Comparison · updated 2026-08-20
TIR-CMM vs CMMC — a contract certification against a response measurement instrument
CMMC is a US Department of Defense compliance certification you must hold to win contracts handling federal contract information or controlled unclassified information. TIR-CMM is a free incident-response maturity model. TIR-CMM is not a CMMC alternative and cannot substitute for one. CMMC says which controls you must hold; TIR-CMM says whether yours would work.
Read this first if you came looking for a CMMC alternative
There is no alternative to CMMC. CMMC is a regulatory programme codified at 32 CFR Part 170 and implemented through DFARS clauses in 48 CFR: if a solicitation carries a CMMC level requirement, you meet that level and affirm it in SPRS or you do not win the award. TIR-CMM produces no certificate, has no accreditation body, is accepted by no assessor and confers no eligibility.
The genuine relationship runs the other way round: CMMC and NIST SP 800-171 tell you which incident-response controls you must have; TIR-CMM tells you whether the ones you have would work under time pressure.
What is CMMC?
CMMC is the Department of Defense's programme for verifying that defence contractors and subcontractors implement the cybersecurity requirements already imposed by FAR clause 52.204-21 and DFARS clause 252.204-7012. The DoD — which since 2025 also operates under the name Department of War — runs the programme through the DoD CIO, replacing self-attestation with graded verification so that a contractor's claimed protection of federal contract information (FCI) and controlled unclassified information (CUI) is checked rather than assumed.
The three levels
CMMC 2.0 has three levels, defined at 32 CFR 170.14:
- Level 1 — the 15 security requirements in FAR clause 52.204-21(b)(1), covering FCI. Annual self-assessment, with annual affirmation in SPRS. No plan of action and milestones is permitted: all 15 must be met.
- Level 2 — the 110 security requirements of NIST SP 800-171 Revision 2 (February 2020, with updates as of 28 January 2021), covering CUI. Assessed every three years with annual affirmations, and met either by self-assessment (32 CFR 170.16) or by a certification assessment from a CMMC Third-Party Assessment Organisation, a C3PAO (32 CFR 170.17), depending on what the contract specifies.
- Level 3 — 24 selected requirements from NIST SP 800-172 (February 2021) with DoD-approved parameters, on top of a Level 2 certification. Assessed by the Defense Contract Management Agency's Defense Industrial Base Cybersecurity Assessment Center, DIBCAC, on a three-year cycle.
Note which NIST revision governs. CMMC Level 2 is built on Revision 2, not Revision 3, of SP 800-171. NIST published Revision 3 in May 2024, but the rule text in force cites Revision 2, and a contractor rebuilding against Revision 3 in the expectation that CMMC has moved is working ahead of the regulation. At Levels 2 and 3 a plan of action and milestones is permitted only above a minimum assessment score of 80 per cent, closed out inside 180 days and confirmed by a closeout assessment.
Where the rulemaking stands in August 2026
Two rules make up the programme, and both are final.
The 32 CFR programme rule, Cybersecurity Maturity Model Certification (CMMC) Program, was published on 15 October 2024 at 89 FR 83092 and took effect on 16 December 2024. That rule establishes the levels, the assessment types, the affirmation regime and the four-phase rollout.
The 48 CFR acquisition rule, DFARS Case 2019-D041, was published on 10 September 2025 and took effect on 10 November 2025, amending DFARS 252.204-7021 and adding the provision DFARS 252.204-7025. Both apply to solicitations issued on or after the effective date, including task and delivery orders, excluding awards solely for commercially available off-the-shelf items.
Phase 1 began on 10 November 2025. Phase 2 — the point at which Level 2 C3PAO certification assessments become a condition of award — was scheduled for 10 November 2026, and has been suspended. On 13 July 2026 the Department of War announced the suspension of CMMC Phase II and stood up a CMMC Reform Task Force to conduct a 60-day review, reporting to the DoW CIO. The DoD CIO's own CMMC pages state that implementation is paused in Phase 1 and that enforcement is currently focused on NIST SP 800-171 Rev 2 compliance through self-assessments and select government-led assessments.
What has not changed: Phase 1 obligations, DFARS 252.204-7012, Level 1 and Level 2 self-assessment requirements where a contract carries them, and the underlying 800-171 Rev 2 obligation. The suspension removed a milestone, not a duty.
The current status is genuinely unsettled. The task force's report was due within 60 days of 13 July 2026 and a supporting request for information closed on 14 August 2026; as at 20 August 2026 no outcome had been published. Re-check phase dates at dodcio.defense.gov/CMMC before relying on them in a bid decision.
What does TIR-CMM measure?
TIR-CMM measures whether an organisation can detect, decide, contain, evict and recover faster than the adversary moves, and prove it. The model holds 8 domains and 58 sub-capabilities, weights summing to 100, scored 0 to 5 across six bands from L0 Improvised to L5 Adaptive, plus a Containment Lattice of 8 attack-path stages by 8 asset classes — 64 cells maximum, typically 24 to 38 in scope — each holding a Response Readiness Status of 0 to 3 that expires 12 months after it was last proven.
The model's central metric is MTTDecide: the interval between having a validated alert and being authorised to act on it, measured separately from MTTR. Containment Margin subtracts MTTD + MTTDecide + MTTC from a priority actor's breakout time; Tempo Ratio expresses the same as a fraction, and constraint R5 caps the band at L1 when that ratio reaches 2.0. Seven constraints, R1 to R7, apply mechanically and only ever lower a score — see scoring and constraints.
How do they compare?
| Axis | CMMC | TIR-CMM v0.2 |
|---|---|---|
| Publisher | US Department of Defense, DoD CIO | Reza Adineh, UTIOM |
| Legal status | Codified in 32 CFR Part 170 and DFARS clauses in 48 CFR | None |
| Scope | All safeguarding of FCI and CUI on contractor systems | Incident response capability only |
| Structure | 3 levels: 15, 110 and 24 requirements; 14 NIST SP 800-171 families | 8 domains, 58 sub-capabilities, 64-cell lattice |
| Incident response content | 3 requirements (3.6.1-3.6.3) of 110 at Level 2 | The whole model |
| Scale | Pass or fail against a requirement set, plus an SPRS score | 0.00-5.00 across six bands, L0-L5 |
| Evidence requirement | Assessor-verified objective evidence at Levels 2 and 3 | Four evidence grades VC0-VC3, capping scores at 1, 2, 4 and 5 |
| Who assesses | Self (L1, some L2), C3PAO (L2), DIBCAC (L3) | Self, at three declared depths |
| Certification issued | Yes, recorded in SPRS | No |
| Consequence of failing | Ineligible for award; False Claims Act exposure for false affirmation | None |
| Cost | Assessment, C3PAO and remediation costs borne by the contractor | Free |
| Typical effort | Months to years of preparation; triennial reassessment | 20 minutes Pulse, 1-2 hours Baseline, 2-4 weeks Assurance |
| Adversary tempo | Not measured | Containment Margin and Tempo Ratio against breakout time |
Do they overlap?
The overlap is narrow and specific. NIST SP 800-171 Rev 2 devotes one of its 14 requirement families to incident response, and that family holds three requirements: 3.6.1, establish an operational incident-handling capability covering preparation, detection, analysis, containment and recovery; 3.6.2, track, document and report incidents to designated officials; 3.6.3, test the organisational incident-response capability.
Three requirements out of 110 is the entire CMMC Level 2 incident-response surface, and TIR-CMM's 58 sub-capabilities sit underneath them. DFARS 252.204-7012 adds the operational clock those requirements do not: cyber incidents reported to DoD within 72 hours of discovery, images of affected systems and relevant monitoring data preserved at least 90 days from submission of the report, and a review for evidence of compromise conducted. TIR-CMM's FI domain (10 per cent weight, 6 sub-capabilities) covers that evidence-handling capability; its RG domain covers reporting clocks.
CMMC Level 3 reaches further into response than most readers expect. The 24 enhanced requirements drawn from NIST SP 800-172 include a security operations centre operating 24 hours a day, seven days a week, and a cyber incident response team deployable within 24 hours — the closest CMMC comes to TIR-CMM, and still a test of existence rather than of proven effectiveness against a clock.
Where CMMC is stronger
CMMC is enforceable and TIR-CMM is not, and that single difference outweighs every structural comparison on this page. A CMMC level requirement in a solicitation carries the force of federal acquisition regulation; a false affirmation in SPRS carries False Claims Act exposure. TIR-CMM has no enforcement mechanism, no sanction and no consequence of any kind.
CMMC is also verified by someone other than you: at Level 2 certification a C3PAO examines objective evidence against 110 requirements, and at Level 3 DIBCAC does it. TIR-CMM's Baseline depth is entirely self-scored, which is why constraint R7 caps a Baseline result at L4 and reserves L5 for an Assurance assessment with independent evidence review. External assessment is a stronger assurance mechanism than a self-imposed ceiling.
CMMC's breadth is greater by an order of magnitude. The 110 Level 2 requirements span 14 families, from access control and audit and accountability through media protection and physical protection to system and information integrity. TIR-CMM covers one of those 14 families and nothing else.
Use CMMC instead if — and this is not really a choice — you hold or intend to bid for US Department of Defense contracts that process, store or transmit FCI or CUI. TIR-CMM does not substitute for CMMC, reduce its scope, satisfy any of its requirements or shorten any assessment.
Where TIR-CMM is stronger
TIR-CMM answers a question CMMC does not ask. NIST SP 800-171 requirement 3.6.1 asks whether an incident-handling capability exists; 3.6.3 asks whether it has been tested. Neither asks who is permitted to isolate a production domain controller at 03:00 on a Sunday, how long that authorisation takes, or whether the containment chain finishes inside the adversary's breakout window. TIR-CMM's RA domain — Response Authority & Decision Rights, 12 per cent of the weight, 6 sub-capabilities — exists for that gap, and constraint R2 holds automation and containment scores to the authority score plus one: automation nobody is permitted to fire is a demonstration, not a capability.
Testing is the sharpest divergence. Requirement 3.6.3 is satisfied by a tabletop exercise and an assessor may accept one. TIR-CMM's R1 constraint caps every domain other than validation at the validation score plus one, and a lattice cell reaches status 3 only on execution against a real incident or live fire, at the designed blast radius, inside its stage time objective, within the last 12 months. An organisation can hold a clean Level 2 certification and score L1 in TIR-CMM without either result being wrong.
Speed is measured in only one of the two models. CMMC's clocks are reporting clocks — 72 hours to DoD, 90 days of preserved images, 180 days to close a POA&M, annual affirmations, triennial reassessment — and none is an adversary clock. TIR-CMM measures the containment chain against actor breakout time: Tempo Ratio at or above 2.0 caps the band at L1, between 1.0 and 2.0 caps at L2, and tempo not supplied at all caps at L3 with the report marked "tempo unverified".
TIR-CMM also costs nothing and takes hours rather than months: model CC BY-ND 4.0, schemas CC BY 4.0, tooling source-available, and the assessment tool runs entirely in the browser, transmitting no assessment data anywhere.
Can you run both?
Running both is coherent, and the sequence is not negotiable: CMMC first, because CMMC decides whether you have a business; TIR-CMM afterwards, because a Level 2 certification tells the DoD your incident-handling capability exists and tells you nothing about whether it would hold.
The productive use of TIR-CMM inside a CMMC programme is as the depth instrument behind three requirements. Run a Baseline assessment scoped to your CUI enclave: the 58 sub-capabilities and the lattice show which stages on which asset classes have no response option, what your MTTDecide actually is, and which of the seven constraints binds — in most organisations R1.
Be exact about what that output is and is not. A TIR-CMM report is not a CMMC artefact: no C3PAO is obliged to accept it, no DIBCAC assessor will score against it, and it appears nowhere in 32 CFR Part 170. Evidence generated during a TIR-CMM assessment — dated exercise reports, timestamped containment logs, signed authorisation matrices — may support a 3.6.1 or 3.6.3 finding. The score itself supports nothing.
Which should you run?
If you bid for US Department of Defense work, run CMMC. There is no if. Determine the level your contracts carry, meet it, affirm it in SPRS, and check the current phase status at the DoD CIO before assuming any date.
If you already hold or are pursuing CMMC and want to know whether your incident response would actually work, run TIR-CMM Baseline. One to two hours, 58 sub-capabilities with evidence grades, the lattice scoped to your CUI enclave, measured tempo. TIR-CMM will not help you pass a C3PAO assessment; it tells you whether the capability the certificate attests to survives contact with a clock.
If you have no DoD exposure, CMMC is not your framework and TIR-CMM might be. Adopting CMMC voluntarily buys a control baseline you could take from NIST SP 800-171 directly, without the certification apparatus.
If you are choosing between them because you think they are alternatives, stop. One is a licence to bid; the other is a measuring instrument.