Cybersecurity Compliance and Risk Assessment (CCRA) Updated Supplier Cybersecurity Requirements in Exostar Following our recent notice, “Document Your CMMC Status in Exostar,” all active Lockheed Martin suppliers are required to submit their Cybersecurity Maturity Model Certification (CMMC) and cyber risk status. The Cybersecurity Compliance and Risk Assessment (CCRA) has been reinstated to include the risk assessment and must be completed in Exostar. - What is the CCRA: Lockheed Martin’s single process to assess suppliers’ compliance with cyber regulations and measure cyber risk, established in March 2024, is being reinstated as the primary cybersecurity form for all Lockheed Martin suppliers. It will include two parts: CCRA – Compliance and CCRA – Risk. - What is going to happen to the CCA: The Cybersecurity Compliance Attestation (CCA) was an interim form used to capture CMMC and DFARS compliance information given the Department of War’s aggressive CMMC implementation timeline. The CCA will be renamed to CCRA - Compliance on Jun. 30, 2026. CCRA – Compliance Survey Requirements The CCRA – Compliance survey is required for all Lockheed Martin suppliers and is part of their Exostar vendor profile Self-Certification. - Suppliers who have completed the interim CCA will have their responses automatically transferred to the CCRA – Compliance survey as part of this update. No action is required to complete this survey. - Suppliers who haven’t completed the CCA will be required to complete the CCRA – Compliance survey. CCRA – Risk Survey Requirements Upon completion of the CCRA – Compliance survey, the system will determine whether the CCRA – Risk is required. See LM Cybersecurity Requirements FAQ (questions 5 and 6) for details. - Suppliers that attested to having a CMMC Level 2 (Self or C3PAO) or higher assessment in SPRS, under question 4.0 of the CCRA – Compliance survey, will not need