Step 1. Login to MAG
To access your TPM profile, you must first login to your Exostar’s Managed Access Gateway (MAG) account. For help resetting your MAG password or any other MAG-related questions, refer to the MyExostar self-help page, Managed Access Gateway.
1. Navigate to https://portal.exostar.com. Input your Email Address or User ID. Click Next.
2. Input your Password. Click Next to access the MAG Dashboard.

Step 2. Access TPM
Once you successfully log into your MAG account, ensure you authenticate with your credential. You can do this by selecting the Elevate Credential Strength button in the My 2FA Credentials section. The system also prompts you for your credential once you select to access TPM.

1. From the MAG Dashboard, select My Account tab, then select View Organization Details sub-tab.
2. Click the View in Trading Partner Management (TPM) link.
3. A notification will display, click Continue button to access the Organization’s profile.


Step 3. Cyber Security Section Review
The Cybersecurity Compliance and Risk Assessment (CCRA – Compliance) questionnaire provides questions related to the applicability of cyber Federal Acquisition Regulation (FAR), Defense Federal Acquisition Regulation Supplement (DFARS) requirement, the handling of Sensitive Information, and Cybersecurity Maturity Model Certification (CMMC) attestation. This questionnaire is required for all Lockheed Martin suppliers.
To update the Cyber Security section:
- Select Self-certification from the left-hand menu.
- Scroll down to the Cyber Security section. Review the information provided.

Step 4. Complete CCRA – Compliance Questionnaire
In the Supplier Management (SM) application, the CCRA – Compliance Questionnaire displays in the Pending Forms tab of the dashboard and displays important details for the form.
To access and complete the CCRA – Compliance questionnaire:
1. Select the highlighted Click here to submit or update your CCRA – Compliance Questionnaire in Exostar’s Supplier Management (SM) System link to open Supplier Management (SM).


2. Locate the CCRA – Compliance Questionnaire in the Pending Forms tab from the SM Dashboard.
3. Select the three dots (ellipsis) button located to the right. Select Edit from the menu.


4. Review the Cybersecurity Compliance question. Click Next.

5. Complete all compliance questions in the form and then navigate to the Submitter section of the questionnaire.


6. Enter the required information. Click the Save button.
7. A Save success message will display. Click OK to confirm the form is saved.

8. Click the Review button (which is now enabled).

Step 5. Review Score Preview
After submitting, the system displays a Form Preview – Cyber Compliance Attestation screen showing your calculated scores in a Pending Submission state before the form is officially recorded.
- Compliance with DFARS 252.204-7012: with a value of Compliant, Non-Compliant, or Not Applicable
- Compliance with DFARS 252.204-7020: with a value of Compliant, Non-Compliant, or Not Applicable
- CMMC_Statuses: table with all the selected CMMC Status, Last Assessment Date, Last Affirmation Date, and Status

Scores are shown with a Pending Submission badge to indicate the form has not yet been officially submitted. Click the Close (X) button to return to the previous screen.
Step 6. Complete CCRA – Risk Form (If Applicable)
Following CCRA – Compliance submission, the system automatically evaluates your responses to determine whether a CCRA – Risk form is required.
What is the CCRA – Risk Form?
The CCRA – Risk form is a separate risk assessment form linked to your CCRA – Compliance submission. It contains only risk-related questions and Cyber Security Control Implementation. It does not repeat the compliance questions already answered in the CCRA – Compliance form. There are two outcomes following the CCRA – Compliance survey completion:
Outcome A – Risk Form Not Required
If your CCRA – Compliance responses determine a Risk Assessment is not required, a green confirmation message displays:
The Submit button is immediately enabled. No further action is required. Submit the form and proceed to the MAG Dashboard for your self-certification affirmation.

Outcome B – Risk Form Required
If your CCRA – Compliance responses determine that a risk assessment is required, a Risk Form Assignment section displays with a red Required badge. The Submit button remains disabled until you assign the CCRA – Risk form to a user.

Assign CCRA – Risk Form
Option 1 – Assign to Existing User or Yourself
1. From the Assign To dropdown, select a user from your organization. Users are listed as: Full Name ([email protected]).
2. Once a user is selected, the Submit button becomes enabled.
3. Click Submit to complete the CCRA – Compliance submission.

Option 2 – Request New User
1. Select + Request New User from the bottom of the Assign To dropdown.
2. Complete the inline fields that display: First Name, Last Name, and valid Email Address.
3. Click Submit. A request is sent to your organization’s SP Admin to add the user.


Complete CCRA – Risk Form (Assigned User)
The user assigned to the CCRA – Risk form receives an email notification and can log in to SM to complete it. The form displays in their Pending Forms tab. To complete the form:
1. Locate the CCRA – Risk form in the Pending Forms tab. Select Edit.

2. Complete all risk assessment questions in the form, including the Cyber Security Controls section.
3. Navigate to the end of the survey. Click Save.
4. Click Submit to complete the Risk Assessment.

5. Click Acknowledge to confirm form submission.

Please note as you progress through the form request, you will see the following Request Status percentages:
- Pending Provisioning: Request Status 20%
- Provisioned: Request Status 40%
- First Time Access: Request Status 60%
- Form Started: Request Status 80%

Submitter’s Details Page Guidance
| Field Name | Guidance |
|---|---|
| Vendor Name | Company / Organization Name |
| Vendor Primary POC Name | First Name, Last Name (i.e., John Doe) |
| Vendor Primary POC Email | Primary POC Email Address |
| Vendor IT Security POC Name | First Name, Last Name (i.e., John Doe) |
| Vendor IT Security POC Email | IT Security POC Email Address |
| Vendor Local DUNS Number(s) | If more than one, use a comma and a space to separate values (i.e., 007505491, 000665432) |
| Vendor CAGE Code(s) | If more than one, use a comma and a space to separate values (i.e., 3T456, 56789) If CAGE code is not applicable use “12345” |
Update Completed Form
To update the submitted form, you must renew the form. Follow the steps below:
1. Navigate to the Completed Forms tab.
2. Click Renew from the action button or from the Forms Details pages.
3. Select to Edit the form and complete the steps as outlined above.

Form Upgrade
It is possible for your partner to upgrade a form from its previous version (i.e., add or remove questions). Once the form has been upgraded, you must edit the form and complete the upgraded questions.
To upgrade a form:
1. Navigate to the desired Form Details page. Click the Edit Form button.

2. An upgrade notification displays. Click the Next button.


3. If you wait for the form to upgrade, click Continue from the confirmation screen to begin editing the upgraded form.

4. If you do not wait for the form to upgrade, you can Exit and come back later. Navigate to the Form Details page. Click the Edit Form button to edit the upgraded form. Complete the form as you would normally.
Additional Resources
See the TPM Training Resources page and the SM Training Resources page for detailed user guides.