Changelog
Every release, and whether it was the model or the site that moved. A change to a level descriptor, a weight, a constraint or a scoping rule can move a score; a change to what the model records and reports moves the model version without moving the maturity arithmetic. Both are tagged model, and each entry says which.
Releases and the features each one added.
Two versions and a date
| Now | What it means | |
|---|---|---|
| Model | 1.6.0 | Domains, sub-capabilities, level descriptors, weights, constraints, scoping rules, and what the model records and reports. This is the number to cite. The assessment tool and the workbooks implement it and stamp it on your report — a tool has no version of its own, because it is an implementation of the model and nothing else. If it moved between two assessments, read the entry: maturity scores stay directly comparable when the scoring arithmetic did not change (as from 1.5.0 to 1.6.0), and are not directly comparable when a descriptor, a weight, a constraint or a scoping rule moved. |
| Documents | v1.6 | The white paper and the workbooks. They follow the model, not the site, so adding a page here never renames a document you have already downloaded or cited. |
| Site | updated 7 September 2026 | A date, not a version. Nobody cites a website, and it answers the only question worth asking: is this current? |
Superseded releases, with their three identifiers and the hashes of the documents they shipped, are kept in the release archive.
Every entry below is tagged [model] or [site]. Only a [model] entry can change a score, and each [model] entry states whether the maturity arithmetic moved — which is what decides whether an earlier result needs re-reading before you compare it.
Site update site — 2026-09-07
No change to the maturity model, its domains, sub-capabilities, weights, level descriptors, constraints C1–C5 or scoring arithmetic; no change to the saved-assessment format or the TIR-CMM export. The model stays 1.6.0 and the documents stay v1.6.
- Licence and permitted use, stated plainly. The licence page now lists what you may do without asking — assess your own organisation, assess clients for a fee, cite and quote with attribution, link to the project — and what needs written permission, such as republishing the model, publishing a derivative, embedding it in another product, or rebranding the tool. TID-CMM is free to use under those permissions; that is not an open-source licence and not a public-domain dedication. Model 1.5.0 and documents v1.4 keep the licence they were released under.
- How the score is calculated, in the open. Methodology → Scoring now shows the whole sequence in order, including the C5 ceiling that the previous list omitted, keeps VCS and SCS on their own branches, and adds a table of what each thing you record actually influences. On the results screen, “How your result was calculated” shows the same arithmetic for your own assessment, domain by domain, down to every weighted contribution and every binding constraint.
- Search works from a downloaded copy. The site search now runs from a local copy opened straight from disk as well as from the web, with keyboard, pointer and screen-reader support and visible loading and no-result states. Queries are matched in your browser and are not transmitted.
- The public project is easier to find. The model, documentation, datasets, citation file and community discussions are on GitHub, now linked from the footer, the developer pages and Resources. The assessment implementation and the build system are not published there.
- Word sources are no longer published. The white paper is published as a PDF. The editable Word files, current and historical, are kept by the author. The previous release stays available in the release archive as its PDF, workbooks and site capture, with checksums.
- Security and delivery. The site’s scripts and styles now load only from the site itself, with no inline stylesheet and no inline script, and the published policy was tightened to match. Production JavaScript and CSS are delivered in compact form.
- Improved guided assessment paths, technique-register focus and results hierarchy without changing the model or scoring.
- Improved guided-route navigation and added a non-scoring, one-change-at-a-time sensitivity view showing what could move the current result. The model and scoring are unchanged.
[1.6.0] model — 2026-09-06
Release. Model 1.6.0 · documents v1.6 · site updated 7 September 2026, aligned to MITRE ATT&CK Enterprise v19.2. 1.6.0 is a backward-compatible expansion of what an assessment records and reports.
What it adds
- Expanded crown-jewel scoping. Structured asset types beside the existing categories. Choosing one lifts the tactics an adversary must succeed at to reach that asset, names the telemetry families that would see it, and offers the scenario templates that fit it.
- Per-technique detection and validation evidence. A register recording, for each in-scope technique, whether a detection is deployed and enabled, whether the telemetry it requires is healthy, and whether it has been validated locally by a controlled adversarial method within a stated window. Evidence is named rather than asserted, and a validation outside the window expires.
- Multi-step scenarios and adversary timelines. Ordered chains to a crown jewel, with detection and validation recorded per step, correlation keys between steps, and the Scenario Coverage Score: a scenario counts as covered only when it is detected at two or more distinct stages, at least one of them validated locally.
- Known-threat assurance and unknown or emerging-threat readiness. Readiness for behaviour outside the threat model, read through sub-capabilities you have already answered and reported as a reading rather than a coverage percentage, with a methodology page on where an external evaluation result is admissible as evidence and where it is not.
- Correlation readiness. Cross-domain correlation and adversary-timeline reconstruction: what the capability needs as input, what it produces as evidence, and why five things commonly called a “path” are not interchangeable.
- Prevention and protection boundary. Where prevention and protection efficacy is assessed inside TID-CMM, and what crosses the line into TIR-CMM.
- Assurance-at-a-glance reporting. Evidence-based readings before the roadmap — technique assurance, technique assurance by stage, scenario status, unknown-threat readiness and the bottlenecks — with counts and denominators, and no percentage without one.
- Standards and UTIOM views, none of them scoring. Non-scoring views onto NIST CSF 2.0, SOC-CMM and ISO/IEC 27001 where a mapping has been reviewed, the UTIOM operating model, and a page setting out how TID-CMM relates to the frameworks and models around it. No level, mapping, score or percentage is invented in a view.
- Accessibility and presentation. The methodology diagrams can be enlarged and inspected at full size by pointer or keyboard; wide tables scroll inside their own container; the header and the forms hold together down to 320 pixels; and the results, roadmap and action plan carry the attribution line when printed.
Corrected state persistence, navigation, offline presentation and responsive-layout defects.
What did not change
The maturity arithmetic is the arithmetic of 1.5.0: the same eight domains and weights, the same 58 sub-capabilities and 348 level descriptors, and the same integrity constraints C1–C5 applied in the same order. For identical maturity responses the overall and domain maturity scores are numerically comparable with 1.5.0. The technique, scenario and readiness outputs are new, and are comparable only where those fields have been assessed.
Importing an assessment saved under 1.5.0
A file saved by the previous release imports without changing the answers it recorded: environment, crown jewels, adversaries, attack paths, telemetry coverage and capability scores are read exactly as saved, and the maturity score is the same. Asset types and the detection and scenario registers start empty, so the assurance sections are incomplete until they are assessed — nothing is invented on import. Saving after an import stamps the file 1.6.0. The saved-assessment format is unchanged, so nothing needs migrating.
Documents
White paper document 1.6, and the self-assessment and worked-example workbooks v1.6, identify model 1.6.0 and 6 September 2026 on their covers, running headers and document properties. The Northgate worked example computes 2.43 self-assessed (2.4336 before rounding) and 2.37 adjusted.
The previous release
Model 1.5.0, documents v1.4 and the site state of 20 August 2026 are preserved in the release archive with their SHA-256 hashes, as a download to run locally. That release is superseded and kept for historical use: reproducing a report written under it, checking an older citation, reading an earlier assessment.
Privacy and security wording
The privacy page no longer states more than can be shown. It sets out what can: the application code sets no cookies, carries no analytics, keeps no accounts and has no upload or submit path for assessment content; the browser holds the assessment and the theme preference in local storage, which is not attached to requests automatically; and Cloudflare, which serves and protects the site, processes ordinary request and security metadata and may set strictly necessary security cookies when those services are active. The Content-Security-Policy is described as a second line a reader can check rather than as a guarantee, and the security contact file carries the standard contact fields and nothing else.
TIR-CMM interoperability
TID-CMM 1.6.0 produces tid-cmm/export/1.0. TIR-CMM 1.0 can import the core handoff context it
recognises — the constrained detection score, the crown jewels with their asset classes, the
adversaries, and the stage and asset-class scope of the attack paths. The export retains additional TID-CMM
1.6 assessment detail, but the current TIR-CMM importer does not yet consume every extended field.
Known limitations
- The extended export fields — structured asset types, crown-jewel impact and rationale, actor identifiers, the per-technique register with its statuses, evidence and mitigations, scenario identity and technique membership, the constraint log, the domain results and the scope block — travel in the file but are not read by the current TIR-CMM importer. Scenario step order does not survive the handoff: a scenario's steps arrive as the set of stages it touches, not as a sequence.
- ISO/IEC 27001:2022 is referenced only where a mapping has been reviewed, currently TI.1 to A.5.7. A declared regulatory regime with no reviewed mapping is named as unmapped rather than scored against.
- Conformance vectors — complete assessments with the scores a conforming implementation must produce — are not published. The scoring specification is, and is complete enough to implement from.
- The framework and UTIOM views and the assurance readings are produced by the browser tool. The workbooks do not carry them.
- A technique with no ATT&CK analytic has no status: reach cannot be computed for it, which is not the same as being blind to it.
- Status 3 is a statement about a validation inside the stated window. Once the window passes, the same evidence counts as 2 until it is re-validated.
Site update site — 2026-08-20
- Using ATT&CK Evaluations as external evidence — a methodology page setting out
where an independent evaluation result is admissible in the model and where it is not. External evidence is advisory; local validation remains authoritative. No change to the model, the domains, the sub-capabilities, the weights or the constraints.
Corrected 2026-09-06: the page described here was not part of the 20 August 2026 production site. It first reaches the public site with model 1.6.0. The entry is left in place, dated as written, rather than deleted.
[1.5.0] model — 2026-08-20
- Workload and identity can now be more than one thing. Picking a single workload
dropped the others' techniques from your scope; picking a single identity provider hid the telemetry of the rest. Changes scores wherever more than one applies.
- AWS IAM and Identity Center, Google Workspace and Ping added as identity providers.
An AWS-native estate previously had to declare "other IdP" and was credited none of its CloudTrail telemetry.
- Regulated organisations are never placed on the essential profile, and the named
regime — DORA, NIS2, PCI-DSS and the rest — is recorded on the report.
- The tool now shows why your profile was derived, rather than only what it derived.
- The model, the documents and the site are versioned separately. Every release is
tagged so you can see at a glance whether a score is still comparable. The assessment tool now stamps the model version onto the report and the export — it has no version of its own, because it implements the model and nothing else.
[1.4.1] site — 2026-08-20
- Licence and copyright page.
[1.4.0] site — 2026-08-17
- Privacy page.
- Share links for LinkedIn, X and Reddit.
- Full icon set and web manifest.
[1.3.1] site — 2026-08-17
- Assessment depth as a first-class choice: rapid, structured and evidence-based.
- Filter and permalinks on the sub-capability register.
- Site search, matched in your browser.
[1.3.0] model — 2026-08-17
- Suggested threat profile: declare your sector and regions, and the tool ranks the
adversaries ATT&CK documents against organisations like yours.
- New Open Data dataset covering all 232 documented groups and campaigns.
- C5, the inherited intent ceiling. Changes scores where the suggested profile is
accepted without review.
[1.2.1] model — 2026-08-17
- Licensing stated as three things: Open Model and Open Data under CC BY 4.0, and the assessment tool free to use but not to redistribute. Corrected 2026-09-05: this entry originally also named “the reference engine under Apache-2.0”. No such engine is published, and the claim is withdrawn.
- The 2022 origin on the record.
- Slogan: Think smarter, Stay Secure.
- TIR-CMM published at tir-cmm.com.
[1.2.0] model — 2026-08-15
- Deception is now computed, not just scored: placement and operationalisation are
declared, and assurance credit follows from both.
[1.0.0] model — 2026-08-10
- First complete release: eight domains, 53 sub-capabilities. Corrected 2026-09-05: this entry originally said 58 sub-capabilities and 348 level descriptors; the repository changelog records 53 at 1.0.0, expanded to 58 (with C4) in 1.1.0 on 2026-08-12.
- Three integrity constraints, applied mechanically at scoring time (C4 followed in 1.1.0, C5 in 1.3.0).
- ATT&CK Validated Coverage Score.
- Browser assessment tool, Excel workbook and white paper. Corrected 2026-09-05: this entry originally also listed a “Python scoring engine”. No such engine is published, and the claim is withdrawn.
- Aligned to MITRE ATT&CK Enterprise v19.2 and crosswalked to NIST CSF 2.0 and SOC-CMM.