Changelog
Every release, and whether it was the model or the site that moved. Only a change to a level descriptor, a weight, a constraint or a scoping rule can move a score — those are tagged model.
Releases and the features each one added.
Two versions and a date
| Now | What it means | |
|---|---|---|
| Model | 1.5.0 | Domains, sub-capabilities, level descriptors, weights, constraints and scoping rules. This is the number to cite. The assessment tool and the Python engine both implement it, and both stamp it on your report — a tool has no version of its own, because it is an implementation of the model and nothing else. If it moved between two assessments, the scores are not directly comparable. |
| Documents | v1.4 | The white paper and the workbooks. They follow the model, not the site, so adding a page here never renames a document you have already downloaded or cited. |
| Site | updated 20 August 2026 | A date, not a version. Nobody cites a website, and it answers the only question worth asking: is this current? |
Every entry below is tagged [model] or [site]. Only a [model] entry can change a score, and only a [model] entry means last year's result needs re-reading before you compare it.
[1.5.0] model — 2026-08-20
- Workload and identity can now be more than one thing. Picking a single workload
dropped the others' techniques from your scope; picking a single identity provider hid the telemetry of the rest. Changes scores wherever more than one applies.
- AWS IAM and Identity Center, Google Workspace and Ping added as identity providers.
An AWS-native estate previously had to declare "other IdP" and was credited none of its CloudTrail telemetry.
- Regulated organisations are never placed on the essential profile, and the named
regime — DORA, NIS2, PCI-DSS and the rest — is recorded on the report.
- The tool now shows why your profile was derived, rather than only what it derived.
- The model, the documents and the site are versioned separately. Every release is
tagged so you can see at a glance whether a score is still comparable. The assessment tool now stamps the model version onto the report and the export — it has no version of its own, because it implements the model and nothing else.
[1.4.1] site — 2026-08-20
- Licence and copyright page.
[1.4.0] site — 2026-08-17
- Privacy page.
- Share links for LinkedIn, X and Reddit.
- Full icon set and web manifest.
[1.3.1] site — 2026-08-17
- Assessment depth as a first-class choice: rapid, structured and evidence-based.
- Filter and permalinks on the sub-capability register.
- Site search, matched in your browser.
[1.3.0] model — 2026-08-17
- Suggested threat profile: declare your sector and regions, and the tool ranks the
adversaries ATT&CK documents against organisations like yours.
- New Open Data dataset covering all 232 documented groups and campaigns.
- C5, the inherited intent ceiling. Changes scores where the suggested profile is
accepted without review.
[1.2.1] model — 2026-08-17
- Licensing stated as three things: Open Model and Open Data under CC BY 4.0, the
reference engine under Apache-2.0, and the assessment tool free to use but not to redistribute.
- The 2022 origin on the record.
- Slogan: Think smarter, Stay Secure.
- TIR-CMM published at tir-cmm.com.
[1.2.0] model — 2026-08-15
- Deception is now computed, not just scored: placement and operationalisation are
declared, and assurance credit follows from both.
[1.0.0] model — 2026-08-10
- First complete release: eight domains, 58 sub-capabilities, 348 level descriptors.
- Three integrity constraints, applied mechanically at scoring time.
- ATT&CK Validated Coverage Score.
- Browser assessment tool, Excel workbook, white paper and Python scoring engine.
- Aligned to MITRE ATT&CK Enterprise v19.2 and crosswalked to NIST CSF 2.0 and SOC-CMM.