TID-CMM Threat-Informed Detection Capability Maturity Model
HomeAssessment

The assessment

Ten screens in the tool, covering six methodological stages: derive your in-scope technique set from your environment, your adversaries and your attack paths, compute what your telemetry cannot see, score the capability, and produce a ranked plan.

Ten screens, six stages — why the two numbers differ. The stages below are the method. The tool splits one of them, threat scope, across four screens — crown jewels, threat actors, likely attacks and attack paths — because each needs its own decision and its own list, and asking for all four at once is how scoping gets skipped. Nothing is added or removed by the split; it is the same six stages, paced.

It runs entirely in your browser. No account, no email address, no server, no analytics, no network requests. Your assessment is saved to your own browser storage and never leaves the page — which is also why there is no endpoint that scores an assessment for you.

Start the assessment Read the guide first

The six stages

Environment

What you run, what you collect and how you work. Everything downstream is derived from this.

Threat scope

Crown jewels, threat actors, the techniques most likely to be used against you, and the attack paths that make a technique matter.

Telemetry

How much of your estate each log source actually covers, and what that makes structurally undetectable.

Capability

Scoring the sub-capabilities in your profile, with the evidence that substantiates each claim.

Results

The adjusted score, which constraints bound it, and which adversaries would walk through the gaps.

Roadmap

What to fix, ranked by what it unlocks, and a 30/60/90 plan naming owners and the artefact that proves each step is done.