Comparison · updated 2026-08-20

TIR-CMM vs TID-CMM — detection maturity, response maturity and which one to run first

TID-CMM measures detection maturity — would you see it. TIR-CMM measures response maturity — could you stop it. Both are modules of UTIOM by the same author, not competitors, and TIR-CMM caps three of its eight domains at the detection score plus one. Most organisations should run TID-CMM first, because detection maturity is usually the binding constraint.

This is not a neutral comparison

Every other page in this cluster compares TIR-CMM with a framework published by somebody else. TID-CMM is not that. TID-CMM and TIR-CMM are siblings — the same author, Reza Adineh, the same parent model, the same scoring arithmetic, the same client-side tooling — and one was designed around a hole deliberately left in the other. Read this page as a design explanation, not an independent evaluation.

What is TID-CMM?

TID-CMM, the Threat-Informed Detection Capability Maturity Model published at tid-cmm.com, measures whether an organisation would actually observe an adversary. Version 1.1.0, released 12 August 2026, runs 8 domains and 58 sub-capabilities with weights summing to 100: Threat Intelligence & Adversary Prioritisation (TI, 12%, 6 sub-capabilities), Threat Modeling & Attack Path Analysis (TM, 12%, 7), Telemetry & Detection Coverage (DC, 14%, 6), Detection Engineering (DE, 16%, 10), Adversarial Validation & Emulation (AV, 14%, 8), Analytics, Automation & Hunting (AA, 12%, 8), Incident Response & Recovery (IR, 10%, 6) and Governance, Metrics & Continuous Improvement (GV, 10%, 7).

Scoring runs 0–5 with four integrity constraints, C1 to C4, applied mechanically at scoring time: a validation ceiling (no domain exceeds the validation domain plus one), a visibility ceiling (detection engineering cannot exceed telemetry coverage plus one), an evidence rule (scores of 4 or 5 without named artefacts count as 3) and an intent ceiling (telemetry and detection cannot exceed threat intelligence and threat modelling plus one). Coverage is graded per technique across four statuses — blind, telemetry-only, detection logic deployed, validated by emulation — each with a recency window. Two assessment modes are offered: a rapid self-assessment in half a day and a structured evidence-backed assessment over two weeks. Model content is CC BY 4.0, tooling Apache-2.0.

TID-CMM's headline finding is a gap. The TIR-CMM specification cites TID-CMM's published worked example, in which an organisation claiming 48.9% detection coverage can prove 12.7%.

What does TIR-CMM measure?

TIR-CMM measures whether an organisation can act on what detection surfaces: 8 domains, 58 sub-capabilities, weights summing to 100, scored 0–5 across six bands from L0 Improvised to L5 Adaptive. The domains are Response Preparation & Readiness (RP, 10%), Response Authority & Decision Rights (RA, 12%), Response Engineering & Playbooks (RE, 16%), Containment, Eradication & Recovery (CE, 14%), Automation & Orchestration (AO, 12%), Forensics, Evidence & Investigation (FI, 10%), Response Validation & Exercising (RV, 14%) and Response Governance, Metrics & Improvement (RG, 12%).

Structural symmetry with TID-CMM is deliberate. Both models carry 8 domains and 58 sub-capabilities, both score 0–5 and, per the TIR-CMM specification, both use identical band ranges so the two scores sit on one axis and the two radars superimpose. Where TID-CMM's atomic unit is an ATT&CK technique, TIR-CMM's is a lattice cell — one of 64 in the Containment Lattice, 8 attack-path stages by 8 asset classes, of which a typical scope is 24–38.

TIR-CMM contains no detection domain at all. Omitting one is the design decision that keeps the two models complementary instead of overlapping, and it is what keeps a combined assessment inside two hours.

Side by side

Axis TID-CMM v1.1.0 TIR-CMM v0.2
QuestionWould we actually see it?Could we actually stop it?
What it measuresDetection capability and coverageResponse capability, authority and tempo
UTIOM pillarEngineering & enablementOperations & analysis
Published12 August 202617 August 2026
Structure8 domains, 58 sub-capabilities, weights to 1008 domains, 58 sub-capabilities, weights to 100
Atomic unitATT&CK techniqueLattice cell — 8 stages × 8 asset classes = 64
Scale0–50–5, banded L0–L5
Constraints4 (C1–C4)7 (R1–R7)
Evidence handlingScores of 4–5 without named artefacts count as 3Graded ceiling: VC0 caps at 1, VC1 at 2, VC2 at 4, VC3 at 5
Validation expiry18 months12 months
Time measurementMTTDMTTDecide and MTTC, against adversary breakout time
Assessment depthsRapid self-assessment (half day); structured (two weeks)Pulse (20 min, caps L3); Baseline (1–2 h, caps L4); Assurance (2–4 weeks, no depth ceiling)
Cross-model dependencyConsumes a TIR-CMM score into its IR domain by substitutionConsumes the detection score as constraint R4
LicenceModel CC BY 4.0; tooling Apache-2.0Model CC BY-ND 4.0; schemas CC BY 4.0; tooling source-available
Cost, certificationFree, noneFree, none

Both are modules of UTIOM

UTIOM, the Unified Threat-Informed Operations Model published at utiom.de, is the foundation framework and methodology for security operations. UTIOM organises security operations into three pillars — leadership and governance, engineering and enablement, operations and analysis — and supplies the vision, strategy, crown jewels and unified improvement roadmap. UTIOM carries its own maturity and capability assessments, and it can be run without either module.

TID-CMM and TIR-CMM do not fill gaps in UTIOM — each adds measurement depth to a pillar UTIOM already defines. TID-CMM and RSMM, the Realistic SIEM Maturity Model covering ingestion, normalisation, correlation and search, sit under engineering and enablement. TIR-CMM sits under operations and analysis. UTIOM defines how security operations should work; a module tells you, with evidence, how well one part of it works in your organisation. You reach for a module when intent is no longer enough and you need proof.

Do they overlap?

Scope overlap between the two models is close to zero by construction, with one exception the specifications resolve explicitly. TID-CMM carries an Incident Response & Recovery domain at 10% weight and 6 sub-capabilities. Publishing a full response model alongside it would leave a user holding two contradictory response numbers, so TIR-CMM specification §11 defines a substitution rule rather than a reweighting: TID-CMM's IR domain narrows from "incident response and recovery" to the detection-to-response interface — alert-to-case fidelity, triage handoff quality, escalation path integrity, the feedback loop into detection tuning — and where a TIR-CMM assessment is imported, TID-CMM's IR score is replaced by the TIR-CMM overall score.

Circular inflation is ruled out by ordering. Substitution happens after TID-CMM's own constraints are computed, and TIR-CMM's constraint R4 consumes the pre-substitution detection score. Note one discrepancy worth stating plainly: the TIR-CMM specification describes this bridge as requiring a non-breaking TID-CMM version bump, and the version published at tid-cmm.com today is 1.1.0. The redefinition is specified, not yet shipped.

Constraint R4 — the hinge

R4 is where detection maturity converts into a hard limit on the response score:

`` RE ≤ D + 1 CE ≤ D + 1 FI ≤ D + 1 ``

You cannot respond to what you never saw. Response Engineering (16%), Containment, Eradication & Recovery (14%) and Forensics (10%) carry 40% of TIR-CMM's total weight between them, so a detection score of 1.5 holds two-fifths of the response model below 2.5 no matter how much response tooling has been bought — R4 is what stops an organisation buying its way to a high response score while remaining blind. Like every constraint in scoring and constraints, R4 only ever lowers a score.

Can you run TIR-CMM without TID-CMM?

Yes, and doing so is a supported path rather than a degraded one. TIR-CMM accepts the detection input D from three sources, each carrying a different band ceiling. An imported TID-CMM assessment carries no ceiling and leaves the assessment open to L5, because detection maturity has been independently evidenced. A built-in prerequisite check caps the band at L4. Supplying nothing at all caps the band at L3, and the report says so on its face.

TIR-CMM's built-in check is eight questions scored 0–5, of which at least six must be answered for the proxy to count. Five produce D: telemetry coverage of crown jewels, where detection content comes from, detection testing, identity and cloud detection coverage and alert quality reaching a responder. Three produce TM, governing confidence in lattice scoping: crown jewel definition, attack path modelling and adversary prioritisation. The L4 ceiling is not arbitrary — a self-assessment is enough to assess response up to validated maturity, but claiming adaptive response maturity on an unaudited detection claim is not credible. An organisation with no detection maturity model of any kind is a normal user of TIR-CMM, not a rejected one, and is precisely the organisation most exposed on response.

Where TID-CMM is stronger

TID-CMM measures what sits upstream of everything TIR-CMM measures, and it measures it more precisely. Detection coverage is quantifiable per ATT&CK technique against a named data source; response readiness is not decomposable that finely, which is why TIR-CMM's lattice collapses ATT&CK tactics into 8 stages — you isolate a compromised laptop the same way whether the adversary arrived via T1566 or T1190. An organisation with no detection at all never gets to have the response conversation.

TID-CMM also carries a more permissive licence. Model content is CC BY 4.0 against TIR-CMM's CC BY-ND 4.0, so TID-CMM's model text may be adapted and redistributed in modified form and TIR-CMM's may not. Its tooling is Apache-2.0 where TIR-CMM's is source-available. For an organisation intending to fork a model into an internal standard, that difference is decisive.

Use TID-CMM instead of TIR-CMM if your telemetry coverage of crown jewels is unknown, if your detection content comes from generic vendor subscriptions rather than a threat model, or if you have never tested a detection rule. TIR-CMM will simply report that R4 is binding and hand you a detection problem you could have measured directly.

Where TIR-CMM is stronger

TIR-CMM measures three things no detection model can reach. Authority is the first: constraint R2 caps Automation & Orchestration and Containment, Eradication & Recovery at the authority domain score plus one, because automation you are not permitted to fire is a demonstration rather than a capability. Tempo is the second: constraint R5 converts MTTD plus MTTDecide plus MTTC, divided by adversary breakout time, into a band ceiling — 2.0 or above caps at L1, 1.0 or above caps at L2, no tempo evidence caps at L3. MTTDecide, the interval between knowing and being authorised to act, is measured separately from MTTR here for the first time.

Perishability is the third. TID-CMM expires validation at 18 months; TIR-CMM expires at 12, and a cell also reverts from proven to engineered on an EDR swap, a SOAR migration, an IdP change, a change to the on-call model or the departure of a named owner. Response capability decays faster than detection logic because it rests on people and authority, and organisations change those more often than they change rules.

Can you use both?

Running both is the intended configuration, and the interface is a file rather than a workshop. TID-CMM exports crown jewels, modelled attack paths, priority actors with breakout times in minutes, in-scope ATT&CK techniques with their Mitigation M-codes and the pre-substitution detection score. TIR-CMM step 1 of 10 imports that export and the lattice then scopes itself: a cell is in scope only where the asset class exists and at least one modelled attack path traverses that stage on that asset class. Without an import, both conditions are declared by hand, and PM-2 records that difference in scope quality rather than hiding it.

Reciprocally, TIR-CMM's overall score substitutes into TID-CMM's IR domain and TIR-CMM's governance domain feeds lessons back into detection tuning: two assessments, two exports, one improvement roadmap at the UTIOM layer. Both run entirely in the browser and neither transmits assessment data anywhere.

Which should you run first?

Run TID-CMM first, in most cases. Three reasons, in order of weight. First, R4 caps 40% of TIR-CMM's model at the detection score plus one, and for most organisations detection maturity is the binding constraint — the response assessment will spend its findings telling you so. Second, without an imported detection score the defensible band ceiling is L4 with the eight-question check or L3 with nothing at all. Third, the TID-CMM export scopes the Containment Lattice automatically; running response first means declaring attack paths by hand and scoring your own scoping quality lower for it.

Run TIR-CMM first if you already know your detection is adequate and suspect your response is the problem. Where detection maturity is evidenced and sits above 3, R4 stops binding and the constraints that bite are R1 (rehearsal) and R2 (authority) — neither of which depends on TID-CMM in any way. Symptoms that point here: playbooks nobody has executed against a clock, containment actions that need an approval unavailable at 03:00, an MTTDecide that dwarfs your MTTC, or a mature disaster recovery programme that has never been exercised as an incident.

If you cannot decide, run a TIR-CMM Pulse first. Twenty questions, 20 minutes, no lattice and no evidence review, capped at L3 — enough to tell you whether the honest problem is detection or authority, at a cost low enough that being wrong does not matter. Start at the assessment tool, or read the model first if you would rather see the questions before answering them.