8 unchanged sentences
We also have a corporate-wide counterintelligence and insider threat detection program to proactively identify external and internal threats and mitigate those threats in a timely manner.
−Removed: As a defense contractor, we must comply with extensive regulations, including requirements imposed by the Defense Federal Acquisition Regulation Supplement (DFARS) related to adequately safeguarding controlled unclassified information (CUI) and reporting cybersecurity incidents to the DoD.
−Removed: We have implemented cybersecurity policies and frameworks based on industry and governmental
−Removed: standards to align closely with DoD requirements, instructions and guidance.
−Removed: Moreover, we continue to work with the DoD on assessing cybersecurity risk and on policies and practices aimed at mitigating these risks.
−Removed: For example, we have worked in collaboration with the other members of the defense industrial base to support DoD’s development of the Cybersecurity Maturity Model Certification (CMMC) program, DoD’s program to ensure members of the defense industrial base meet cybersecurity requirements for handling CUI and federal contract information.
−Removed: We believe we are well positioned to meet the requirements of the CMMC and are preparing for certification.
−Removed: In addition to following DoD guidance and implementing pre-existing third party frameworks, we have developed our own practices and frameworks, which we believe enhance our ability to identify and manage cybersecurity risks.
+Added: As a defense contractor, we must comply with extensive regulations, including requirements imposed by the DFARS related to adequately safeguarding controlled unclassified information (CUI) and reporting cybersecurity incidents to the DoW.
+Added: We have implemented cybersecurity policies and frameworks based on industry and governmental standards to align closely with DoW requirements, instructions and guidance.
+Added: Moreover, we continue to work with the DoW on assessing cybersecurity risk and on policies and practices aimed at mitigating these risks.
+Added: For example, we have worked in collaboration with the other members of the defense industrial base to support DoW’s development of the Cybersecurity Maturity Model Certification (CMMC) program, DoW’s program to ensure members of the defense industrial base meet cybersecurity requirements for handling CUI and federal contract information.
+Added: In November 2025, we submitted our initial CMMC certification as required by the program.
+Added: In addition to following DoW guidance and implementing pre-existing third party frameworks, we have developed our own practices and frameworks, which we believe enhance our ability to identify and manage cybersecurity risks.
For example, we use a proactive risk management strategy that we developed and implemented called the Intelligence Driven Defense ® model that seeks to identify and prevent cybersecurity incidents by understanding the nature of adversaries and using this information to minimize the impact of an attack.
−Removed: Third parties also play a role in our cybersecurity.
−Removed: We engage third-party services to conduct evaluations of our security controls, whether through penetration testing, independent audits or consulting on best practices to address new challenges.
−Removed: These evaluations include testing both the design and operational effectiveness of security controls.
+Added: The effectiveness of our security controls are validated by external third parties, including an independent audit agency to maintain our ISO 27001 certification.
+Added: Whether through independent audits or consulting on best practices, we continuously evaluate both the design and operational effectiveness of security controls.
We also share and receive threat intelligence with our defense industrial base peers, government agencies, information sharing and analysis centers and cybersecurity associations.
8 unchanged sentences
The Board of Directors oversees management’s processes for identifying and mitigating risks, including cybersecurity risks, to help align our risk exposure with our strategic objectives.
−Removed: Senior leadership, including our Chief Information Security Officer (CISO), regularly briefs the Board of Directors on our cybersecurity and information security posture and the Board of Directors is apprised of cybersecurity incidents deemed to have a moderate or higher business impact, even if immaterial to us.
+Added: Senior leadership, including our Chief Information Security Officer (CISO), report to the Board of Directors on our cybersecurity and information security posture at least annually and the Board of Directors is apprised of cybersecurity incidents deemed to have a moderate or higher business impact, even if immaterial to us.
The Classified Business and Security Committee of the Board of Directors is briefed by senior leadership, as appropriate, on the cybersecurity of classified programs and the security of our classified business supply chain.
11 unchanged sentences
Notwithstanding the extensive approach we take to cybersecurity, we may not be successful in preventing or mitigating a cybersecurity incident that could have a material adverse effect on us.
−Removed: While Lockheed Martin maintains cybersecurity
−Removed: insurance, the costs related to cybersecurity threats or disruptions may not be fully insured.
+Added: While Lockheed Martin maintains cybersecurity insurance, the costs related to cybersecurity threats or disruptions may not be fully insured.
“Risk Factors” for a discussion of cybersecurity risks.
Compared sentence by sentence after normalising whitespace, quotation marks, case and digits, so re-formatting and restated figures do not read as changed language. Wording changes appear as one removal and one addition. The current filing and the prior one are authoritative.