HTTPS (tls, really) allows clients to present a certificate, just like the server does. This is commonly used, eg, for microservices authenticating to each other in a backend.
It is less commonly used for people to authenticate to servers.
In particular, the "Common Access Card" is the ID badge used by the DoD, various parts of the armed forces, and in particular the NSA (whose website this is). Those access cards have a key and certificate usable for this.
So your keyboard (or laptop) has a smartcard reader in it, and you can insert your ID badge (maybe with a PIN? not sure if usa gov't does that) to log into any website.
Browser UX for this isn't great. Unlike the newer Webauthn specs where javascript (and thus site-specific instructions) can ask you to log in, the browser has to prompt you in a very generic way to present your certificate.