Comparison · updated 2026-08-20

TIR-CMM vs NIST CSF 2.0 — how the Respond function and a response maturity model differ

NIST CSF 2.0, published 26 February 2024, is an outcome catalogue: six Functions, 22 Categories and a Respond function of 4 Categories and 13 Subcategories. TIR-CMM is a measurement instrument: 8 domains, 58 sub-capabilities, scored 0–5 against evidence. CSF tells you what good response looks like. TIR-CMM tells you whether yours works, and how fast.

What is NIST CSF 2.0?

The NIST Cybersecurity Framework 2.0 is published by the US National Institute of Standards and Technology as NIST CSWP 29, released 26 February 2024 and replacing CSF 1.1 from 2018. Version 2.0 added a sixth Function, GOVERN (GV), alongside the five carried forward from 1.1: IDENTIFY (ID), PROTECT (PR), DETECT (DE), RESPOND (RS) and RECOVER (RC). NIST defines GOVERN as the Function under which "the organization's cybersecurity risk management strategy, expectations, and policy are established, communicated, and monitored."

The CSF Core is a hierarchy of Functions, Categories and Subcategories. Counting the Appendix A Core, CSF 2.0 contains 22 Categories: 6 under GOVERN, 3 under IDENTIFY, 5 under PROTECT, 2 under DETECT, 4 under RESPOND and 2 under RECOVER. Every Subcategory is written as a desired outcome, not an action. CSF 2.0 §2 is explicit about that: "These outcomes are not a checklist of actions to perform; specific actions taken to achieve an outcome will vary by organization and use case."

What the Respond function actually contains

RESPOND (RS) is defined in CSF 2.0 as "Actions regarding a detected cybersecurity incident are taken." Respond holds 4 Categories and 13 Subcategories in total:

  • RS.MA — Incident Management (5 Subcategories, RS.MA-01 to RS.MA-05): plan execution, triage and validation, categorisation and prioritisation, escalation, and the criteria for initiating recovery.
  • RS.AN — Incident Analysis (4 Subcategories: RS.AN-03, RS.AN-06, RS.AN-07, RS.AN-08): establishing what took place and root cause, recording investigative actions, preserving incident data and metadata, and estimating magnitude.
  • RS.CO — Incident Response Reporting and Communication (2 Subcategories: RS.CO-02, RS.CO-03): notifying stakeholders and sharing information.
  • RS.MI — Incident Mitigation (2 Subcategories: RS.MI-01, RS.MI-02): "Incidents are contained" and "Incidents are eradicated."

Two Subcategories carry the entire weight of containment and eradication in CSF 2.0. Restoration lives next door in RECOVER (RC.RP, RC.CO — 8 Subcategories). The Subcategory numbering is deliberately non-sequential, because 2.0 withdrew and renumbered elements from 1.1 and left the gaps in place.

CSF Tiers describe risk-governance rigour, not capability maturity

CSF 2.0 defines four Tiers — Tier 1 Partial, Tier 2 Risk Informed, Tier 3 Repeatable, Tier 4 Adaptive — and they are commonly misread as a maturity scale. CSF 2.0 §3.2 states: "An organization can choose to use the Tiers to inform its Current and Target Profiles. Tiers characterize the rigor of an organization's cybersecurity risk governance and management practices, and they provide context for how an organization views cybersecurity risks and the processes in place to manage those risks."

Tiers apply to the Profile as a whole, not to individual Subcategories, and they describe how the organisation governs risk, not how well any specific outcome is achieved. The word "maturity" appears only twice in CSF 2.0, both times to say the framework is useful "regardless of the maturity level" of a cybersecurity programme. NIST also frames Tier movement as conditional rather than aspirational: "Progression to higher Tiers is encouraged when risks or mandates are greater or when a cost-benefit analysis indicates a feasible and cost-effective reduction of negative cybersecurity risks."

Organizational Profiles are how CSF expresses current versus target

CSF 2.0 §3.1 defines two Profiles. A Current Profile "specifies the Core outcomes that an organization is currently achieving (or attempting to achieve) and characterizes how or to what extent each outcome is being achieved." A Target Profile "specifies the desired outcomes that an organization has selected and prioritized." NIST gives five steps for using them: scope, gather information, create, analyse gaps, and implement and update.

Note what CSF does not supply. NIST provides no scale, no scoring arithmetic and no evidence standard for "how or to what extent each outcome is being achieved." Each organisation invents that itself, which is why two CSF Profiles from two organisations are almost never comparable. NIST is also unambiguous that no conformity assessment exists: the CSF FAQs state that "NIST does not offer certifications or endorsements of CSF-related products, implementations, or services, and there are no plans to develop a conformity assessment program."

What does TIR-CMM measure?

TIR-CMM measures one thing: whether an organisation can stop an intrusion in time, and whether it can prove it. The model has 8 domains with weights summing to 100 — Response Preparation & Readiness (10), Response Authority & Decision Rights (12), Response Engineering & Playbooks (16), Containment, Eradication & Recovery (14), Automation & Orchestration (12), Forensics, Evidence & Investigation (10), Response Validation & Exercising (14) and Response Governance, Metrics & Improvement (12). Beneath those sit 58 sub-capabilities, each scored 0–5 and rolled up to six maturity bands from L0 Improvised to L5 Adaptive.

Three mechanisms do the work that a catalogue cannot. The Containment Lattice crosses 8 attack-path stages against 8 asset classes to give 64 cells, of which a typical scope is 24–38, and each in-scope cell is scored 0 to 3 for whether an option exists, is engineered, or has been proven. Scoring and constraints applies seven integrity constraints, R1 to R7, which only ever lower a score and never raise it. And evidence acts as a ceiling rather than a conversion: VC0 assertion caps a sub-capability at 1, VC1 design at 2, VC2 implemented and tested at 4, VC3 repeatably validated at 5.

The central claim is a timing one. TIR-CMM measures MTTDecide — the interval between knowing and being authorised to act — separately from MTTR, on the argument that most of the loss sits in that interval and it is invisible once folded into a single mean time to respond. Tempo Ratio compares MTTD + MTTDecide + MTTC against the priority actor's breakout time, and constraint R5 caps the band at L1 when that ratio is 2.0 or worse, and at L2 when it is 1.0 or worse.

TIR-CMM vs NIST CSF 2.0 at a glance

Axis NIST CSF 2.0 TIR-CMM v0.2
ScopeWhole cybersecurity risk programme: 6 Functions, 22 CategoriesIncident response capability only: 8 domains, 58 sub-capabilities
What it isOutcome catalogue and taxonomyMeasurement instrument with fixed arithmetic
Response contentRS: 4 Categories, 13 Subcategories; RC adds 2 Categories, 8 Subcategories8 domains, 58 sub-capabilities, plus a 64-cell lattice scoped to 24–38 cells
ScaleNone for outcomes; Tiers 1–4 apply to the Profile as a whole0–5 per sub-capability, six bands L0–L5, weights summing to 100
Meaning of the scaleRigour of risk governance and management practiceDemonstrated response capability against adversary tempo
Evidence requirementNot specified; each organisation defines its ownMandatory ceiling — VC0 caps at 1, VC1 at 2, VC2 at 4, VC3 at 5
Time measurementNone publishedMTTDecide, MTTC and Tempo Ratio against actor breakout time
Anti-inflation mechanismNone7 constraints, R1–R7, that only lower scores
Expiry of a claimNot addressedProven status reverts after 12 months, or on tooling, on-call, owner or architecture change
Current-vs-target expressionCurrent Profile and Target Profile, five stepsBand, per-domain scores, lattice gaps and a sequenced roadmap
PublisherNIST, a US federal agencyReza Adineh, UTIOM — an individual author, not a standards body
CostFreeFree
CertificationNone; NIST states no conformity assessment programme is plannedNone; no accreditation, no vendor
Update cadenceMajor revisions: 1.0 in 2014, 1.1 in 2018, 2.0 in 2024v0.2 published 17 August 2026; no fixed cadence
Typical effortWeeks to months for an Organizational Profile across 22 Categories20 minutes (Pulse), 1–2 hours (Baseline), 2–4 weeks (Assurance)
OutputA Profile: current outcomes, target outcomes, gap action planA band, two headline metrics, blind cells and a prioritised roadmap

Do they overlap?

Overlap exists, and TIR-CMM's standards alignment page maps it at domain level: RE to RS.AN and RS.MI, CE to RS.MI and RC.RP, FI to RS.AN and ID.RA, AO to RS.MI and DE.AE, RA to GV.RR and RS.MA, RG to GV, ID.IM and RS.CO.

The overlap is one of subject, not of function. CSF Subcategory RS.MI-01 says "Incidents are contained." TIR-CMM's CE domain and the Containment Lattice answer which incidents, at which of 8 attack-path stages, on which of 8 asset classes, with what blast radius, under whose authority, proven when. RS.MI-01 is one sentence; the same ground in TIR-CMM is 8 sub-capabilities in CE plus up to 38 in-scope lattice cells. Neither statement contradicts the other. One names the outcome and one measures the distance to it.

One genuine gap runs the other way. No CSF Category corresponds cleanly to TIR-CMM's RA domain — response authority and decision rights. GV.RR covers roles, responsibilities and authorities at the governance level, and RS.MA-04 covers escalation, but neither asks how long it takes to get a containment decision authorised at 03:00 on a Sunday. TIR-CMM's crosswalk marks this absence deliberately.

Where NIST CSF 2.0 is stronger

CSF 2.0 is stronger on almost every axis that is not response measurement, and the difference is not close. CSF covers the full risk programme across 6 Functions where TIR-CMM covers one slice of one Function. CSF has supply chain risk management as a whole Category (GV.SC), plus asset management, data security, platform security, awareness and training and continuous monitoring — none of which TIR-CMM touches at all. If the question on the table is "how mature is our security programme," TIR-CMM cannot answer it and does not try.

Authority is the second difference. NIST is a federal standards body, and regulators, insurers, auditors and boards recognise a CSF Profile on sight. TIR-CMM is v0.2, authored by one person at UTIOM, with no institutional backing and no adoption claim of any kind. A board that has never heard of it will ask who publishes it, and the honest answer will not carry the same weight.

CSF is also better at what it was built for: one shared vocabulary across a whole organisation, in a Target Profile that survives reorganisation, procurement and audit. TIR-CMM produces a diagnostic, and a diagnostic is not a programme.

Use CSF 2.0 instead of TIR-CMM if you need a whole-programme view, a regulator-recognised artefact, a common language across IT, risk and the board, or a current-versus-target picture that covers governance, identify, protect and detect as well as respond. Running TIR-CMM in place of CSF would leave four and a half Functions unmeasured.

Where TIR-CMM is stronger

TIR-CMM is stronger on exactly one axis, and only within response: it produces a number that resists inflation. CSF supplies no scale for outcome achievement, so a Current Profile records whatever the assessor was willing to write down. TIR-CMM makes that impossible in four ways — the evidence ceiling of R3, the rehearsal ceiling R1 which holds every domain except RV to no more than RV + 1, the authority ceiling R2 which holds AO and CE to no more than RA + 1, and the assessment-depth ceiling R7 which caps a Pulse assessment at L3 and any self-assessment lacking independent calibration at L4.

Time is the second axis, and it has no CSF counterpart at all. Nothing in RS or RC measures duration. TIR-CMM's Containment Margin subtracts MTTD + MTTDecide + MTTC from a priority actor's breakout time, and the model refuses to award L4 or L5 without supplied tempo evidence. An organisation can satisfy all 13 RS Subcategories and still be structurally behind the adversary on every path, and CSF has no mechanism that would surface that.

Perishability is the third. TIR-CMM expires a proven lattice cell after 12 months, and immediately on EDR swap, SOAR migration, IdP change, on-call model change, departure of the named owner, material architecture change or a change of managed provider. A CSF Profile has no equivalent decay rule, so a Profile written eighteen months ago describes an organisation that no longer exists.

Can I use both?

Both together is the intended configuration, and TIR-CMM's own specification says so: CSF 2.0 is described in the crosswalk as the reporting layer above TIR-CMM, with TIR-CMM supplying the evidence that CSF Respond and Recover ask for. Nothing in TIR-CMM asks you to stop running CSF, and TIR-CMM deliberately anchors to NIST SP 800-61r3, which is itself a CSF 2.0 Community Profile.

If you already run CSF, here is where TIR-CMM slots in

Take your Current Profile and find the 13 RS Subcategories and the 8 RC Subcategories. For each one you have marked as achieved, TIR-CMM asks the follow-up question CSF leaves open: at what evidence level, at what depth, and proven when. Run a Baseline assessment — 1–2 hours, all 58 sub-capabilities, the lattice scoped to your crown jewels, the authority map and response tempo — and use the output as the "how or to what extent" text that CSF §3.1 requires but does not define.

Three handoffs work well. The lattice blind-cell count gives RS.MI-01 a defensible answer instead of a tick. MTTDecide gives RS.MA-04 and GV.RR a measured escalation latency rather than an org chart. And the seven constraints separate real Target Profile gaps from ceilings you have imposed on yourself — R1 usually reveals that the binding constraint is rehearsal, not tooling. TIR-CMM runs entirely in the browser and transmits nothing, so it can be run against a real Profile without a procurement conversation.

Which should you run?

If you have no framework at all, run CSF 2.0 first. A programme needs a whole-programme taxonomy before it needs a response diagnostic, and 22 Categories across 6 Functions will find larger gaps than 58 response sub-capabilities will.

If you already have a CSF Organizational Profile and your Respond outcomes are all marked achieved, run TIR-CMM. Marked-achieved is the condition TIR-CMM was built to interrogate, and the gap between engineered and proven is usually where the surprise lives.

If you are being asked by a regulator, insurer or board for evidence of programme maturity, run CSF 2.0 and do not substitute TIR-CMM. TIR-CMM has no certification, no accreditation and no standards body behind it, and presenting a v0.2 model from a single author as a compliance artefact will not survive scrutiny.

If your specific question is "could we actually stop it, and are we faster than the adversary," run TIR-CMM. CSF 2.0 does not answer that question, does not claim to, and no amount of Profile work will make it. Start with Pulse at 20 minutes if you want the shape of the answer, and Baseline at 1–2 hours if you want one you can defend. Both are free, and terms are in the glossary.