Comparison · updated 2026-08-20
TIR-CMM vs SIM3 — team maturity and response tempo are two different measurements
SIM3 is the Open CSIRT Foundation's maturity model for incident response teams: 45 parameters across Organisation, Human, Tools and Processes, each scored 0 to 4. TIR-CMM measures response capability against the adversary's clock, whoever owns it. SIM3 asks whether the function is governed; TIR-CMM asks whether you would win the race.
What is SIM3?
SIM3 — the Security Incident Management Maturity Model — is a maturity standard for CSIRTs, owned and published by the Open CSIRT Foundation. The current reference version is SIM3 v2 interim, dated 1 January 2023, authored by Don Stikvoort, Klaus-Peter Kossakowski and Mirosław Maj. Copyright on the standard runs to the Open CSIRT Foundation from 2016, with rights held earlier by S-CURE bv, PRESECURE Consulting GmbH and Fundacja Bezpieczna Cyberprzestrzeń from 2008. A full version 2 is stated by OCF as expected during 2026, extending the model beyond CSIRTs to ISACs, SOCs and PSIRTs.
SIM3's origin is the European CSIRT community rather than a standards body or a vendor. Trusted Introducer adopted SIM3 in May 2010 and established a certification scheme on it in September 2010; the standard records that over 200 European CSIRTs supported adoption through TF-CSIRT and Trusted Introducer. SIM3 is free for internal and not-for-profit use. Commercial audit work and any SIM3 training require prior permission from OCF, and OCF runs a certified auditor scheme.
The 45 parameters and the four quadrants
SIM3 organises into four parameter categories, which the standard calls quadrants. Enumerated from the SIM3 v2 interim full standard, they are:
| Quadrant | Parameters | Examples |
|---|---|---|
| O — Organisation | 11 (O-1 to O-11) | O-1 Mandate, O-2 Constituency, O-3 Authority, O-6 Public Media Policy |
| H — Human | 7 (H-1 to H-7) | H-1 Code of Conduct, H-2 Staff Resilience, H-5 Technical Training |
| T — Tools | 10 (T-1 to T-10) | T-4 Incident Tracking System, T-9 Incident Detection Toolset, T-10 Incident Resolution Toolset |
| P — Processes | 17 (P-1 to P-17) | P-1 Escalation to Governance Level, P-6 Incident Resolution Process, P-8 Audit & Feedback |
| Total | 45 |
O-6 Public Media Policy is new in v2 interim, which is why an assessment carried out against SIM3 v1 covers 44 parameters rather than 45.
The maturity scale
Every SIM3 parameter is scored on the same five-point scale, 0 to 4, and the labels are about formality of documentation and authority, not about performance:
| Level | Label |
|---|---|
| 0 | not available / undefined / unaware |
| 1 | implicit — known or considered but not written down |
| 2 | explicit, internal — written down but not formalised |
| 3 | explicit, formalised on authority of the CSIRT head or above |
| 4 | explicit, audited on authority of governance levels above the CSIRT head |
Read that scale carefully, because it tells you exactly what SIM3 is measuring. Level 4 is reached by being audited at a governance level above the team. Nothing on the scale refers to speed, outcome or effectiveness, and that is a design decision rather than an omission.
The baselines are where SIM3 gets its weight
SIM3 baselines are minimum required levels per parameter, published by the bodies that use them. OCF lists four: the Trusted Introducer certification baseline (2010), setting minimum levels for 44 of the 45 parameters, with recertification every 3 years; the ENISA baselines (2019) at Basic, Intermediate and Advanced, covering all 45, with a stricter Expert baseline added in 2024 as a consequence of the EU NIS2 Directive; the FIRST membership baseline (2023), covering 11 of the 45; and the CSIRTAmericas baseline (2024) from the Organization of American States, covering all 45. That is the reason SIM3 matters institutionally: FIRST, ENISA and the EU CSIRTs Network have all adopted SIM3 v2 interim, and Trusted Introducer certification runs on it.
What TIR-CMM measures
TIR-CMM measures whether an organisation can stop an intrusion inside the adversary's breakout window, with someone permitted to act, and prove it. The model holds 8 domains and 58 sub-capabilities, weights summing to 100, scored 0–5 against six bands from L0 Improvised to L5 Adaptive. Containment is assessed on a lattice of 8 attack-path stages × 8 asset classes = 64 cells, typically 24–38 in scope, each graded 0–3 for Response Readiness Status.
TIR-CMM's distinguishing measurement is MTTDecide — the interval between knowing and being authorised to act — scored separately from MTTR, on the claim that most of the loss sits in that interval and it is invisible inside MTTR. A Tempo Ratio of (MTTD + MTTDecide + MTTC) over breakout time drives constraint R5, which caps the band at L1 at a ratio of 2.0 and at L2 from 1.0. Seven integrity constraints (R1–R7) only ever lower a score. Evidence acts as a ceiling: VC0 caps a sub-capability at 1, VC1 at 2, VC2 at 4, VC3 at 5. Three depths are available — Pulse at 20 minutes capping at L3, Baseline at 1–2 hours capping at L4, Assurance at 2–4 weeks with no depth ceiling. Details are in the model and scoring and constraints.
Side by side
| Axis | SIM3 | TIR-CMM |
|---|---|---|
| Unit of assessment | A CSIRT, as an organisational unit | An organisation's response capability, wherever it lives |
| What it measures | Formality, documentation and governance of the function | Whether response is authorised, rehearsed and faster than the adversary |
| Structure | 4 quadrants, 45 parameters | 8 domains, 58 sub-capabilities, weights totalling 100 |
| Scale | 0–4, five levels, per parameter | 0–5 across six bands, L0 to L5, weighted to one score |
| Aggregate score | None by default — baselines set minimum levels parameter by parameter | Single weighted score plus a band, plus lattice coverage and tempo |
| Time dimension | None | Central: MTTD + MTTDecide + MTTC against breakout time |
| Evidence requirement | Formality of documentation and level of authority approving it | Four grades VC0–VC3 acting as caps of 1, 2, 4 and 5 |
| Downward-only constraints | None | 7 (R1–R7), which can only lower a result |
| Current version | v2 interim, 1 January 2023; full v2 expected during 2026 | v0.2, 17 August 2026 |
| Publisher | Open CSIRT Foundation, European CSIRT community origin | Reza Adineh, UTIOM |
| Certification | Yes — Trusted Introducer certification, recertified every 3 years, plus certified SIM3 auditors | None. No certification, no accreditation, no vendor |
| Cost | Free for internal and not-for-profit use; commercial audit and training need OCF permission | Free. Model CC BY-ND 4.0, schemas CC BY 4.0, tooling source-available |
| External adoption | ENISA (4 baselines), FIRST, EU CSIRTs Network, Trusted Introducer, OAS CSIRTAmericas | None claimed |
| Typical effort | Self-assessment via the SIM3 online tool, or a certified auditor engagement | 20 minutes to 4 weeks depending on depth |
| Output | Level per parameter, measured against a chosen baseline | Band, weighted score, lattice coverage, tempo ratio, ranked roadmap |
Do SIM3 and TIR-CMM overlap?
SIM3 and TIR-CMM overlap on roughly a quarter of their surface, and diverge sharply on the rest. Genuine overlaps exist: SIM3 O-3 Authority sits close to TIR-CMM's RA domain (Response Authority & Decision Rights, weighted 12%); T-10 Incident Resolution Toolset and P-6 Incident Resolution Process touch the CE and AO domains; P-8 Audit & Feedback Process corresponds to parts of RG (Response Governance, Metrics & Improvement, 12%); and O-8 Incident Classification maps into RP.
The divergence is larger in both directions. SIM3 covers ground TIR-CMM does not touch at all — O-2 Constituency, H-1 Code of Conduct, H-6 Soft Skills Training, P-13 Outreach, P-15 Constituency Reporting, P-17 Peer Collaboration and O-9 Participation in CSIRT Systems have no TIR-CMM counterpart, because TIR-CMM does not assess a team's standing in a community or its duty of care to a constituency. TIR-CMM in turn holds structures SIM3 has no place for: the 64-cell Containment Lattice scoped per asset class, the rehearsal ceiling R1 that holds every domain to at most one band above the validation domain, and the tempo measurement itself.
Where SIM3 is stronger
SIM3 is the more consequential model of the two, and pretending otherwise would be dishonest. SIM3 has been in continuous use since 2010, is owned by a foundation rather than an individual, has a certified auditor scheme, and carries external recognition TIR-CMM does not have and has not asked for: Trusted Introducer certification, FIRST membership assessment, four ENISA baselines including the NIS2-driven Expert level introduced in 2024, and the OAS CSIRTAmericas baseline. A SIM3 result is portable — another party recognises the number.
SIM3 also covers the human and organisational dimensions of an incident response function properly, where TIR-CMM covers them barely at all. Staff resilience, skillset description, technical and soft-skills training, code of conduct, constituency definition and peer collaboration are the substance of whether a team survives its third year, and TIR-CMM measures none of them. Use SIM3 instead of TIR-CMM if you are a CSIRT seeking Trusted Introducer certification, applying for FIRST membership, meeting an ENISA baseline as a national or sectoral team, or standing up a new team and needing to know what a complete function looks like. TIR-CMM will not help you with any of those, and it will not produce anything an external body accepts.
Where TIR-CMM is stronger
TIR-CMM measures against a clock and SIM3 does not. A SIM3 level 4 means a parameter is explicit and audited above the head of the CSIRT — a statement about the formality of the arrangement, not about how long it takes to execute. TIR-CMM's central figures are elapsed times: MTTDecide, MTTC and the ratio of their sum plus MTTD to the adversary's breakout window. A documented, formalised, audited escalation path that takes 40 minutes to reach a person authorised to isolate a domain controller at 03:00 scores well on SIM3 P-9 Emergency Reachability and is capped at L2 by TIR-CMM's tempo ceiling.
TIR-CMM also does not require you to have a CSIRT. UTIOM's premise is that response capability is an organisational property of which the incident response team is one component and frequently not the binding one — the binding constraint is often a business owner who must accept the impact of containment. An organisation running response through a managed provider, a platform team and an on-call rota with no formally constituted CSIRT is unassessable under a model whose unit is the CSIRT, and entirely assessable under TIR-CMM. The third difference is downward-only constraints: TIR-CMM's R1–R7 can lower a result and never raise it, and R6 caps the whole assessment at L2 on a single Tier-1 lattice cell where you have no containment option at all.
Can you run both, and can they disagree?
A team can score well on SIM3 and badly on TIR-CMM, and both results can be correct. That is not a flaw in either model — it is what happens when two instruments measure different properties. SIM3 asks whether you have documented, staffed and governed the function. TIR-CMM asks whether you would win the race. A mature, certified CSIRT with every process formalised at level 3 or 4 can still hold a Tempo Ratio above 1.0, an unexercised playbook set and a Tier-1 asset class it cannot contain — and TIR-CMM will return L2 for exactly those reasons while the SIM3 result stays valid.
The reverse is equally possible and equally correct. A small, fast, well-tooled team with pre-authorised containment and a live-fire exercise programme can land at TIR-CMM L3 or L4 while failing several SIM3 parameters outright, because it has never written down its mandate, has no service level description, publishes no constituency reporting and has no succession plan. A model that only measured tempo would call that team excellent. SIM3 correctly calls it fragile.
Run them in sequence rather than in parallel. SIM3 first if the function itself is immature or unrecognised, because a team that cannot describe its own mandate will not produce reliable answers to TIR-CMM's evidence questions. TIR-CMM second, once the function exists, to find out whether the documented capability survives contact with a clock. The two outputs sit together well in a board pack: SIM3 shows the function is properly constituted, TIR-CMM shows whether it is fast enough.
Which should you run?
If your unit of concern is a CSIRT and you need external recognition, run SIM3. SIM3 v2 interim, 45 parameters, levels 0–4, against whichever of the four published baselines applies to you. Nothing on this site substitutes for Trusted Introducer certification or an ENISA baseline, and TIR-CMM does not try to.
If your unit of concern is whether the organisation can stop an intrusion in time, run TIR-CMM — Pulse takes 20 minutes and caps at L3, Baseline takes 1–2 hours and caps at L4. Response authority, rehearsal evidence and tempo are the three things SIM3 does not grade, and they are the three that most often decide the outcome.
If you can only run one and you have no CSIRT at all, run SIM3. Building the function comes before timing it, and SIM3 is a far better description of what a complete function contains than TIR-CMM's 58 sub-capabilities will ever be. Come back to TIR-CMM when the plans exist, the tooling is in place, and the honest question has become whether any of it has ever met a clock.