What counts as evidence
A score of 4 or 5 requires a named artefact recorded against it. Without one the score is counted as 3. This is constraint C3, and it is the rule most likely to change your headline number.
The test
An artefact qualifies if someone who was not in the assessment could ask for it by name and be handed it. That is the whole test.
Qualifies
- A dated report, ticket, dashboard, repository path or configuration export
- A purple-team result naming the technique and the observed detection
- A coverage metric with the query that produces it
- A runbook with a revision history
Does not qualify
- “We do this” without a location
- A tool being licensed, as distinct from configured and in use
- A policy stating that something should happen
- An individual's recollection, however senior
The rule is not about distrust. It is about what happens over time. In any process where an unevidenced claim scores the same as an evidenced one, the unevidenced claim is cheaper, so assertion gradually drives out evidence — and nobody notices until the assessment is tested by something real.
Evidence is defined per sub-capability
Every sub-capability names the evidence that substantiates a claim, so the requirement is specific rather than generic. One example from each domain:
| ID | Sub-capability | Example evidence |
|---|---|---|
TI.1 | Intelligence requirements and PIRs | Signed PIR/SIR register with named decision owners |
TM.1 | Asset, identity and crown-jewel identification | Crown-jewel register with business impact statements |
DC.1 | Log source inventory and ownership | Log source inventory with owners, coverage % and data-component mapping |
DE.1 | Detection lifecycle and intake | Documented lifecycle with stage gates |
AV.1 | Atomic testing and control verification | Test library mapped to sub-technique IDs |
AA.1 | Triage enrichment and context automation | Enrichment specification per detection class |
IR.1 | Response plan, playbooks and readiness | Scenario playbook set traced to threat profile |
GV.1 | Strategy, mandate and funding | Signed multi-year strategy with target maturity per domain |
All 58 sub-capabilities with their evidence criteria.
Recording it
The assessment tool and the workbook both carry an evidence field beside every score, and both flag an unevidenced 4 or 5 as a challenge before it reaches the result. Strict mode is on by default; turning it off shows the raw self-assessment and should never be reported externally.