CTI-CMM is the community-driven, vendor-neutral maturity model for CTI programs — built by 30+ practitioners, aligned with the C2M2’s stakeholder domains, and use-case-driven rather than checkbox-driven. Version 1.2 spans 11 stakeholder domains with maturity levels CTI0 (pre-foundational) → CTI3 (leading).
We score ourselves against it publicly — including the low scores. A solo initiative claiming full maturity would be lying; showing the gaps is the point.
Self-assessment — 2026 (draft)
| Domain (C2M2-aligned) | Score | Honest note |
|---|---|---|
| Threat & Vulnerability Management | CTI2 | Core strength — Watch products + feeds exist for exactly this |
| Situational Awareness | CTI2 | Radar + landscape dashboard serve this directly |
| Information Sharing & Communications | CTI2 | MISP feeds, TLP discipline, open publication |
| Risk Management | CTI1 | Sector-level claim data supports risk framing; no formal risk-register integration |
| Event & Incident Response | CTI1 | IoC support only — we are explicitly not an IR function |
| Asset, Change & Configuration Mgmt | CTI0–1 | Readers’ asset context is theirs; we provide exposure signals only |
| Identity & Access Management | CTI0 | Out of scope for a public program |
| Third-Party Risk Management | CTI0–1 | Indirect via vendor-CVE coverage |
| Workforce Management | CTI1 | CCAP, events, PhishHuntMY develop the MY bench |
| Cybersecurity Architecture | CTI0–1 | Guides (segmentation, MISP deployment) touch this |
| Program Management | CTI1 | This very page + published PIR/GIR are the evidence |
Using Rectifyq to raise your maturity
Free resources mapped to practice areas — evidence you can cite in your own assessment:
| If you adopt… | It supports practices around… |
|---|---|
| MISP-ICS-OT feeds | External intelligence sources, structured ingestion |
| Published PIR mapping | Requirements definition & stakeholder alignment |
| Radar briefings | Dissemination to leadership, situational awareness |
| Deployment guides | Tooling & platform capability |
| Breach Watch sector data | Risk framing with local evidence |
Changelog
| Date | Change |
|---|---|
| 2026 | First public self-assessment (draft) |