TID-CMM Threat-Informed Detection Capability Maturity Model
HomeAssessmentCapability

Step 7 — capability

Scoring the sub-capabilities in your profile, with the evidence that substantiates each claim.

What this step establishes

Score the sub-capabilities in your profile from 0 to 5 against explicit descriptors, and record the artefact that substantiates anything above 3. This is the only step that is genuinely a self-assessment, which is why it is the one the constraints police hardest.

Scoring what is true today

Score the present tense. Intent belongs in the target column, not the score, and a capability that is half rolled out is scored at what is actually running rather than at what the project plan says it will be.

The descriptors are written to make this easier: each level says what would have to be true, in terms concrete enough to check. If two levels both sound partly right, the lower one is correct — the higher level's requirements are cumulative.

Evidence, and why the rule exists

A score of 4 or 5 requires a named artefact. Without one the model counts it as 3. The test for whether something qualifies is simple: could someone who was not in the room ask for it by name and be handed it?

This is not about distrust. In any process where an unevidenced claim scores the same as an evidenced one, the unevidenced claim is cheaper, so assertion gradually drives out evidence — and nobody notices until the assessment is tested by something real.

How many you will be asked

The applicability profile is derived from what you declared in step 1, so the burden matches the estate rather than the ambition:

ProfileSub-capabilitiesTypical organisation
Essential22Small, no dedicated SOC, not regulated
Standard50Mid-sized with some dedicated detection capability
Comprehensive58Large, regulated, or an in-house SOC

You may choose a heavier or lighter profile than the one derived. The model records a challenge if the choice is implausible for what you declared, and the challenge appears in the result rather than being silently dropped.

What happens to these scores

They are weighted and rolled up, then the five constraints are applied in the order C3, C4, C2, C1. Both figures are reported — what you assessed, and what the model will stand behind. The gap between them is usually the most useful output of the whole exercise.

What counts as evidence · The five constraints · All 58 sub-capabilities

Start the assessment