About
An instrument for the last unmeasured link
TIR-CMM measures whether an organisation can act on what it detects, inside the time the adversary allows, with the authority to do so — and whether it can prove it. It is the response module of UTIOM and the companion to TID-CMM.
It does not measure the incident response team. Under UTIOM Law 6 — operations functions as continuous incident response — it measures the organisation’s capacity to act, of which the IR team is one component and frequently not the binding one. The binding component is usually authority: the playbook exists, the tooling works, and nobody at 03:00 on a Sunday is permitted to isolate the production domain controller.
The model scores eight domains and 58 sub-capabilities, scores a Containment Lattice of eight attack-path stages crossed with eight asset classes, measures decision latency as a first-class metric, and applies seven integrity constraints mechanically — lower scores only, and not arguable.
From v0.2 it runs at three depths — twenty minutes, an afternoon, or a facilitated engagement — each a strict superset of the one below.
Who it is for
Anyone who has to answer the question could we actually stop it with something other than a list of the tools they own.
Security leaders
Leaders who need to know whether their organisation can act, not whether it has bought the means to act. The model separates the two: an engineered rate that says “we believe we can act here” and a proven rate that says “we have shown we can.” The gap between them is the finding.
Response engineers
Response content deserves the same engineering discipline as detection content: version control, testing before release, parameterised reusable actions, lifecycle and deprecation, mapping to RE&CT and D3FEND. The RE domain carries the largest weight in the model for exactly that reason.
SOC and IR leads
The lattice gives a per-cell picture of where response options exist, where they are engineered but unproven, and where there is no option at all. The roadmap that comes out of it is mechanical — ranked by criticality tier and stage leverage, with no facilitator bias and no advocacy.
CISOs answering to boards and regulators
Containment Margin is one signed number a board understands: minutes of margin against the adversary, or minutes of deficit. For DORA and NIS2, the model produces the testing, reporting-clock and continuity evidence those regimes ask for — without being a compliance model.
Status
This is v0.2, a design draft for review, dated 17 August 2026. It is not yet published. The specification has been validated numerically end to end against a fictional organisation — a run that found and corrected two real defects, the roadmap scale mismatch and the constraint-reporting problem, both of which would have shipped unnoticed without executing the arithmetic — but it has not yet been run against a real estate by anyone other than its author.
What is wanted at this stage is not endorsement. It is counter-examples and critique: the organisation whose constraints do not behave as the model predicts, the domain weighting that produces an obviously wrong answer, the lattice cell that cannot be scored honestly because the model asked the wrong question.
What changed in v0.2
v0.1 was a complete model that was too heavy to start with. Every change below either lowers the cost of the first assessment or raises the standard the deepest one has to meet. Nothing was removed, and no v0.1 record needs rescoring.
Three tiers
The headline change. The model now runs at three depths: Pulse (20 minutes, 20 questions, caps at L3), Baseline (1–2 hours, the 58 sub-capabilities plus the lattice and tempo, caps at L4) and Assurance (2–4 weeks, adding telemetry attributes, scenarios and governance, no ceiling). Each is a strict superset of the one below, so an organisation can start in twenty minutes and deepen later without rescoring anything. The three tiers →
Evidence is a level, not a flag
The v0.1 yes/no “named, dated artifact” flag is replaced by an evidence level of 0 to 3, each carrying a cap: VC0 assertion only caps at 1, VC1 design or policy at 2, VC2 implemented and tested at 4, VC3 repeatably validated at 5. The levels align to TID-CMM’s Validated Coverage grades, so an imported VC grade sets the ceiling directly. The cap is a ceiling, not a conversion, and a blank level is treated conservatively as 0. Evidence levels →
S0 Prevent joins the lattice
A new stage sits ahead of S1 with stage leverage 1.6, the highest in the model, because prevention buys the one thing response cannot manufacture, which is time. The lattice is now 8 stages × 8 asset classes. The lattice →
Constraint R7
A seventh constraint: assessment depth and governance ceiling. Pulse caps the band at L3, Baseline at L4, and a self-assessment run without evidence-led scoring, independent calibration and separation of assessor from approver caps at L4 whatever tier it was run at. R7 →
Scenario validation
New at the Assurance tier: 12 starter scenarios, each scored across 10 lifecycle stages, with pass conditions and a minimum scenario record. A scenario passes only when every stage is above 1, it was exercised, the exercise was timed, and observed recovery met its target — because an exercise with no recorded times cannot lift a readiness claim. Scenario validation →
Telemetry attributes
New at the Assurance tier: eight attributes scored per asset class rather than per ATT&CK data component. Telemetry health is a property of a platform, not of a log type, and scoring 106 data components is the single largest cost in a traditional assessment for very little added signal. Telemetry attributes →
The governance layer
New at the Assurance tier: eight assurance conditions, ten calibration questions, decision rights, a response RACI, anti-gaming rules, board reporting rules and publication cautions. Without evidence-led scoring, independent calibration and separation of assessor from approver, a result is a self-assessment — useful, but capped at L4 and not to be presented as assurance. The governance layer →
The worked example moved
Re-running “Meridian Group” against the v0.2 model changes the published figures.
| Figure | v0.1 | v0.2 | Why it moved |
|---|---|---|---|
| Self-assessed overall | 2.69 | 2.69 | Unchanged — the pre-constraint arithmetic is identical. |
| Constraint-adjusted overall | 2.35 | 2.32 | The graduated evidence cap removes more than the flag did. |
| R3 sub-capabilities bound | 3 | 6 | A level-1 answer now caps at 2 rather than passing at 3. |
| In-scope lattice cells | 28 | 32 | Four cells of the new S0 Prevent row fall in scope. |
| Engineered rate | 39.3% | 40.6% | Two of the four new S0 cells are at status 2. |
| Proven rate | 3.6% | 3.1% | The same single proven cell, over a larger denominator. |
| Reported band | L1 | L1 | Unchanged. R5 still binds three bands below R7. |
The R3 count is the change worth reading twice. Under the v0.1 flag, three sub-capabilities lost a point; under graduated levels, six do, and they lose more. The difference is not severity for its own sake — it is that a yes/no question let a policy document and a tested implementation give the same answer, and the six are all capabilities this organisation genuinely believed it had.
The family: UTIOM and TID-CMM
UTIOM — the Unified Threat-Informed Operations Model — organises around three pillars. The two capability maturity modules map onto two of them with no overlap: TID-CMM sits in Engineering and Enablement and asks would we see it?; TIR-CMM sits in Operations and Analysis and asks could we stop it? UTIOM itself covers Leadership and Governance — vision, strategy, crown jewels.
On the UTIOM V-model, TID-CMM measures the descending arm’s output, what the engineering decisions produced. TIR-CMM measures the ascending arm: whether the design survives contact and is proven by validation.
TIR-CMM deliberately contains no detection domain. It consumes detection maturity as an input constraint under R4 rather than re-assessing it. That is what makes the two models complementary rather than overlapping, and it is the decision that keeps a combined assessment under two hours.
TIR-CMM is nonetheless usable on its own, and the tool defaults to that. An organisation without a TID-CMM assessment answers an eight-question prerequisite check instead — five questions on detection, three on threat modelling — which supplies R4 with a self-assessed proxy and caps the band at L4. Supply neither an import nor the check and the cap is L3. R4 is not relaxed in any of the three cases; only the credibility of the figure feeding it changes, and the ceiling states that plainly.
This strengthens the pairing rather than weakening it. A dependency that turns organisations away recruits nobody: the standalone route lets a response assessment happen at all, and it makes the value of the detection assessment legible from inside the result — the report says, in terms, that the top of the scale is unavailable until detection maturity has been assessed against its own model with its own evidence rule. An organisation that runs the standalone route and finds L4 binding has been shown precisely why TID-CMM exists, which is a better argument for it than a prerequisite ever was.
The bridge — resolving the IR domain overlap
TID-CMM v1.2 contains an IR — Incident Response & Recovery — domain at 10% with six sub-capabilities. Publishing TIR-CMM without addressing that would leave users holding two contradictory response numbers.
The resolution is substitution, not reweighting. TID-CMM keeps its IR domain at 10% — the weight does not move and existing assessments are not invalidated — but the domain is redefined and gains a substitution rule.
The redefinition narrows IR from “incident response and recovery, shallowly” to the detection-to-response interface: the handoff, not the response. Alert-to-case fidelity and enrichment, triage handoff quality and completeness of context, escalation path integrity from detection to responder, the response feedback loop into detection tuning, case data sufficiency for tempo measurement, and declared response maturity or an imported TIR-CMM score. That is genuinely within detection’s remit — a detection function is accountable for whether its output is actionable — and it removes the pretence that a detection model can assess containment.
The substitution rule is simple: where a TIR-CMM assessment is imported, TID-CMM’s IR domain takes the TIR-CMM overall score, annotated with the model version and assessment date. Where none is imported, IR is scored on the bridge sub-capabilities alone and the report is annotated “response capability not independently assessed.” Reciprocally, TIR-CMM consumes TID-CMM’s overall as D in constraint R4. Because TID-CMM’s IR is substituted by TIR-CMM rather than added to it, TIR-CMM contains no detection domain, the substitution is applied after TID-CMM’s own constraints are computed, and R4 uses the pre-substitution score, there is no circular inflation.
The change to TID-CMM is a non-breaking version bump to v1.3: IR sub-capabilities rewritten at unchanged weight, the substitution rule added to the scoring page, the export schema extended with detection_score_pre_substitution, and a cross-link added. Existing TID-CMM v1.2 assessments remain valid and comparable at overall level.
Open questions for v0.2
These are the eight decisions in the model that were not settled at publication — seven of which remain open, and one of which has since been resolved. The resolved one is kept in place, with its resolution, rather than quietly deleted: how a question was closed is as much a part of the model’s reasoning as the question was.
They are published because a maturity model that hides its uncertainties invites you to trust the parts that deserve challenge, and because every one of them is a question a practitioner is better placed to answer than an author. If you have run an assessment and one of these bit you, that is the feedback worth sending.
- R4 basis. Should D — the detection score that caps RE, CE and FI — be TID-CMM’s overall score, or the lower of its overall and its DC telemetry domain? The latter is harsher and arguably more correct, since response depends most acutely on visibility. The trade-off is double-penalisation: an organisation already constrained by TID-CMM’s C2 would be constrained again here for the same underlying weakness.
- Lattice versus domain coupling. The lattice currently constrains the band through R6 but does not feed the arithmetic. The alternative is to make it a ninth pseudo-domain. The recommendation is to keep them separate, matching TID-CMM’s treatment of its Validated Coverage Score — conflating them would let broad shallow coverage mask a structural inability to act — but the alternative should be tested against the worked example rather than assumed away.
- Threat modelling without TID-CMM.
Resolved
The question was: an organisation running TIR-CMM standalone has no assessed threat-modelling capability, so the role of TID-CMM’s C4 intent ceiling is unfilled. Two options were on the table — add a light threat-modelling gate to the RP domain, or require a minimal attack-path declaration that is itself scored — with a leaning towards the latter, because a declared path with no evidence behind it should not earn the same scope quality as an imported modelled one.
The resolution took the second option and generalised it. The tool now carries a built-in prerequisite check: eight standalone questions, five on detection and three on threat modelling, scored on the same 0–5 scale as everything else. The three modelling questions — crown jewel definition, attack path modelling and adversary prioritisation — are scored rather than assumed, and they determine how much confidence the lattice scoping carries. The five detection questions produce the figure constraint R4 consumes, so no gate had to be added to the RP domain and no domain weight moved. Because the check is a self-assessment, it carries its own ceiling: at least six of the eight must be answered, and the band is then capped at L4 — sufficient to assess response, insufficient to claim adaptive maturity on an unaudited detection figure. Supplying nothing at all still caps the band at L3. What remains genuinely open is calibration: whether six answered questions is the right threshold, and whether the L4 ceiling is too generous to a self-assessment or too harsh on an organisation that simply has no detection model available to it. - A8 (OT/ICS) depth. OT response differs enough from IT response — safe-state, manual fallback, no reimaging — that it may warrant its own sub-capability set rather than being a single column of the lattice. D3FEND now maintains a distinct OT domain, which supports splitting it. The cost is a larger model and a longer assessment for the organisations that do not run OT at all.
- Breakout time source. Where an organisation has no actor-specific breakout intelligence, the model needs a defensible default. The proposal is to use published industry breakout figures as a fallback with an explicit estimated flag, and never to allow an L4 claim on estimated tempo. The tension is obvious: a fallback that is too generous flatters everyone who has no threat intelligence, and one that is too harsh makes the tempo metric unusable for the organisations that most need it.
- MTTDecide instrumentation. Many case systems cannot distinguish “alert validated” from “containment authorised” without a process change. The tool should ship guidance on instrumenting this, because the metric is only as good as the timestamp discipline behind it — and MTTDecide is the model’s central contribution. The assessment guide carries the interim position: estimate from a sample of recent incidents, and flag the figure as estimated.
- R1 dominance. Numerical validation shows the rehearsal ceiling binding six of eight domains and subsuming R2 and R4 entirely. This is inherited behaviour — TID-CMM’s C1 has the same property — and it is directionally the model’s argument: an unrehearsed playbook is an assumed capability. But it is worth testing whether a ceiling of RV + 1.5, or exempting RP from R1, produces a more diagnostically useful spread without weakening the honesty mechanism. The independent-effect reporting rule mitigates the problem but does not resolve it.
- Worked example publication. The numerical validation in §8.8 of the specification is a validation trace, not a published worked example. v0.2 needs the practitioner-facing version with the full 58-item score sheet and lattice, matching the presentation of TID-CMM’s.
The model is stronger for publishing what is unsettled. Each of the seven still open is an invitation to argue, and an argument with evidence behind it will change the specification — as one already has.
Contribute
The model improves through counter-examples. An organisation that ran it and found the constraints wrong is the most valuable feedback there is — considerably more valuable than agreement, because agreement does not tell you where the instrument is miscalibrated.
Useful things to send:
- A constraint that fired where it should not have, or failed to fire where it obviously should have — with the domain scores that produced it.
- A lattice cell that could not be scored honestly on the 0–3 scale, and what the missing status would have been.
- An asset class or attack-path stage the eight-by-eight grid cannot express for your estate.
- A measured MTTDecide — especially one that contradicts the expectation that decision latency exceeds containment time by an order of magnitude.
- An engineered-versus-proven gap that came out very differently from the validation run’s 40.6% against 3.1%, in either direction.
- A position on any of the seven open questions above, particularly from an organisation running TIR-CMM standalone without TID-CMM, or one running OT at scale.
- A prerequisite check that came out clearly wrong — a self-assessed detection figure well above or well below what a TID-CMM assessment later produced for the same estate. That comparison is the only thing that can calibrate the standalone route.
The model is deliberately built so that criticism is cheap to act on: the domains, weights, sub-capabilities, lattice and constraints are all published in machine-readable form, so a proposed change can be tested numerically against the worked example rather than debated.
Licence and independence
- The model is licensed CC BY-ND 4.0. Use it, share it, quote it and publish your results, with attribution. Derivative models are the one thing the licence withholds, because a score only means something if it means the same thing everywhere.
- The schemas and the machine-readable model are licensed CC BY 4.0. Build integrations against them freely, including in commercial products, with attribution.
- The tooling is source-available, all rights reserved. The assessment tool, the site and the reference server are free to run, self-host and audit, but not to redistribute as your own product.
TIR-CMM is free to use, including commercially, and consultancies need no permission and owe no fee. The full terms are on the licence page.
Non-commercial. Not vendor-aligned. Nothing to buy, nothing to install. There is no product behind this model and no consultancy attached to it. The output names capabilities and authorities required, never products — a design principle inherited directly from TID-CMM, and the reason the validation run’s top five priorities contained no purchase of any kind. Everything on this site, including the assessment tool, runs entirely in your browser: no server calls, no analytics, no transmission.
Author
TIR-CMM is written by Reza Adineh, author of UTIOM — the Unified Threat-Informed Operations Model and of TID-CMM — the Threat-Informed Detection Capability Maturity Model. TIR-CMM is the response module of the first and the companion, and successor-in-scope, to the second.
TIR-CMM v0.1 · design draft, not yet published · 16 August 2026