Frequently asked questions · v0.2

Frequently asked questions

TIR-CMM is the Threat-Informed Response Capability Maturity Model, a free model that measures whether an organisation can act on the attacks it detects. This page answers the questions people ask most often about what TIR-CMM is, how it relates to the frameworks you already run, what an assessment involves, and what you are permitted to do with it.

The basics

What is TIR-CMM?

TIR-CMM is a free capability maturity model that measures whether an organisation can act on the attacks it detects. TIR-CMM scores eight domains and 58 sub-capabilities, scores a Containment Lattice of eight attack-path stages crossed with eight asset classes, and applies seven integrity constraints that can only lower a result. The output is a maturity band from L0 to L5, a Validated Response Score, a Containment Margin measured against adversary breakout time, and a ranked roadmap.

What does TIR-CMM stand for?

TIR-CMM stands for Threat-Informed Response Capability Maturity Model. The word threat-informed means that response capability is measured against modelled attack paths, named crown jewels and prioritised adversaries, rather than against a generic checklist.

Who created TIR-CMM?

TIR-CMM was created by Reza Adineh at Minimal Cyber. Reza Adineh is also the author of UTIOM, the Unified Threat-Informed Operations Model, and of TID-CMM, the Threat-Informed Detection Capability Maturity Model. TIR-CMM is the response module of the first and the companion to the second.

Is TIR-CMM free?

TIR-CMM is free to use, including commercially, with no fee and no permission required. There is nothing to buy, nothing to install and no account to create. Consultancies may run TIR-CMM assessments for paying clients on the same terms as an internal team running it on itself.

Is TIR-CMM open source?

No — TIR-CMM is free to use but it is not an open-source project, and the difference matters. The model is licensed under CC BY-ND 4.0, which permits use, sharing, quotation and publication of your results but not derivative models. The tooling is source-available rather than open source: you may read, audit, run and self-host it, but not redistribute modified versions of it. The JSON Schemas and machine-readable model exports are the exception and are released under CC BY 4.0 so that integrations can be built freely.

Why does TIR-CMM forbid derivative models?

TIR-CMM forbids derivative models because a maturity score is only useful if it means the same thing everywhere. The integrity constraints exist specifically to stop an organisation flattering itself, and a fork that quietly removed the rehearsal ceiling or the evidence cap would still be called TIR-CMM, would produce a friendlier number, and would make every honest assessment less credible by comparison. Tailoring weightings for private internal use, mapping the model into your own GRC schema and building tooling against the schemas are all permitted.

Is TIR-CMM a certification?

No — TIR-CMM is not a certification, an audit standard or a regulatory approval, and no TIR-CMM result is issued, validated or endorsed by anyone. TIR-CMM is a practitioner model provided as-is, without warranty. A TIR-CMM assessment is evidence you produce about yourself, and the Assurance tier exists precisely because a self-assessment nobody challenged is not assurance.

What version is TIR-CMM at?

TIR-CMM is at version 0.2, published as a draft for review and challenge. Version 0.2 introduced the three assessment tiers, added the Prevent & Harden stage to the Containment Lattice, and made standalone use without TID-CMM the default. Several design questions remain deliberately open, and an organisation that ran the model and found a constraint miscalibrated is the most valuable feedback there is.

TIR-CMM and the other models

Do I need TID-CMM to use TIR-CMM?

No — TIR-CMM can be used standalone, and the assessment tool defaults to standalone. Eight short questions on detection and threat modelling replace a TID-CMM import, and a standalone assessment can reach band L4. Supplying no detection input at all caps the band at L3, and importing a real TID-CMM export lifts the ceiling to L5.

What is the difference between TID-CMM and TIR-CMM?

TID-CMM measures detection and answers would we see it?, while TIR-CMM measures response and answers could we stop it? TID-CMM scores coverage against in-scope ATT&CK techniques and produces a Validated Coverage Score. TIR-CMM scores the ability to decide, contain, evict and restore, and produces a Validated Response Score and a Containment Margin. TIR-CMM contains no detection domain at all and consumes detection maturity as an input constraint, which is what keeps the two models complementary rather than overlapping.

What is UTIOM?

UTIOM is the Unified Threat-Informed Operations Model, the parent operating model that TIR-CMM belongs to, published at utiom.de. UTIOM organises security operations into three pillars — leadership and governance, engineering and enablement, and operations and analysis. TID-CMM measures the engineering pillar and TIR-CMM measures the operations pillar, and both export upward into the UTIOM improvement roadmap.

How does TIR-CMM relate to NIST CSF 2.0 and SP 800-61r3?

TIR-CMM crosswalks to NIST CSF 2.0 at domain level and follows NIST SP 800-61r3 rather than r2. Revision 3, published in April 2025 as a CSF 2.0 Community Profile, deliberately abandons the linear four-phase incident lifecycle in favour of CSF 2.0 functions, and TIR-CMM is built on that structure. NIST supplies the governance vocabulary; TIR-CMM supplies the measurement layer NIST does not provide — whether the capability is proven, authorised and faster than the adversary.

How does TIR-CMM relate to MITRE ATT&CK and D3FEND?

TIR-CMM uses ATT&CK tactics to define the attack-path stages of the Containment Lattice and D3FEND to supply the countermeasure vocabulary for containment, eviction and restoration. The eight lattice stages collapse ATT&CK tactics into the boundaries at which a different response decision becomes available, because response does not vary meaningfully per technique — a compromised laptop is isolated the same way whichever technique got in. MITRE ATT&CK and D3FEND are trademarks of The MITRE Corporation, and these references indicate alignment, not endorsement.

How does TIR-CMM relate to SOC-CMM?

SOC-CMM measures the maturity of a security operations centre as a function, while TIR-CMM measures an organisation’s capacity to act on an attack, of which the SOC is one component and frequently not the binding one. The two are complementary and TIR-CMM crosswalks to SOC-CMM at domain level. The domains where SOC-CMM has no counterpart are the interesting ones: no crosswalk partner covers response authority, and only SOC-CMM and the regulatory frameworks reach validation at all.

Does TIR-CMM help with DORA or NIS2?

Yes — TIR-CMM produces exactly the kind of evidence DORA and NIS2 testing obligations ask for, although it is not a compliance tool and no regulator recognises it. The validation domain maps to DORA threat-led penetration testing and NIS2 testing requirements, the governance domain maps to reporting clocks, and the containment domain maps to ICT continuity and backup expectations. A TIR-CMM result demonstrates that response capability has been tested rather than documented, which is the distinction both regimes turn on.

Running an assessment

How long does a TIR-CMM assessment take?

A TIR-CMM assessment takes twenty minutes, one to two hours, or two to four weeks, depending on which of the three tiers you run. Pulse is twenty questions in twenty minutes and caps at band L3. Baseline covers all 58 sub-capabilities, the Containment Lattice and response tempo in one to two hours, and caps at L4. Assurance adds telemetry attributes, exercised scenarios and the governance layer over two to four weeks, with no band ceiling.

Which tier should I run first?

Run Pulse first unless you already know your evidence is strong. Each tier is a strict superset of the one below, every answer carries forward, and nothing is ever rescored, so starting shallow costs nothing. A tier’s band ceiling is not a punishment: the depth an assessment reaches is itself evidence about how far its result can be trusted.

Does my data leave my browser?

No — no assessment data ever leaves your browser. The TIR-CMM assessment tool runs entirely client-side, with no server calls, no analytics and no transmission of anything you type. The source is deliberately readable so that you can verify this claim yourself rather than take it on trust, and you can export your progress to a file you control.

Can I self-host TIR-CMM?

Yes — you may download and self-host the TIR-CMM assessment tool within your own organisation, including on an air-gapped network. A single-file standalone build exists for exactly this purpose, and a reference scoring server is provided for platforms that need REST. Self-hosting is permitted for internal use; redistributing the tooling as your own product or service is not.

Is there a TIR-CMM API?

There is no hosted TIR-CMM API, and that is deliberate. The assessment tool’s strongest property is that nothing you type ever leaves your machine, and that property is only credible if there is no server to send it to. A dependency-free reference scoring server is published for you to run yourself, exposing the model, the constraints, the tiers, the scenarios and endpoints to score an assessment and generate a report — inside your own network, on your own infrastructure.

Can I use TIR-CMM for client work?

Yes — you may run TIR-CMM assessments for clients and charge for them, with no fee and no permission required. Attribution is the only condition: credit TIR-CMM, name the version, and link to the canonical source. The assessment output belongs to the organisation assessed, and the Assurance tier is explicitly designed as a facilitated engagement with an assessment lead, business owners and an independent validator.

What do I need to have ready before I start?

You need a crown-jewel list, some idea of which adversaries target you, and whatever timing data your case system holds. A TID-CMM export is useful but optional, and it pre-fills crown jewels, attack paths, priority actors and the detection score. If you cannot separate decision latency from containment time in your own data, that is not a blocker — it is your first finding.

How do I cite TIR-CMM?

Cite TIR-CMM as: TIR-CMM v0.2 — Threat-Informed Response Capability Maturity Model, Reza Adineh, https://tir-cmm.com. Attribution requires crediting TIR-CMM, naming the version and linking to the canonical source, and it is the single condition attached to using the model.

How the model works

What is the Containment Lattice?

The Containment Lattice is the atomic scoring unit of TIR-CMM: a grid of eight attack-path stages crossed with eight asset classes, in which each in-scope cell is scored 0 to 3 for response readiness. The full lattice is 64 cells and is deliberately never the working set — a typical scoped lattice is 24 to 38 cells, because a cell counts only where the asset class exists in the environment and a modelled attack path traverses that stage on it. The lattice exists because response varies by where on the attack path you are and what kind of asset you are acting on, not by which ATT&CK technique the adversary used.

What is MTTDecide, and why measure it separately from MTTR?

MTTDecide is the mean time from a validated alert to an authorised containment decision, and TIR-CMM measures it separately because every other maturity model folds it into MTTR, where it disappears. Separating decision latency exposes the most common and most fixable failure in incident response: the organisation is not slow at containing, it is slow at being allowed to contain. Organisations that measure MTTDecide routinely discover it exceeds containment execution time by an order of magnitude, and the fix is usually a pre-authorisation decision rather than a purchase.

What is breakout time?

Breakout time is the interval between an adversary establishing an initial foothold and moving laterally to a second system, and it is the clock every response capability is racing. TIR-CMM uses breakout time as the denominator of the Tempo Ratio and the baseline of the Containment Margin, taken from threat intelligence for your priority actors, or from published industry figures with an explicit estimated flag where actor-specific intelligence is unavailable. A band L4 claim is never permitted on estimated tempo.

What is the Containment Margin?

Containment Margin is breakout time minus the sum of mean time to detect, mean time to decide and mean time to contain, expressed in minutes and signed. A positive Containment Margin means containment lands before the adversary spreads; a negative margin means you are containing a spread intrusion rather than a foothold. Containment Margin is the metric unique to response, because detection maturity is a coverage problem and response maturity is a race.

What is the Validated Response Score?

The Validated Response Score, or VRS, is the proportion of achievable response readiness actually demonstrated across the in-scope Containment Lattice, weighted by cell criticality. Crown-jewel cells carry a weight of 3, cells on a modelled path to a crown jewel carry 2, and peripheral cells carry 1, so the reported figure reflects readiness where it matters rather than readiness on average. VRS is reported alongside the engineered rate and the proven rate, and the gap between those two is usually the finding that lands.

What are the integrity constraints?

The integrity constraints are seven rules applied mechanically at scoring time that cap a TIR-CMM result where a claim is not safe to make. R1 caps every domain at the validation score plus one. R2 caps authority-dependent domains at the authority score plus one. R3 caps every score at the strength of its evidence. R4 caps response domains at the detection score plus one. R5 caps the band where response is slower than the adversary. R6 caps the band where a crown-jewel cell has no response option at all. R7 caps the band by assessment depth and governance.

Why can constraints only lower my score?

Constraints only lower a score because every one of them encodes a claim that has already been made and cannot be substantiated. A constraint firing is not a penalty added to an honest result — it is the removal of credit that the underlying evidence never supported. Allowing a constraint to raise a score would mean rewarding an organisation for a strength in one domain that does nothing to make an unrehearsed, unauthorised or unseen capability work at three in the morning.

What is a blind cell?

A blind cell is a Containment Lattice cell scored at status 0 — no response option exists at all — that sits on a modelled path to a crown jewel. A blind cell means there is a point on an attack path to something that must not fail where you would improvise or watch. Any Tier-1 blind cell caps the whole assessment at band L2 under constraint R6, because an organisation with no option at all on a crown jewel is not threat-informed, whatever the rest of the result says.

Why does proven status expire after twelve months?

Proven status expires after twelve months because response capability rests on people, tooling and authority, and organisations change those faster than they change detection logic. A cell also reverts from proven to engineered on any tooling change, any change to the on-call or escalation model, any reorganisation of the response function or departure of the named owner, any material architecture change affecting that asset class, and any change of managed provider or retainer. Response maturity is perishable in a way detection maturity is not.

Can I reach L5?

You can reach L5, but almost nobody should expect to, and any L5 claim deserves scepticism unless the evidence is exceptional. Band L5 requires that response adapts as the threat model changes, with playbook and authority coverage regenerating from threat change without a project. Reaching L5 also requires an Assurance-tier assessment, an audited detection input rather than a self-declared one, and sustained repeatable validation evidence — the constraints make an accidental L5 impossible. L3, threat-informed, is the realistic target for most organisations.

What is the most common result?

L2, Repeatable, is the most common band, and it is the band where response spending most exceeds response capability. An L2 organisation has playbooks and tooling in place and executes them consistently for known scenarios, but has never proved any of it under time pressure. The typical shape of an L2 result is a healthy engineered rate across the lattice beside a proven rate in low single figures.

Can I score well by writing better documentation?

No — documentation alone caps a TIR-CMM score at 2 out of 5 under the evidence cap. An assertion caps at 1, a design or policy document caps at 2, implementation with a test result caps at 4, and only recent, repeatable, independently reviewable proof from the live environment permits 5. Raising an evidence level to lift a cap is explicitly listed as gaming: the cap is the finding.

Every term used on this page is defined on the glossary, and every figure comes from the machine-readable model. If a question you need answering is not here, the about page explains how to raise it.