TID-CMM Threat-Informed Detection Capability Maturity Model
Home › Methodology › Evidence requirements

What counts as evidence

A score of 4 or 5 requires a named artefact recorded against it. Without one the score is counted as 3. This is constraint C3, and it is the rule most likely to change your headline number.

The test

An artefact qualifies if someone who was not in the assessment could ask for it by name and be handed it. That is the whole test.

Evidence produced somewhere else — an independent product evaluation, for instance — is admissible in some parts of the model and not others. Where ATT&CK Evaluations evidence lands, and where it stops.

Qualifies

  • A dated report, ticket, dashboard, repository path or configuration export
  • A purple-team result naming the technique and the observed detection
  • A coverage metric with the query that produces it
  • A runbook with a revision history

Does not qualify

  • “We do this” without a location
  • A tool being licensed, as distinct from configured and in use
  • A policy stating that something should happen
  • An individual's recollection, however senior

The rule is not about distrust. It is about what happens over time. In any process where an unevidenced claim scores the same as an evidenced one, the unevidenced claim is cheaper, so assertion gradually drives out evidence — and nobody notices until the assessment is tested by something real.

Evidence is defined per sub-capability

Every sub-capability names the evidence that substantiates a claim, so the requirement is specific rather than generic. One example from each domain:

IDSub-capabilityExample evidence
TI.1Intelligence requirements and PIRsSigned PIR/SIR register with named decision owners
TM.1Asset, identity and crown-jewel identificationCrown-jewel register with business impact statements
DC.1Log source inventory and ownershipLog source inventory with owners, coverage % and data-component mapping
DE.1Detection lifecycle and intakeDocumented lifecycle with stage gates
AV.1Atomic testing and control verificationTest library mapped to sub-technique IDs
AA.1Triage enrichment and context automationEnrichment specification per detection class
IR.1Response plan, playbooks and readinessScenario playbook set traced to threat profile
GV.1Strategy, mandate and fundingSigned multi-year strategy with target maturity per domain

All 58 sub-capabilities with their evidence criteria.

Recording it

The assessment tool and the workbook both carry an evidence field beside every score, and both flag an unevidenced 4 or 5 as a challenge before it reaches the result. Strict mode is on by default; turning it off shows the raw self-assessment and should never be reported externally.

The same rule reaches the per-technique detection register: a deployed detection without a named artefact is status 1, not 2, and a validation without a date inside the window, a method and a fired outcome is not a 3. A scenario step counts as validated only against a dated, named test. The artefact is the claim; the fields exist so it can be named.

Two kinds that are easy to get wrong

Evidence of readiness for behaviour outside the threat model is not a coverage figure and must not be recorded as one; the artefacts that qualify are listed on Known-Threat Assurance and Unknown-Threat Readiness. Evidence for correlation and timeline reconstruction is the output itself — a correlated incident, an ordered timeline with sources on every relationship, marked blind periods — and the correlation page lists what an assessor should be able to open.

Common questions

What counts as evidence in a TID-CMM assessment?
An artefact qualifies as evidence if someone outside the assessment could ask for it by name and be handed it — a dated report, ticket, dashboard, repository path, configuration export, purple-team result or coverage query. A policy, a licensed tool, or an individual's recollection does not qualify. Scores of 4 or 5 without a named artefact are counted as 3.