CTI-CMM

The capability maturity model for threat intelligence. We run independent assessments against the model, and help you act on what they find.

Benchmark your threat intelligence programme against four maturity levels

CTI0
Pre-foundational

The practice isn’t happening yet.

CTI1
Foundational

Ad hoc and reactive. Work happens case by case, largely undocumented, delivering short-term value that is hard to measure.

CTI2
Advanced

Standardised and proactive. Practices are documented, repeatable and often automated, and you can show their impact.

CTI3
Leading

Prescriptive and business-aligned. Intelligence carries recommendations, and its metrics map to business outcomes.

How the model works
What our customers say about us
“The cyber threat intelligence maturity assessment report and subsequent recommendations were practical and thoughtfully developed, going well beyond high-level suggestions to clearly outline how we could approach implementation in our context.”
Sasenka Abeysooriya, Program Director
Read the case study
the framework

Why CTI-CMM

CTI-CMM is the Cyber Threat Intelligence Capability Maturity Model: a free, vendor-neutral framework for measuring how well your threat intelligence programme supports the people who depend on it.

It scores your practices across 11 business domains at four maturity levels, CTI0 to CTI3, and gives you a prioritised path to improve.

Test yourself

Score yourself before you talk to us. Our assessment tool is free, needs no sign-up, and covers all 11 domains of CTI-CMM v1.3. Everything saves in your browser, so your answers never leave your machine.

We are volunteer contributors to CTI-CMM, and we built this tool.

Try the free assessment tool

Once you have a draft score, talk to us about an independent assessment.

Nobody knows CTI-CMM better.

Our CTI-CMM assessors Chris Horsley and Prescott Pym are volunteer contributors to the framework.

how it works

Eleven domains

CTI-CMM organises your programme around 11 domains covering the business functions threat intelligence exists to support. Each has a purpose, the CTI mission that serves it, and the practices that mark each level of maturity.

01

Asset, Change and Configuration Management

02

Threat and Vulnerability Management

03

Risk Management

04

Identity and Access Management

05

Situational Awareness

06

Event and Incident Response, Continuity of Operations

07

Third-Party Risk Management

08

Fraud and Abuse Management

09

Workforce Management

10

Cybersecurity Architecture

11

Cybersecurity Program Management

Four maturity levels

We score each domain separately rather than handing you a single number. That shows you both halves of the picture: the domains where you are already strong and can prove it to your leadership, and the ones where the next level of maturity is within reach. Most programmes are uneven — that is normal, and it is what makes a roadmap specific to you rather than generic.

CTI0
Pre-foundational

The practice isn’t happening yet.

CTI1
Foundational

Ad hoc and reactive. Work happens case by case, largely undocumented, delivering short-term value that is hard to measure.

CTI2
Advanced

Standardised and proactive. Practices are documented, repeatable and often automated, and you can show their impact.

CTI3
Leading

Prescriptive and business-aligned. Intelligence carries recommendations, and its metrics map to business outcomes.

what you get

What an assessment gives you

01

A pulse-check with stakeholders

We run the scoring sessions with the stakeholders themselves, in their language (vulnerability management, third-party risk, incident response) not intelligence jargon.

02

A strong budget case

“We need more feeds” is a hard ask. We give you the other version: you are at CTI1 for incident response, here is where comparable organisations sit, and here are the three practices that close the gap. An independent score carries weight a self-assessment does not.

03

A prioritised roadmap

We hand back a rating per domain and recommendations ordered by impact and effort, one maturity level at a time, in the domains that matter most to you. Not a list of everything that is imperfect.

04

A baseline you can measure against

Your first assessment with us is the reference point. When we re-run it, you can show your leadership whether the work they funded actually shifted anything.

why cosive

We helped build the model we assess you against

Talk to us about an assessment
Cosive running cyber threat intelligence training at the AUSCERT conference.

We contribute to CTI-CMM

Chris Horsley and Prescott Pym are among the volunteer contributors to the framework.

We built the official online assessment tool

Open source, and tracking the current v1.3 model.

We run national-scale sharing

Cosive co-designed CTIS, Australia’s national threat intelligence sharing programme, serving 450+ organisations.

We deploy threat intelligence platforms worldwide

Multiple deployments across APAC, Europe and the Middle East.

We are practitioners, not just auditors

Every engagement is staffed by senior consultants who have built and run CTI programmes themselves.

case study

A CTI-CMM baseline the university could act on

The University of Queensland’s Walter Harrison Law Library.
client
The University of Queensland
sector
Higher Education
engagement
CTI-CMM maturity assessment
delivered
Assessment report and recommendations
the engagement

The University of Queensland engaged Cosive to assess its threat intelligence programme against CTI-CMM. We agreed on the methodology and the deliverables with the university’s team at the outset, and kept them involved throughout the assessment.

the outcome

The report and its recommendations set out how the university could approach implementation in its own context, leaving the team with the confidence and clarity to progress its CTI roadmap.

“Cosive brought a high level of expertise and depth of knowledge to our engagement, and from the outset they were collaborative in developing the engagement methodology and deliverables. Throughout the engagement, we valued how transparent and engaged the team was, keeping us informed and involved throughout the process.

The cyber threat intelligence maturity assessment report and subsequent recommendations were practical and thoughtfully developed, going well beyond high-level suggestions to clearly outline how we could approach implementation in our context. This has given us strong confidence and clarity as we progress our CTI roadmap. The Cosive team was extremely professional, and we would strongly recommend them to organisations looking to mature their CTI capability in a considered and pragmatic way.”

Sasenka Abeysooriya
The University of Queensland · Australia
our approach

How a CTI-CMM engagement works

We run assessment as a cycle rather than a one-off audit. The score is where the work starts, not where it ends. The value is in what you do with it, and in coming back to check whether it worked.

01

Assess

Chris Horsley and Prescott Pym are among the volunteer contributors to the framework.

02

Plan

We turn the gaps into a roadmap, built one maturity level at a time and sequenced by impact and effort. Your stakeholders help set the targets.

03

Deploy

You execute the roadmap. We stay involved for the parts needing specialist help — requirements, tooling, integration, training — or step back.

04

Measure

Are you delivering measurable value, can you demonstrate it, what did not get done, and what support do you need from leadership to finish it.

Then the cycle starts again from a higher baseline.
FAQ

Frequently asked questions

get in touch

Tell us about your programme and we’ll come back with a realistic scope for an assessment. A call is the quickest way to work out whether an assessment is the right move for your team.