TID-CMM Threat-Informed Detection Capability Maturity Model
HomeMethodologyEvidence requirements

What counts as evidence

A score of 4 or 5 requires a named artefact recorded against it. Without one the score is counted as 3. This is constraint C3, and it is the rule most likely to change your headline number.

The test

An artefact qualifies if someone who was not in the assessment could ask for it by name and be handed it. That is the whole test.

Qualifies

  • A dated report, ticket, dashboard, repository path or configuration export
  • A purple-team result naming the technique and the observed detection
  • A coverage metric with the query that produces it
  • A runbook with a revision history

Does not qualify

  • “We do this” without a location
  • A tool being licensed, as distinct from configured and in use
  • A policy stating that something should happen
  • An individual's recollection, however senior

The rule is not about distrust. It is about what happens over time. In any process where an unevidenced claim scores the same as an evidenced one, the unevidenced claim is cheaper, so assertion gradually drives out evidence — and nobody notices until the assessment is tested by something real.

Evidence is defined per sub-capability

Every sub-capability names the evidence that substantiates a claim, so the requirement is specific rather than generic. One example from each domain:

IDSub-capabilityExample evidence
TI.1Intelligence requirements and PIRsSigned PIR/SIR register with named decision owners
TM.1Asset, identity and crown-jewel identificationCrown-jewel register with business impact statements
DC.1Log source inventory and ownershipLog source inventory with owners, coverage % and data-component mapping
DE.1Detection lifecycle and intakeDocumented lifecycle with stage gates
AV.1Atomic testing and control verificationTest library mapped to sub-technique IDs
AA.1Triage enrichment and context automationEnrichment specification per detection class
IR.1Response plan, playbooks and readinessScenario playbook set traced to threat profile
GV.1Strategy, mandate and fundingSigned multi-year strategy with target maturity per domain

All 58 sub-capabilities with their evidence criteria.

Recording it

The assessment tool and the workbook both carry an evidence field beside every score, and both flag an unevidenced 4 or 5 as a challenge before it reaches the result. Strict mode is on by default; turning it off shows the raw self-assessment and should never be reported externally.