TPM Cyber Security

This page provides steps on how to access and navigate Trading Partner Management (TPM) and Supplier Management (SM) applications. In addition, this page walks through the process of updating your Cybersecurity Compliance and Risk Assessment – Compliance (CCRA – Compliance) survey, and — where required — completing the linked CCRA – Risk form.

Please see the TPM SM Guide for detailed instructions on how to access and complete the CCRA – Compliance and CCRA – Risk forms.

IMPORTANT! You MUST use a PC and Google Chrome to access the Supplier Management application.

Step 1. Login to MAG

To access your TPM profile, you must first login to your Exostar’s Managed Access Gateway (MAG) account. For help resetting your MAG password or any other MAG-related questions, refer to the MyExostar self-help page, Managed Access Gateway.

NOTE: If you are the first user in your organization to access SM, you must accept the standard MAG Usage Service Agreement. If you see Agree to Terms on the Supplier Management tile in your MAG account, click the button and accept the service agreement.

1. Navigate to https://portal.exostar.com. Input your Email Address or User ID. Click Next.

2. Input your Password. Click Next to access the MAG Dashboard.


Step 2. Access TPM

Once you successfully log into your MAG account, ensure you authenticate with your credential. You can do this by selecting the Elevate Credential Strength button in the My 2FA Credentials section. The system also prompts you for your credential once you select to access TPM.

1. From the MAG Dashboard, select My Account tab, then select View Organization Details sub-tab.

2. Click the View in Trading Partner Management (TPM) link.

3. A notification will display, click Continue button to access the Organization’s profile.


Step 3. Cyber Security Section Review

The Cybersecurity Compliance and Risk Assessment (CCRA – Compliance) questionnaire provides questions related to the applicability of cyber Federal Acquisition Regulation (FAR), Defense Federal Acquisition Regulation Supplement (DFARS) requirement, the handling of Sensitive Information, and Cybersecurity Maturity Model Certification (CMMC) attestation. This questionnaire is required for all Lockheed Martin suppliers.

To update the Cyber Security section:

  1. Select Self-certification from the left-hand menu.
  2. Scroll down to the Cyber Security section. Review the information provided.

Step 4. Complete CCRA – Compliance Questionnaire

In the Supplier Management (SM) application, the CCRA – Compliance Questionnaire displays in the Pending Forms tab of the dashboard and displays important details for the form.

To access and complete the CCRA – Compliance questionnaire:

1. Select the highlighted Click here to submit or update your CCRA – Compliance Questionnaire in Exostar’s Supplier Management (SM) System link to open Supplier Management (SM).

NOTE: You can also access Supplier Management via Managed Access Gateway (MAG) dashboard and click Launch.

2. Locate the CCRA – Compliance Questionnaire in the Pending Forms tab from the SM Dashboard.

NOTES:
Anyone with SM access and that is assigned to the form can update or complete the questionnaire. The Assigned To section indicates the current user assigned to the form. Only one person can be assigned to a form at any given time.

You can initiate work on the form only when the Request Status is at 40%.

IMPORTANT! If the Request Status is at 20%, it indicates either the form is not provisioned, or the invitee accepting the invitation and the designated organization administrator are two different users. In such cases, the designated organization administrator needs to re-assign the form to themselves. See Step 3 below.

The Form Progress for a new form starts at 0% and the revision is 0.1 for a form that has never been started. In the provided screenshot the user has already submitted the form once and is now renewing it for the second time. Therefore, the Form Progress is at 100%, and the Revision is 1.1.

3. Select the three dots (ellipsis) button located to the right. Select Edit from the menu.

NOTE: You can also reassign the form by selecting the three dots (ellipsis) button.

IMPORTANT! If the Edit button is not displayed, the form is not currently assigned to you. Use the Reassign option to assign the form to the correct user. Only one person can be assigned to a form at any given time.

4. Review the Cybersecurity Compliance question. Click Next.

NOTE: Once the supplier begins working on the form, they have the flexibility to save the form and exit at any point. All information entered will be saved during this process.

5. Complete all compliance questions in the form and then navigate to the Submitter section of the questionnaire.

6. Enter the required information. Click the Save button.

NOTE: Please see the Submitter’s Detail Page Guidance section below for guidance on completing these fields.

IMPORTANT!  Users must ensure they click the Save button prior to clicking the Review button at the end of the survey to review results before submitting the questionnaire. The Save button does not submit the survey for scoring or updates. The Review button remains greyed out until ALL questions are answered and the form has been saved.

7. A Save success message will display. Click OK to confirm the form is saved.

8. Click the Review button (which is now enabled).


Step 5. Review Score Preview

After submitting, the system displays a Form Preview – Cyber Compliance Attestation screen showing your calculated scores in a Pending Submission state before the form is officially recorded. 

  • Compliance with DFARS 252.204-7012: with a value of Compliant, Non-Compliant, or Not Applicable
  • Compliance with DFARS 252.204-7020: with a value of Compliant, Non-Compliant, or Not Applicable
  • CMMC_Statuses: table with all the selected CMMC Status, Last Assessment Date, Last Affirmation Date, and Status

Scores are shown with a Pending Submission badge to indicate the form has not yet been officially submitted. Click the Close (X) button to return to the previous screen.


Step 6. Complete CCRA – Risk Form (If Applicable)

Following CCRA – Compliance submission, the system automatically evaluates your responses to determine whether a CCRA – Risk form is required.

What is the CCRA – Risk Form?
The CCRA – Risk form is a separate risk assessment form linked to your CCRA – Compliance submission. It contains only risk-related questions and Cyber Security Control Implementation. It does not repeat the compliance questions already answered in the CCRA – Compliance form. There are two outcomes following the CCRA – Compliance survey completion:

NOTE: The CCRA – Risk form and the CCRA – Compliance form are separate PDF artifacts. Each can be downloaded independently from the Cyber Rating section in TPM.

Outcome A – Risk Form Not Required

If your CCRA – Compliance responses determine a Risk Assessment is not required, a green confirmation message displays: 

Based on your responses, a Risk Assessment is not required at this time. You may proceed with submitting your form.

The Submit button is immediately enabled. No further action is required. Submit the form and proceed to the MAG Dashboard for your self-certification affirmation.

NOTE:  When the CCRA – Compliance responses for Q1 = One of Exemptions, Q2 = One of Exemptions, Q5 = No, and the supplier’s CMMC status is CMMC Level 1 or below, the Cyber Risk Rating is automatically set to N/A. No CCRA – Risk form will be assigned in this scenario.

Outcome B – Risk Form Required

If your CCRA – Compliance responses determine that a risk assessment is required, a Risk Form Assignment section displays with a red Required badge. The Submit button remains disabled until you assign the CCRA – Risk form to a user.

Assign CCRA – Risk Form

Option 1 – Assign to Existing User or Yourself

1. From the Assign To dropdown, select a user from your organization. Users are listed as: Full Name ([email protected]).

2. Once a user is selected, the Submit button becomes enabled.

3. Click Submit to complete the CCRA – Compliance submission.

NOTE: A confirmation toast displays: Risk Form assigned to [user email].

Option 2 – Request New User

1. Select + Request New User from the bottom of the Assign To dropdown.

2. Complete the inline fields that display: First Name, Last Name, and valid Email Address.

3. Click Submit. A request is sent to your organization’s SP Admin to add the user.

NOTE: A confirmation toast displays: New user request for [Name] ([email]) has been sent to your organization’s SP Admin.

IMPORTANT!  The CCRA – Risk form assignment remains pending until the SP Admin adds the requested user. The organization administrator will receive an email with instructions on how to activate the new user and the user is required to complete the account setup.

NOTE: All the steps needed to do the above actions will be provided in the emails sent out.

Complete CCRA – Risk Form (Assigned User)

The user assigned to the CCRA – Risk form receives an email notification and can log in to SM to complete it. The form displays in their Pending Forms tab. To complete the form:

1. Locate the CCRA – Risk form in the Pending Forms tab. Select Edit.

 

 

 

2. Complete all risk assessment questions in the form, including the Cyber Security Controls section.

3. Navigate to the end of the survey. Click Save.

4. Click Submit to complete the Risk Assessment.

 

 

 

 

 

NOTES:
Once submitted, the CCRA – Risk form displays under the Completed Forms tab.
A Cyber Risk Rating is calculated from the submitted Risk Form and transmitted to TPM, where it is visible to your prime contractor in the Cyber Rating section.
The Cyber Risk Rating displays as Pending Risk Form in TPM until the CCRA – Risk form is completed.
If a Risk Form was previously submitted and the requirement subsequently cycles through not-required and back to required, the historic Risk Form and its derived Cyber Rating are retained until a new Risk Form is submitted.

5. Click Acknowledge to confirm form submission.

Please note as you progress through the form request, you will see the following Request Status percentages:

  • Pending Provisioning: Request Status 20%
  • Provisioned: Request Status 40%
  • First Time Access: Request Status 60%
  • Form Started: Request Status 80%

NOTES: 
– Once the user submits the form, the form displays under the Completed Forms tab.
– The score summary details are displayed on the bottom right of the Forms Details page.
– Recent Request will be updated to include expiration date of the form.
– Revision History will display the latest revision. Additionally, you will have the ability to download all the revisions. The answers will display along the right-hand side of the PDF.


Submitter’s Details Page Guidance

Field NameGuidance
Vendor NameCompany / Organization Name
Vendor Primary POC NameFirst Name, Last Name (i.e., John Doe)
Vendor Primary POC EmailPrimary POC Email Address
Vendor IT Security POC NameFirst Name, Last Name (i.e., John Doe)
Vendor IT Security POC EmailIT Security POC Email Address
Vendor Local DUNS Number(s)If more than one, use a comma and a space to separate values (i.e., 007505491, 000665432)
Vendor CAGE Code(s)If more than one, use a comma and a space to separate values (i.e., 3T456, 56789) 
If CAGE code is not applicable use “12345” 

NOTE: If the response on this form is applicable to more than one of your organization’s business units/divisions, provide all the Local DUNS Number and CAGE Codes that apply. You’ll be able to export a single form for multiple DUNS/CAGE Code.


Update Completed Form

To update the submitted form, you must renew the form. Follow the steps below:

1. Navigate to the Completed Forms tab.

2. Click Renew from the action button or from the Forms Details pages.

NOTE: This action will move the form back to the Pending Forms tab.

3. Select to Edit the form and complete the steps as outlined above.


Form Upgrade

It is possible for your partner to upgrade a form from its previous version (i.e., add or remove questions). Once the form has been upgraded, you must edit the form and complete the upgraded questions.

To upgrade a form:

1. Navigate to the desired Form Details page. Click the Edit Form button.

2. An upgrade notification displays. Click the Next button.

NOTE: The system can take up to five minutes to upgrade the form. You do not have to wait for form to upgrade and can Exit and come back later. If you do wait, a confirmation screen displays.

3. If you wait for the form to upgrade, click Continue from the confirmation screen to begin editing the upgraded form.

4. If you do not wait for the form to upgrade, you can Exit and come back later. Navigate to the Form Details page. Click the Edit Form button to edit the upgraded form. Complete the form as you would normally.


Additional Resources

See the TPM Training Resources page and the SM Training Resources page for detailed user guides.

Updated on July 6, 2026

Related Articles

Need Support?
Can’t find the answer you’re looking for? Don’t worry we’re here to help!
Contact Support