CTI-CMM is the Cyber Threat Intelligence Capability Maturity Model: a free, vendor-neutral framework for measuring how well your threat intelligence programme supports the people who depend on it.
It scores your practices across 11 business domains at four maturity levels, CTI0 to CTI3, and gives you a prioritised path to improve.
Score yourself before you talk to us. Our assessment tool is free, needs no sign-up, and covers all 11 domains of CTI-CMM v1.3. Everything saves in your browser, so your answers never leave your machine.
We are volunteer contributors to CTI-CMM, and we built this tool.
Try the free assessment toolOnce you have a draft score, talk to us about an independent assessment.


Our CTI-CMM assessors Chris Horsley and Prescott Pym are volunteer contributors to the framework.
CTI-CMM organises your programme around 11 domains covering the business functions threat intelligence exists to support. Each has a purpose, the CTI mission that serves it, and the practices that mark each level of maturity.
Asset, Change and Configuration Management
Threat and Vulnerability Management
Risk Management
Identity and Access Management
Situational Awareness
Event and Incident Response, Continuity of Operations
Third-Party Risk Management
Fraud and Abuse Management
Workforce Management
Cybersecurity Architecture
Cybersecurity Program Management
We score each domain separately rather than handing you a single number. That shows you both halves of the picture: the domains where you are already strong and can prove it to your leadership, and the ones where the next level of maturity is within reach. Most programmes are uneven — that is normal, and it is what makes a roadmap specific to you rather than generic.
We run the scoring sessions with the stakeholders themselves, in their language (vulnerability management, third-party risk, incident response) not intelligence jargon.
“We need more feeds” is a hard ask. We give you the other version: you are at CTI1 for incident response, here is where comparable organisations sit, and here are the three practices that close the gap. An independent score carries weight a self-assessment does not.
We hand back a rating per domain and recommendations ordered by impact and effort, one maturity level at a time, in the domains that matter most to you. Not a list of everything that is imperfect.
Your first assessment with us is the reference point. When we re-run it, you can show your leadership whether the work they funded actually shifted anything.
Chris Horsley and Prescott Pym are among the volunteer contributors to the framework.
Open source, and tracking the current v1.3 model.
Cosive co-designed CTIS, Australia’s national threat intelligence sharing programme, serving 450+ organisations.
Multiple deployments across APAC, Europe and the Middle East.
Every engagement is staffed by senior consultants who have built and run CTI programmes themselves.
The University of Queensland engaged Cosive to assess its threat intelligence programme against CTI-CMM. We agreed on the methodology and the deliverables with the university’s team at the outset, and kept them involved throughout the assessment.
The report and its recommendations set out how the university could approach implementation in its own context, leaving the team with the confidence and clarity to progress its CTI roadmap.
“Cosive brought a high level of expertise and depth of knowledge to our engagement, and from the outset they were collaborative in developing the engagement methodology and deliverables. Throughout the engagement, we valued how transparent and engaged the team was, keeping us informed and involved throughout the process.
The cyber threat intelligence maturity assessment report and subsequent recommendations were practical and thoughtfully developed, going well beyond high-level suggestions to clearly outline how we could approach implementation in our context. This has given us strong confidence and clarity as we progress our CTI roadmap. The Cosive team was extremely professional, and we would strongly recommend them to organisations looking to mature their CTI capability in a considered and pragmatic way.”

We run assessment as a cycle rather than a one-off audit. The score is where the work starts, not where it ends. The value is in what you do with it, and in coming back to check whether it worked.
Chris Horsley and Prescott Pym are among the volunteer contributors to the framework.
We turn the gaps into a roadmap, built one maturity level at a time and sequenced by impact and effort. Your stakeholders help set the targets.
You execute the roadmap. We stay involved for the parts needing specialist help — requirements, tooling, integration, training — or step back.
Are you delivering measurable value, can you demonstrate it, what did not get done, and what support do you need from leadership to finish it.
Any organisation that has a threat intelligence function, or is about to build one. CTI-CMM measures how well intelligence supports the people who use it, not how much tooling you own, so it works for a team of one as well as a team of thirty.
Yes. We assess against CTI-CMM for threat intelligence programmes, SIM3 for CSIRT and incident-response maturity, and SOC-CMM for SOC-focused teams. We also map detection coverage against MITRE ATT&CK, and use VERIS where incidents need classifying and reporting consistently.
We recommend once you have had time to act on the last set of recommendations. For most programmes that is about every 12 months. CTI maturity assessment works best as a cycle, not a one-off audit.
Yes, and you should. Our CTI-CMM assessment tool is free, needs no sign-up, and covers all 11 domains of CTI-CMM v1.3. Once that’s completed you should get in touch to get a proper CTI-CMM assessment done, to confirm your own scoring and to learn what your next steps are.
Tell us about your programme and we’ll come back with a realistic scope for an assessment. A call is the quickest way to work out whether an assessment is the right move for your team.