TID-CMM Threat-Informed Detection Capability Maturity Model
HomeModelMaturity levels

The 0–5 maturity scale

Six levels, from a capability that does not exist to one that corrects itself. The scale is deliberately shaped: the lower levels describe absence and habit, the upper levels describe practice that can be evidenced.

Level 0

Absent — The capability does not exist in any recognisable form.

Level 1

Ad hoc — Happens occasionally, driven by individual initiative or an incident. Undocumented, unrepeatable, lost when the individual leaves.

Level 2

Repeatable — Documented and consistently performed, but driven by compliance, tooling defaults or vendor content rather than by adversary behaviour.

Level 3

Threat-Informed — Driven by a prioritised adversary profile. Work is explicitly mapped to ATT&CK techniques and traceable back to an intelligence requirement or a threat model.

Level 4

Measured & Validated — Quantitatively managed and independently proven. Claims are tested by emulation, results are measured over time, and gaps enter a managed backlog.

Level 5

Adaptive — A self-correcting closed loop. Change in the threat landscape automatically produces changes in telemetry, detection and validation, with measured cycle time. The organisation contributes findings back to the community.

Maturity tiers and their entry gates

A weighted score alone does not buy a tier. Each tier has entry gates — specific sub-capabilities that must reach a minimum — so an organisation cannot average its way past a structural gap.

TierMinimum scoreEntry gates
Ad Hoc1.0DC.1 >= 1
Defined2.0DC.1 >= 2; TM.3 >= 2; DE.3 >= 2
Managed3.0TI.5 >= 3; TM.3 >= 3; TM.5 >= 3; DE.2 >= 3
Predictive4.0AV.1 >= 3; AV.3 >= 3; AA.5 >= 4; AA.7 >= 3
Optimized4.75AV.7 >= 4; GV.6 >= 4

Why level 5 is not a target

Level 5 describes a self-correcting loop that contributes back to the community. It is rare, and treating it as a target produces theatre. A defensible target for a well-resourced enterprise is 3.5 to 4.0 overall with validation at 4.0 or above, so that it stops being the binding constraint. For a smaller organisation, 2.5 to 3.0 over an honest, narrow in-scope set is a stronger position than 3.5 over a scope chosen to flatter.