CTI-CMM is the community-driven, vendor-neutral maturity model for CTI programs — built by 30+ practitioners, aligned with the C2M2’s stakeholder domains, and use-case-driven rather than checkbox-driven. Version 1.2 spans 11 stakeholder domains with maturity levels CTI0 (pre-foundational) → CTI3 (leading).

We score ourselves against it publicly — including the low scores. A solo initiative claiming full maturity would be lying; showing the gaps is the point.

Self-assessment — 2026 (draft)

Domain (C2M2-aligned)ScoreHonest note
Threat & Vulnerability ManagementCTI2Core strength — Watch products + feeds exist for exactly this
Situational AwarenessCTI2Radar + landscape dashboard serve this directly
Information Sharing & CommunicationsCTI2MISP feeds, TLP discipline, open publication
Risk ManagementCTI1Sector-level claim data supports risk framing; no formal risk-register integration
Event & Incident ResponseCTI1IoC support only — we are explicitly not an IR function
Asset, Change & Configuration MgmtCTI0–1Readers’ asset context is theirs; we provide exposure signals only
Identity & Access ManagementCTI0Out of scope for a public program
Third-Party Risk ManagementCTI0–1Indirect via vendor-CVE coverage
Workforce ManagementCTI1CCAP, events, PhishHuntMY develop the MY bench
Cybersecurity ArchitectureCTI0–1Guides (segmentation, MISP deployment) touch this
Program ManagementCTI1This very page + published PIR/GIR are the evidence

Using Rectifyq to raise your maturity

Free resources mapped to practice areas — evidence you can cite in your own assessment:

If you adopt…It supports practices around…
MISP-ICS-OT feedsExternal intelligence sources, structured ingestion
Published PIR mappingRequirements definition & stakeholder alignment
Radar briefingsDissemination to leadership, situational awareness
Deployment guidesTooling & platform capability
Breach Watch sector dataRisk framing with local evidence

Changelog

DateChange
2026First public self-assessment (draft)