What counts as evidence
A score of 4 or 5 requires a named artefact recorded against it. Without one the score is counted as 3. This is constraint C3, and it is the rule most likely to change your headline number.
The test
An artefact qualifies if someone who was not in the assessment could ask for it by name and be handed it. That is the whole test.
Evidence produced somewhere else — an independent product evaluation, for instance — is admissible in some parts of the model and not others. Where ATT&CK Evaluations evidence lands, and where it stops.
Qualifies
- A dated report, ticket, dashboard, repository path or configuration export
- A purple-team result naming the technique and the observed detection
- A coverage metric with the query that produces it
- A runbook with a revision history
Does not qualify
- “We do this” without a location
- A tool being licensed, as distinct from configured and in use
- A policy stating that something should happen
- An individual's recollection, however senior
The rule is not about distrust. It is about what happens over time. In any process where an unevidenced claim scores the same as an evidenced one, the unevidenced claim is cheaper, so assertion gradually drives out evidence — and nobody notices until the assessment is tested by something real.
Evidence is defined per sub-capability
Every sub-capability names the evidence that substantiates a claim, so the requirement is specific rather than generic. One example from each domain:
| ID | Sub-capability | Example evidence |
|---|---|---|
TI.1 | Intelligence requirements and PIRs | Signed PIR/SIR register with named decision owners |
TM.1 | Asset, identity and crown-jewel identification | Crown-jewel register with business impact statements |
DC.1 | Log source inventory and ownership | Log source inventory with owners, coverage % and data-component mapping |
DE.1 | Detection lifecycle and intake | Documented lifecycle with stage gates |
AV.1 | Atomic testing and control verification | Test library mapped to sub-technique IDs |
AA.1 | Triage enrichment and context automation | Enrichment specification per detection class |
IR.1 | Response plan, playbooks and readiness | Scenario playbook set traced to threat profile |
GV.1 | Strategy, mandate and funding | Signed multi-year strategy with target maturity per domain |
All 58 sub-capabilities with their evidence criteria.
Recording it
The assessment tool and the workbook both carry an evidence field beside every score, and both flag an unevidenced 4 or 5 as a challenge before it reaches the result. Strict mode is on by default; turning it off shows the raw self-assessment and should never be reported externally.
The same rule reaches the per-technique detection register: a deployed detection without a named artefact is status 1, not 2, and a validation without a date inside the window, a method and a fired outcome is not a 3. A scenario step counts as validated only against a dated, named test. The artefact is the claim; the fields exist so it can be named.
Two kinds that are easy to get wrong
Evidence of readiness for behaviour outside the threat model is not a coverage figure and must not be recorded as one; the artefacts that qualify are listed on Known-Threat Assurance and Unknown-Threat Readiness. Evidence for correlation and timeline reconstruction is the output itself — a correlated incident, an ordered timeline with sources on every relationship, marked blind periods — and the correlation page lists what an assessor should be able to open.
Common questions
- What counts as evidence in a TID-CMM assessment?
- An artefact qualifies as evidence if someone outside the assessment could ask for it by name and be handed it — a dated report, ticket, dashboard, repository path, configuration export, purple-team result or coverage query. A policy, a licensed tool, or an individual's recollection does not qualify. Scores of 4 or 5 without a named artefact are counted as 3.