Comparison · updated 2026-08-20

TIR-CMM vs the CISA Zero Trust Maturity Model — architecture posture against response capability

CISA's Zero Trust Maturity Model measures architectural posture across five pillars; TIR-CMM measures whether an organisation can execute an incident response. ZTMM version 2.0 states plainly that it does not address incident response. Run ZTMM to plan the estate, TIR-CMM to test whether that estate can be defended once an adversary is already inside it.

What is the CISA Zero Trust Maturity Model?

The Zero Trust Maturity Model, published by the US Cybersecurity and Infrastructure Security Agency, is a roadmap for moving an enterprise estate towards zero-trust architecture. Version 2.0, dated April 2023 and 32 pages long, supersedes the version 1.0 released in September 2021 — one major revision in nineteen months, and no further revision published since. CISA structures the model as five pillars — Identity, Devices, Networks, Applications and Workloads, Data — with three cross-cutting capabilities repeated inside every pillar: Visibility and Analytics, Automation and Orchestration, Governance.

Each pillar decomposes into functions: four each under Identity, Devices and Networks, five each under Applications and Workloads and Data, giving 22 functions in total. Adding the three cross-cutting capability rows to each of the five pillars produces 37 assessable rows. Every row is graded against four maturity stages — Traditional, Initial, Advanced, Optimal — described in version 2.0 as a gradient rather than a set of discrete gates, so an agency can make incremental progress inside a single function.

Who ZTMM is actually for

ZTMM version 2.0 is written for US Federal Civilian Executive Branch agencies. Version 2.0 states it "is specifically tailored for federal agencies as required by EO 14028", and CISA's own guidance records that agencies were required to achieve specific zero-trust goals by the end of Fiscal Year 2024 under the OMB federal zero-trust strategy, Memorandum M-22-09. For everyone else the model is advisory and explicitly so: version 2.0 adds that "all organizations should review and consider adoption of the approaches outlined in this document" and that the model "should not be viewed as a strict set of requirements but as a general guide". No certification exists, no assessor scheme exists and the document is free.

What ZTMM says it does not cover

CISA draws the boundary itself, in one sentence in version 2.0: the model "does not address other aspects of cybersecurity such as activities related to incident response, specifics for logging, monitoring, alerting, forensic analysis, risk acceptance, recovery". That exclusion is not an oversight to be worked around. Zero trust is a design philosophy about how access decisions are made; running an incident is a different discipline with different failure modes. A CISO who reads the ZTMM exclusion list and notices that it covers most of what happens on the worst day of the year has correctly identified the gap this comparison is about.

What does TIR-CMM measure?

TIR-CMM measures one thing: whether an organisation can act on an intrusion in time, with someone permitted to authorise the action, at the blast radius intended — and prove it. The model runs 8 domains and 58 sub-capabilities with weights summing to 100, scored 0–5 against six maturity bands from L0 Improvised to L5 Adaptive. Alongside the questionnaire sits the Containment Lattice — 8 attack-path stages by 8 asset classes, 64 cells maximum, of which a typical scope is 24–38 — where each cell carries a Response Readiness Status of 0 to 3 and status 3 expires after twelve months.

TIR-CMM's central claim is a metric: MTTDecide, the interval between knowing and being authorised to act, measured separately from MTTR. Seven integrity constraints, R1 to R7, only ever lower a score. Evidence is a ceiling rather than a conversion — VC0 caps a sub-capability at 1, VC1 at 2, VC2 at 4, VC3 at 5. See scoring and constraints for the arithmetic.

Side by side

Axis CISA ZTMM v2.0 TIR-CMM v0.2
What it measuresArchitectural posture against zero-trust principlesAbility to detect-to-contain an active intrusion and prove it
PublisherCISA, a US federal agencyReza Adineh, UTIOM — independent, not vendor-aligned
Current version2.0, April 20230.2, 17 August 2026
Structure5 pillars, 22 functions, 3 cross-cutting capabilities8 domains, 58 sub-capabilities, weights summing to 100
Scale4 stages: Traditional, Initial, Advanced, Optimal0–5 continuous, banded L0–L5
Second scoring axisNone — functions onlyContainment Lattice, 8 stages × 8 asset classes = 64 cells
Evidence requirementNot specified; agency self-assessmentExplicit: VC0–VC3 caps scores at 1, 2, 4, 5
Time measurementNoneMTTDecide, MTTC, Containment Margin against adversary breakout time
Incident responseExcluded by the document's own scope statementThe entire subject
MandateRequired for US federal civilian agencies under EO 14028 and M-22-09; advisory for all othersAdvisory for everyone; no mandate anywhere
CostFreeFree
CertificationNoneNone
Typical effortMulti-week estate survey across five pillars20 minutes (Pulse), 1–2 hours (Baseline), 2–4 weeks (Assurance)
OutputStage per function, architecture roadmapBand, Validated Response Score, Containment Margin, ranked roadmap
LicenceUS government publication, TLP:CLEARModel CC BY-ND 4.0; schemas CC BY 4.0; tooling source-available

Do they overlap?

Overlap between ZTMM and TIR-CMM is narrow but real, and it sits in exactly two places. ZTMM's Automation and Orchestration cross-cutting capability concerns, in version 2.0's wording, "automated tools and workflows that support security response functions across products and services" — that is response machinery, described at the architectural level. ZTMM's own stage definitions carry response language too: Traditional includes "manual response and mitigation deployment" and Advanced includes "response to pre-defined mitigations". TIR-CMM's AO domain, weighted 12%, asks the harder version of the same question — does machine speed actually reach the decision, or does the automation stop at an approval nobody can give at 03:00.

Everywhere else the two models pass each other without touching. ZTMM has no equivalent of response authority, no rehearsal requirement, no forensic domain and no clock. TIR-CMM has no view on traffic encryption, data categorisation or supply chain risk.

Identity maturity is where zero trust becomes a containment option

The most useful connection between ZTMM and TIR-CMM is not a crosswalk row — it is a causal chain, and it runs through identity. TIR-CMM's lattice carries an asset class A1, Identity & Access Infrastructure, covering Tier-0 estate: Active Directory, Entra ID, the IdP, PAM. The containment primitives TIR-CMM expects at A1 are disable, revoke session or token, force re-authentication, break trust and tier-isolate. Whether those primitives exist at all is decided by ZTMM Identity-pillar maturity, not by the incident response team.

Consider an estate sitting at ZTMM Traditional on the Identity pillar: identity stores are siloed, lifecycle assignment is manual, least privilege is established only at provisioning. In that estate, a global token revocation is not a button anybody can press. TIR-CMM will score cells S3×A1 (Privilege Escalation & Credential Access on identity infrastructure) and S4×A1 (Discovery & Lateral Movement on identity infrastructure) at Response Readiness Status 0 or 1 — no option, or manual only. If either cell is a Tier-1 crown-jewel cell, constraint R6, the blind-cell gate, caps the whole assessment at band L2 regardless of how good the playbooks are.

Move the same estate to ZTMM Advanced or Optimal on Identity — consolidated identity stores, continuous validation, real-time risk assessment, just-in-time authorisation — and those cells become technically actionable. They do not become mature. Status 2 in TIR-CMM means engineered, owned and pre-authorised but unproven; status 3 requires the revocation to have been executed against a real incident or a live-fire exercise within twelve months, inside its stage time objective, with the blast radius as designed. Zero-trust maturity buys the primitive. TIR-CMM asks whether anybody is permitted to fire it, whether it has been fired recently and whether it landed inside the adversary's breakout window. Constraint R2 makes the point mechanically: AO and CE cannot exceed RA, the authority domain, plus one. An Optimal identity architecture with an unreachable approver scores no better than a Traditional one.

Where the CISA ZTMM is stronger

ZTMM is far broader than TIR-CMM and better at the thing TIR-CMM barely touches: deciding what to build. Five pillars and 22 functions cover segmentation, encryption, device compliance, application security testing, data categorisation and supply-chain risk — a multi-year modernisation agenda. TIR-CMM's entire architectural interest is one lattice row, S0 Prevent & Harden, carrying the highest stage leverage in the model at λ 1.6 precisely because an attack path that architecture closes never needs a response. One row is not an architecture programme.

ZTMM also carries something TIR-CMM structurally cannot: federal authority. A US agency reporting zero-trust progress against OMB M-22-09 needs ZTMM stages, and no independent maturity model substitutes for that. ZTMM is a US government publication with an agency behind it and a public comment process behind version 2.0; TIR-CMM is version 0.2 of an independent model published in August 2026 with no institutional backing at all.

Use ZTMM instead of TIR-CMM if you are a federal civilian agency reporting against M-22-09, if your question is which architectural investment to fund next, or if the organisation has not yet decided how access decisions should be made. TIR-CMM will not answer any of those, and it will not pretend to.

Where TIR-CMM is stronger

TIR-CMM measures execution under a clock, which ZTMM does not attempt. Three mechanisms carry that difference. Constraint R5 converts response tempo into a band ceiling: where MTTD plus MTTDecide plus MTTC divided by adversary breakout time reaches 2.0, the band caps at L1; at 1.0 it caps at L2; supply no tempo evidence at all and the band caps at L3. Constraint R1 caps every domain at the rehearsal domain score plus one, so unexercised capability cannot inflate the result. Constraint R3 caps each sub-capability by its evidence grade, meaning an assertion cannot outrank an audited finding.

TIR-CMM is also far cheaper to run. A Pulse assessment takes 20 minutes and caps at L3; Baseline takes 1–2 hours and caps at L4; Assurance takes 2–4 weeks and removes the depth ceiling. Everything runs in the browser and no assessment data is transmitted anywhere — see the assessment tool. A ZTMM self-assessment across 37 rows of a federal estate is a materially larger undertaking with no published time estimate.

Can you use both?

Running both models together is the intended configuration for a non-federal organisation, and the sequencing is not symmetrical. ZTMM produces the architectural facts that decide which containment primitives exist; TIR-CMM consumes exactly those facts when scoping the Containment Lattice across asset classes A1 to A8. ZTMM Identity maturity governs what is possible at A1. ZTMM Networks maturity — segmentation, traffic management, network resilience — governs what is possible at A5, Network & Edge. ZTMM Data maturity governs A7, Data Stores & Backup.

A practical pattern: score ZTMM once a year at pillar level as an architecture roadmap, and run a TIR-CMM Baseline quarterly against the estate that architecture produced. The two outputs answer different board questions. ZTMM answers "are we building the right estate". TIR-CMM answers "if it started tonight, could we stop it, and can you prove that".

Which should you run?

If you are a US federal civilian agency, run ZTMM — it is required, and TIR-CMM does not substitute for a mandated reporting instrument. Add a TIR-CMM Pulse afterwards for the 20 minutes it costs, because ZTMM will not tell you whether your incident response works and version 2.0 says as much in its own scope statement.

If you are not a federal agency and you have never assessed zero-trust posture, run ZTMM first. Architecture decides which containment options can exist at all, and measuring response capability across an estate you have not yet decided how to build produces a roadmap you will invalidate.

If your architecture programme is already running and your worry is the incident, run TIR-CMM first. ZTMM will tell you your Identity pillar is Advanced. It will not tell you that the only person permitted to isolate a domain controller is unreachable for forty minutes at 03:00, that the isolation playbook has never been executed against a clock, or that your MTTDecide exceeds your MTTC by an order of magnitude. Those findings sit in the model, and none of them are visible from an architecture assessment.

If you can only run one and you are trying to decide what to spend next year's budget on, run ZTMM. TIR-CMM is narrow by design — it measures response capability and nothing else — and a narrow instrument is the wrong tool for a broad allocation question.