TID-CMM Threat-Informed Detection Capability Maturity Model
HomeChangelog

Changelog

Every release, and whether it was the model or the site that moved. Only a change to a level descriptor, a weight, a constraint or a scoping rule can move a score — those are tagged model.

Releases and the features each one added.

Two versions and a date

NowWhat it means
Model1.5.0Domains, sub-capabilities, level descriptors, weights, constraints and scoping rules. This is the number to cite. The assessment tool and the Python engine both implement it, and both stamp it on your report — a tool has no version of its own, because it is an implementation of the model and nothing else. If it moved between two assessments, the scores are not directly comparable.
Documentsv1.4The white paper and the workbooks. They follow the model, not the site, so adding a page here never renames a document you have already downloaded or cited.
Siteupdated 20 August 2026A date, not a version. Nobody cites a website, and it answers the only question worth asking: is this current?

Every entry below is tagged [model] or [site]. Only a [model] entry can change a score, and only a [model] entry means last year's result needs re-reading before you compare it.

[1.5.0] model — 2026-08-20

dropped the others' techniques from your scope; picking a single identity provider hid the telemetry of the rest. Changes scores wherever more than one applies.

An AWS-native estate previously had to declare "other IdP" and was credited none of its CloudTrail telemetry.

regime — DORA, NIS2, PCI-DSS and the rest — is recorded on the report.

tagged so you can see at a glance whether a score is still comparable. The assessment tool now stamps the model version onto the report and the export — it has no version of its own, because it implements the model and nothing else.

[1.4.1] site — 2026-08-20

[1.4.0] site — 2026-08-17

[1.3.1] site — 2026-08-17

[1.3.0] model — 2026-08-17

adversaries ATT&CK documents against organisations like yours.

accepted without review.

[1.2.1] model — 2026-08-17

reference engine under Apache-2.0, and the assessment tool free to use but not to redistribute.

[1.2.0] model — 2026-08-15

declared, and assurance credit follows from both.

[1.0.0] model — 2026-08-10