Changelog · updated 2026-08-20
TIR-CMM changelog
TIR-CMM is at version 0.2, published 17 August 2026. This page records what changed in each version of the model and of this site, with dates, so that anyone comparing two assessments can tell whether a score moved because the organisation changed or because the model did.
Does a version change invalidate my score?
A version change can move a score without anything about the organisation changing, which is why every change is recorded here rather than applied silently. The rule TIR-CMM follows: scores are comparable within a minor version, and a change that alters scoring is called out explicitly below. Version 0.2 changed the evidence rule, which moves most v0.1 scores down. Re-scoring against v0.2 is worth doing before comparing a v0.1 result to anything.
Site — 20 August 2026
Content and structure, no change to the model or its arithmetic. Scores produced before and after this date are identical.
- Added a comparison cluster: eight pages covering NIST CSF 2.0, NIST SP 800-61r3, C2M2, CMMC, MITRE D3FEND, SIM3, the CISA Zero Trust Maturity Model and TID-CMM. Each states where the other framework is the better instrument.
- Rebuilt the glossary from a single 40-row table into 40 self-contained definitions, each with its own anchor, so a definition can be quoted without the rest of the page.
- Added 197 links from where a defined term is used to where it is defined. There were none before.
- Gave all 450 section headings a stable anchor, up from 152, so any section can be linked to directly.
- Added an answer-first summary to the top of every page.
- Corrected two retired NIST identifiers on the standards alignment page:
PR.IPandPR.PTwere CSF 1.1 codes with no CSF 2.0 equivalent, and are nowPR.PSandPR.IR. - Replaced
HowTostructured data withItemList. The three assessment depths are mutually exclusive choices, not sequential steps, and the previous markup told a crawler otherwise. - Added
DatasetandSoftwareSourceCodestructured data for the machine-readable model and the scoring library. - Made every AI crawler permission explicit in
robots.txt, separating training crawlers from search and citation crawlers.
Version 0.2 — 17 August 2026
The release that made the model usable in twenty minutes and honest about partial data.
- Three assessment depths. Pulse takes 20 minutes and caps the reported band at L3. Baseline takes 1 to 2 hours and caps at L4. Assurance takes 2 to 4 weeks with no ceiling from depth. Each is a strict superset of the one below.
- Graduated evidence ceilings, replacing a yes/no flag. Evidence is now classed VC0 to VC3, capping a sub-capability at 1, 2, 4 and 5 respectively. Under v0.1's single "named, dated artifact" flag, a policy document and a tested implementation gave the same answer. On the worked example this took the R3 firing count from 3 to 6.
- A new lattice stage. S0, Prevent and Harden, was added at the top of the Containment Lattice with the highest stage leverage of 1.6. An attack path that architecture closes never needs a response. The lattice is now 8 stages by 8 asset classes, 64 cells.
- Standalone use became the default. An eight-question detection check now stands in for a TID-CMM import, carrying an L4 band ceiling rather than the L3 that supplying nothing carries.
- Constraint R7 added, capping the band by assessment depth and by governance quality. Seven integrity constraints now, not five.
- Unscored domains are excluded rather than scored zero. A domain nobody answered used to score 0.00, which then became a ceiling of 1.00 under R1 or R2 and dragged every other domain down with it. A half-finished assessment read as a catastrophic organisation. Coverage is now reported alongside every score.
- Band ceilings are recorded only when they bind. An assessment at L0 used to be told its band was held down by L3 and L4 ceilings that were not constraining anything.
- Tempo entries are validated. Negative, non-numeric, zero-breakout and all-zero timings are rejected as input errors rather than accepted as measurements. An all-zero tempo previously reached L5.
Version 0.1 — 16 August 2026
The first complete model. Eight domains, 58 sub-capabilities, a 7-stage by 8-asset Containment Lattice, six maturity bands, and five integrity constraints. Complete, and too heavy to start with — which is what version 0.2 addressed.
What is still open
Several design questions are deliberately unresolved, and an organisation that ran the model and found one of them miscalibrated is the most valuable input there is. The full list is on the about page. The two most consequential: whether R1's rehearsal ceiling is too aggressive, and whether capping a self-assessed detection figure at L4 is calibrated correctly.