or grade, DoD ID, unit, office symbol, and phone. Double-check the DoD ID character by character.

Account type. Select general user or privileged user. Privileged users — system administrators and network engineers — have elevated rights and face additional training requirements under DoD 8140.

Network designation. Mark NIPRNet, SIPRNet, or both. A SIPRNet request triggers a separate security-manager validation confirming your clearance.

Acknowledgment sections. The body of the form lays out user responsibilities, prohibited conduct, and the government’s right to monitor. Read it. Your digital signature certifies you understand every provision.

Signing and Routing

Sign using your CAC’s digital certificate in an approved PDF viewer. Adobe Acrobat on a government workstation is the standard tool. A wet-ink signature on a printed copy is sometimes accepted with prior IAO approval, but a digital CAC signature is the default and speeds routing.

Once signed, the form goes to your unit’s IAO or Information Assurance Manager (IAM). The IAO checks that your personal data matches your records, confirms your Cyber Awareness certificate is current, and verifies your clearance if you asked for SIPRNet. A wrong office symbol, an expired training certificate, or a missing contractor CAGE code will bring the form back to you. After the IAO signs, the form moves to the network administrators for account creation. Turnaround varies by installation and workload; most units provision accounts within a few business days of final approval. Keep a personal copy of the signed agreement — it is your proof of compliance during command inspections and security audits.

What You Are Agreeing To

The signature is legally enforceable. The core commitments are worth understanding before you click through.

Consent to Monitoring

You acknowledge that the Department of Defense may monitor, intercept, search, and seize any data or communication on its networks at any time, for any purpose. You have no expectation of privacy on government-owned equipment. DoDI 8500.01 requires a notice-and-consent banner at every login and the same consent language in every user agreement.5Executive Services Directorate. DoDI 8500.01 – Cybersecurity

Credential and CAC Security

Protect your passwords and your CAC. Never share your PIN. The CAC is government property, and lending it or allowing unauthorized use can result in a fine, imprisonment, or both.6Common Access Card (CAC). Managing Your Common Access Card Never leave the card in a workstation when you walk away. Lock the screen or remove the card, even for a short break.

Multi-Factor Authentication

Some systems, including Army 365 remote access, require multi-factor authentication through a time-based one-time password app such as Google Authenticator or Authy. Your phone’s clock must be synced correctly or the codes will not work. If you replace or lose your phone, deactivate the old credentials and set up new ones through your unit or the site’s token-request process.7U.S. Army War College. Multifactor Authentication Support

Data Handling

Use only authorized hardware and software on the network you’re on. Handle data according to its classification. Moving classified information onto an unclassified system — a spillage — triggers a mandatory incident response that can involve wiping drives, quarantining systems, and a formal investigation. Report any suspected breach to your IAO immediately.

Conduct That Will Cost You Your Access

The AUP explicitly forbids several categories of behavior. These are where users most often get into trouble:

  • Personal profit or commercial use. Running a side business or conducting outside employment through government networks violates the Joint Ethics Regulation.
  • Bypassing security controls. Attempting to gain unauthorized privileges, circumventing firewalls, or probing for vulnerabilities is treated as a hostile act.
  • Unauthorized software. No peer-to-peer file-sharing, streaming apps, games, browser extensions, or anything not approved for the environment.
  • Inappropriate material. Pornographic, extremist, or otherwise prohibited content on government systems draws immediate revocation and possible criminal charges.
  • Partisan political activity. While on duty, in uniform, or using government systems, you may not post partisan content, share material from political candidates, or advocate for a party or cause.8U.S. Army. Personal Social Media Use
  • Personal removable media. Personal USB drives, external hard drives, and memory cards are banned. Only government-procured, inventoried media may be used, only when the mission requires it, and only with the appropriate authorization.9DoD Cyber Exchange. Removable Media and Mobile Devices
  • Unapproved AI tools. The DoD provides access to approved generative AI models through the GenAI.mil initiative. Do not paste sensitive information into external AI chatbots. Ask your IAO before using any AI tool on a government workstation.10War.gov. War Department Launches AI Acceleration Strategy to Secure American Military AI

Consequences of a Violation

Penalties scale with severity, and your chain of command has wide latitude:

  • Administrative action. Letter of reprimand, suspension of network privileges, or mandatory retraining. Losing access often makes it impossible to do your job.
  • Security clearance review. A serious violation, particularly a spillage or unauthorized disclosure, can trigger review or revocation of your clearance, which for many military occupational specialties ends the career.
  • UCMJ prosecution. An AUP violation can be charged under Article 92 as failure to obey a lawful regulation, with punishment as a court-martial sees fit — including confinement, forfeiture of pay, reduction in rank, and a punitive discharge.11Office of the Law Revision Counsel. 10 U.S.C. 892 – Art. 92. Failure to Obey Order or Regulation
  • Criminal prosecution. Severe breaches involving classified information can be referred for federal criminal prosecution outside the UCMJ.

The heaviest consequences fall on people who knew the rules and ignored them: the soldier who plugged in a personal thumb drive “just once,” or the contractor who emailed a classified document to a personal account for convenience. The signed AUP is the record that no one can claim ignorance after the fact.