TID-CMM Threat-Informed Detection Capability Maturity Model
Home › Changelog

Changelog

Every release, and whether it was the model or the site that moved. A change to a level descriptor, a weight, a constraint or a scoping rule can move a score; a change to what the model records and reports moves the model version without moving the maturity arithmetic. Both are tagged model, and each entry says which.

Releases and the features each one added.

Two versions and a date

NowWhat it means
Model1.6.0Domains, sub-capabilities, level descriptors, weights, constraints, scoping rules, and what the model records and reports. This is the number to cite. The assessment tool and the workbooks implement it and stamp it on your report — a tool has no version of its own, because it is an implementation of the model and nothing else. If it moved between two assessments, read the entry: maturity scores stay directly comparable when the scoring arithmetic did not change (as from 1.5.0 to 1.6.0), and are not directly comparable when a descriptor, a weight, a constraint or a scoping rule moved.
Documentsv1.6The white paper and the workbooks. They follow the model, not the site, so adding a page here never renames a document you have already downloaded or cited.
Siteupdated 7 September 2026A date, not a version. Nobody cites a website, and it answers the only question worth asking: is this current?

Superseded releases, with their three identifiers and the hashes of the documents they shipped, are kept in the release archive.

Every entry below is tagged [model] or [site]. Only a [model] entry can change a score, and each [model] entry states whether the maturity arithmetic moved — which is what decides whether an earlier result needs re-reading before you compare it.

Site update site — 2026-09-07

No change to the maturity model, its domains, sub-capabilities, weights, level descriptors, constraints C1–C5 or scoring arithmetic; no change to the saved-assessment format or the TIR-CMM export. The model stays 1.6.0 and the documents stay v1.6.

[1.6.0] model — 2026-09-06

Release. Model 1.6.0 · documents v1.6 · site updated 7 September 2026, aligned to MITRE ATT&CK Enterprise v19.2. 1.6.0 is a backward-compatible expansion of what an assessment records and reports.

What it adds

Corrected state persistence, navigation, offline presentation and responsive-layout defects.

What did not change

The maturity arithmetic is the arithmetic of 1.5.0: the same eight domains and weights, the same 58 sub-capabilities and 348 level descriptors, and the same integrity constraints C1–C5 applied in the same order. For identical maturity responses the overall and domain maturity scores are numerically comparable with 1.5.0. The technique, scenario and readiness outputs are new, and are comparable only where those fields have been assessed.

Importing an assessment saved under 1.5.0

A file saved by the previous release imports without changing the answers it recorded: environment, crown jewels, adversaries, attack paths, telemetry coverage and capability scores are read exactly as saved, and the maturity score is the same. Asset types and the detection and scenario registers start empty, so the assurance sections are incomplete until they are assessed — nothing is invented on import. Saving after an import stamps the file 1.6.0. The saved-assessment format is unchanged, so nothing needs migrating.

Documents

White paper document 1.6, and the self-assessment and worked-example workbooks v1.6, identify model 1.6.0 and 6 September 2026 on their covers, running headers and document properties. The Northgate worked example computes 2.43 self-assessed (2.4336 before rounding) and 2.37 adjusted.

The previous release

Model 1.5.0, documents v1.4 and the site state of 20 August 2026 are preserved in the release archive with their SHA-256 hashes, as a download to run locally. That release is superseded and kept for historical use: reproducing a report written under it, checking an older citation, reading an earlier assessment.

Privacy and security wording

The privacy page no longer states more than can be shown. It sets out what can: the application code sets no cookies, carries no analytics, keeps no accounts and has no upload or submit path for assessment content; the browser holds the assessment and the theme preference in local storage, which is not attached to requests automatically; and Cloudflare, which serves and protects the site, processes ordinary request and security metadata and may set strictly necessary security cookies when those services are active. The Content-Security-Policy is described as a second line a reader can check rather than as a guarantee, and the security contact file carries the standard contact fields and nothing else.

TIR-CMM interoperability

TID-CMM 1.6.0 produces tid-cmm/export/1.0. TIR-CMM 1.0 can import the core handoff context it recognises — the constrained detection score, the crown jewels with their asset classes, the adversaries, and the stage and asset-class scope of the attack paths. The export retains additional TID-CMM 1.6 assessment detail, but the current TIR-CMM importer does not yet consume every extended field.

Known limitations

Site update site — 2026-08-20

where an independent evaluation result is admissible in the model and where it is not. External evidence is advisory; local validation remains authoritative. No change to the model, the domains, the sub-capabilities, the weights or the constraints.

Corrected 2026-09-06: the page described here was not part of the 20 August 2026 production site. It first reaches the public site with model 1.6.0. The entry is left in place, dated as written, rather than deleted.

[1.5.0] model — 2026-08-20

dropped the others' techniques from your scope; picking a single identity provider hid the telemetry of the rest. Changes scores wherever more than one applies.

An AWS-native estate previously had to declare "other IdP" and was credited none of its CloudTrail telemetry.

regime — DORA, NIS2, PCI-DSS and the rest — is recorded on the report.

tagged so you can see at a glance whether a score is still comparable. The assessment tool now stamps the model version onto the report and the export — it has no version of its own, because it implements the model and nothing else.

[1.4.1] site — 2026-08-20

[1.4.0] site — 2026-08-17

[1.3.1] site — 2026-08-17

[1.3.0] model — 2026-08-17

adversaries ATT&CK documents against organisations like yours.

accepted without review.

[1.2.1] model — 2026-08-17

[1.2.0] model — 2026-08-15

declared, and assurance credit follows from both.

[1.0.0] model — 2026-08-10