The repository
The public TID-CMM project on GitHub carries the model definition, the documentation, the derived datasets, the citation file and the community discussions.
Explore the public TID-CMM model, documentation, data and community discussions on GitHub. The assessment implementation and build system are not published there.
Public model and community on GitHub
What is published
model/— the complete model definition and JSON Schemasdata/— the derived ATT&CK datasetsdocs/scoring-reference.md— the full scoring specification
Conformance vectors — complete assessments with the scores a conforming implementation must produce — are not yet published; they may accompany a future release. No scoring engine or package is published: the specification is complete enough to implement from.
What is not
The development repository, the build system and the maintainers’ source materials are not published. Because the assessment runs locally in your browser, the client-side implementation delivered to the browser is technically inspectable. That technical visibility does not grant permission to redistribute, rebrand or create derivative tooling.
The implementation is copyright © 2022–2026 Reza Adineh, all rights reserved. It is free to use under the permissions on the licence page, including commercial assessment work; it is not open-source licensed. The model, the datasets and the scoring specification are free to use on the same terms: republishing, adapting or embedding them needs written permission. See the licence page.
Why publish the specification but not the implementation. The model's central claim is that an assessment cannot flatter itself, because the constraints are applied mechanically rather than urged. That claim is only worth something if someone other than the author can check it — which the published specification allows, without the implementation.
Contributing
Descriptors, weights and crosswalks are open to challenge. The most useful contribution is not a correction but a counter-example: if a level descriptor does not match what you see in practice, say which sub-capability, which level, and what you actually observed.