Changelog · updated 2026-08-24
TIR-CMM changelog and version compatibility
The TIR-CMM model is at version 1.0, published 24 August 2026. This page records what changed in each version, and sets out which artifact versions work together. Anyone comparing two assessments needs both: a score can move because the organisation changed, or because the model did, and only one of those is progress.
Why the version numbers differ, and why that is correct
TIR-CMM ships four artifacts that change for different reasons and at different rates. They carry independent version numbers on purpose, and forcing them to match would either freeze one or falsely imply the others had changed.
| Artifact | Current | What a change means |
|---|---|---|
| Model | 1.0 | The domains, weights, anchors, constraints and scoring rules. A change here can move a score. |
| Browser tool and library | 1.0.0 | The implementation. A change here fixes behaviour or adds interface; it must never change a score on its own. |
| Export schema | 1.0 | The import/export contract. A change here affects integrators. |
| Workbook | 1.0 | Tracks the model, because it is a rendering of the model. |
Every export states all four separately, so a consumer can tell exactly what produced a result:
``json { "schema": "tir-cmm/export/1.0", "schema_version": "1.0", "model_version": "1.0", "tool_version": "1.0.0", "assessment_tier": "baseline", "assessed_at": "2026-08-24" } ``
Scores are comparable within a model minor version. A model change that alters scoring is called out explicitly below.
Version 1.0 — 24 August 2026
The release that closes the model's open methodological questions and makes its honesty mechanisms real rather than documented.
Constraint R5b: estimated tempo cannot evidence a validated capability
A tempo result computed from an estimated breakout window, or from estimated interval timings, now caps the band at L3. This rule was published on this site from v0.2 and was never implemented. Until now, selecting an adversary archetype with a 1440-minute breakout window produced a Tempo Ratio of 0.03 and permitted L5 on a guess.
"Estimated" means not measured in the assessed environment. A published cross-industry benchmark is a legitimate default and is still an estimate for a specific estate.
Breakout time now carries its source
Five ranked sources, of which the first two count as measured:
| Rank | Source | Measured? |
|---|---|---|
| 1 | Observed in your own incidents or exercises | Yes |
| 2 | Actor-specific threat intelligence | Yes |
| 3 | Sector-specific evidence | No |
| 4 | Published industry benchmark | No |
| 5 | Assessor estimate | No |
Source, reference and date are recorded with the figure. Unknown provenance is treated as an estimate.
The three tempo intervals are defined by start and stop events
Only MTTDecide was normatively defined before, so two assessors could not measure the same thing. All four are now specified: MTTDetect ends when a human or system has validated the activity as a real incident, not when an alert fired. MTTContain ends when the action has taken effect, not when it was issued. The model also records P50, P90, sample size, measurement window and data source where available, and flags a mean drawn from fewer than ten timed incidents as underpowered.
Proof expires — section 3.6, finally enforced
The specification has called the twelve-month expiry "the single most important honesty mechanism in the model" since v0.2, and nothing implemented it. A lattice cell at Proven now reverts to Engineered when the proof is older than twelve months, when no proof date is recorded at all, or when any of five structural changes applies: the tooling, the on-call model, the owner or team, the architecture, or the provider. VC3 evidence likewise grades to VC2 when undated or aged.
This is the change most likely to move your score. An assessment carried over from v0.2 has no dates, so its Proven cells and VC3 evidence will grade down until dates are added. That is the intended behaviour of a mechanism that was normative but unenforced — see the migration note below.
Band ceilings are no longer suppressed
A ceiling landing on a band that another ceiling had already reached was discarded as "not binding". A Tier-1 blind cell under R6 therefore vanished from the report and the export whenever tempo under R5 had already capped to L2 — exactly the co-occurring failure the model exists to surface. Ceilings are now evaluated against the band the score earns, so every binding ceiling is reported. Exports carry ceilings_considered with every ceiling and whether it binds.
Thirteen consistency checks
A new advisory layer that never changes a score. Each check names a pattern that is usually a scoring error, states which answers conflict, why it matters, whether an integrity constraint already governs it, and what to verify. They are deliberately not constraints: turning a heuristic into arithmetic would penalise the same weakness twice.
R4 detection dependency: the open question is closed
D is TID-CMM's constraint-adjusted, pre-substitution overall detection score. The telemetry domain is not used as a second cap, because TID-CMM has already applied its own visibility constraints and capping again on the same weakness would penalise it twice. Where telemetry sits materially below the overall figure, consistency check C13 raises it as context rather than a penalty.
Also in 1.0
- Evidence records carry a date and an artifact reference.
- Exports carry the full contract: the tool and the reference server now emit the same fields, and the export schema requires 27 of them rather than 5.
- Blueprint items carry impact, effort, horizon, acceptance criteria and closure fields, so a plan can be reproduced and tracked rather than arriving as an unordered list.
- The S0 Prevent & Harden boundary is defined with in-scope and out-of-scope examples: it measures pre-incident attack-path interruption that changes response readiness, not general vulnerability management.
- ATT&CK, D3FEND, actor and procedure references may be recorded beneath a lattice cell as optional traceability. They are never mandatory scoring dimensions.
- An OT/ICS profile is published as a normative extension design and is explicitly not validated.
- Two retired NIST CSF 1.1 identifiers were corrected, and three crosswalk errors fixed against primary sources: ISO/IEC 27035-1:2023 has no "Recovery" phase, SOC-CMM has no "Governance" domain, and NIST SP 800-61r3 does not carry the r2 lifecycle phases.
Migrating a v0.2 assessment
A v0.2 progress file loads into the v1.0 tool without error. Three things will change in the result, all of them deliberate:
- Proven lattice cells will show as Engineered until you add a proof date. The report names each reverted cell and why.
- VC3 evidence will grade as VC2 until you add an evidence date, which lowers the affected sub-capability ceiling from 5 to 4.
- If your breakout figure came from a preset, the band will cap at L3 under R5b until you record a measured or actor-specific source.
Nothing is lost and nothing is silently changed: every reversion is listed in the report and in the export's recency block. To restore a score, add the dates — which is the point of the mechanism.
If you need to compare a v1.0 result against a v0.2 one, compare the self-assessed figure, which is unaffected by any of this.
Version 0.2 — 17 August 2026
- Three assessment depths: Pulse (20 minutes, caps at L3), Baseline (1–2 hours, caps at L4), Assurance (2–4 weeks, no depth ceiling).
- Graduated evidence ceilings VC0–VC3 replacing a yes/no artifact flag, capping at 1, 2, 4 and 5.
- S0 Prevent & Harden added to the Containment Lattice with the highest stage leverage of 1.6, making it 8 stages by 8 asset classes.
- Standalone use became the default, with an eight-question detection check carrying an L4 ceiling.
- Constraint R7 added, capping the band by assessment depth and governance quality.
- Unscored domains excluded from the mean rather than scored zero.
- Tempo entries validated: negative, non-numeric, zero-breakout and all-zero timings rejected as input errors.
Version 0.1 — 16 August 2026
The first complete model. Eight domains, 58 sub-capabilities, a 7-stage by 8-asset Containment Lattice, six maturity bands, five integrity constraints. Complete, and too heavy to start with, which is what v0.2 addressed.
What TIR-CMM v1.0 is not
Version 1.0 means the model specification is stable and internally validated: the arithmetic is verified, the specification matches the machine-readable model, and the browser tool, the scoring library, the REST implementation and the Excel workbook produce the same numbers on the same inputs.
It does not mean the model has been independently validated, piloted across organisations, or established as an industry benchmark. No practitioner pilot has been run. Inter-assessor variance is unmeasured. The OT/ICS profile is a design and has never been used. Those limitations are stated in the specification and will stay there until real evidence replaces them.