Steps 11 and 12 — roadmap and plan
What to fix, ranked by what it unlocks, and a 30/60/90 plan naming owners and the artefact that proves each step is done.
What these steps produce
The roadmap ranks what to fix. The action plan turns it into something with dates, owners and an artefact that proves each step is done.
Ranked by what it unlocks
Prioritisation is mechanical — domain weight × sub-capability weight × gap — with one important addition: a domain that is capping others is promoted above its own weighted gap. If validation is holding six domains at 2, raising validation buys back their suppressed score as well as its own, and the roadmap says so in those terms.
Example. With validation at 1, the roadmap leads with adversarial emulation and states plainly: AV is capping other domains; raising it releases 1.72 of weighted score already earned elsewhere.
The 30/60/90 plan
Three horizons, each item naming what to do, who owns it, and the artefact that would prove it done — which is the same artefact the evidence rule will ask for at the next assessment. Telemetry fixes appear here too when a material share of your scope is blind.
Detection and validation gaps
A third card reads the detection register for Tier A: techniques not assessed first, because that is the cheapest thing to fix and the one most often mistaken for coverage, then those not observable, visible only, evidenced but unvalidated, and evidenced with a validation outside the window. Each row says what removes it. Capability rows carry the references of any standard in the lens, and telemetry rows name the declared crown jewel whose telemetry family includes the source.
Where the work continues
A compact UTIOM view closes the roadmap. It sorts the same ranked findings by where the work continues and adds no priority and changes no order: TID-CMM keeps threat scope, visibility, detection engineering, validation, correlation and detection-side improvement, and the section names the TI/TM, DC, DE, AV, AA, GV and IR rows the roadmap already ranks; TIR-CMM owns response authority, decision tempo, containment, recovery, crisis coordination and response rehearsal, none of which is ranked here, and the existing export hands it what it needs without proving response readiness; UTIOM is the operating context that connects the detection and response cycle. This is an operating-model interpretation of existing TID-CMM results. It is non-scoring and is not a formal crosswalk or compliance assessment.
Taking it away
Export the plan as CSV, the whole assessment as JSON, the coverage set as CSV, and the exposure detail as CSV for a risk register. Or print the results to PDF.