ARMORARMOR

About

How it works

The two-axis model, design principles, and current validation status

The two-axis model

ARMOR evaluates offensive security maturity across two independent axes. An organization is assigned a coordinate position, for example T3/G2, representing its current state on the Technical Practice axis and the Governance and Integration axis independently.

T

Technical Practice

What offensive security activities are actually being executed, how sophisticated they are, and how consistently they are sustained.

How well do you practice the game?

G

Governance & Accountability

How well offensive security outcomes are owned, connected to business risk, and used to drive decisions across the organization.

How well does the organization act on what testing reveals?

The two-axis structure reflects how organizations actually develop: asymmetrically. A T4/G1 organization, technically capable but organizationally isolated, has a completely different problem than a T1/G4 organization, where governance has been built ahead of the testing program it depends on. A single average score cannot describe either honestly.

Design principles

Vendor-agnostic

ARMOR does not prescribe specific tools, platforms, or delivery mechanisms. The model evaluates whether activities are occurring and producing outcomes, not how they are staffed or tooled.

Self-administered

The model is designed for honest self-assessment. No external certification, no audit, no enforcement. The model delivers value in proportion to the honesty of the responses.

Sustainment before advancement

Organizations should not advance to the next level until all sustainment criteria for the current level are demonstrably met. Progress is only durable if the foundation holds.

Open and free

ARMOR is published under CC BY-NC-SA 4.0. It is free to use, share, and adapt for non-commercial purposes with appropriate credit. The model is not owned by any company and is not a sales funnel.

Validation and research status

ARMOR has not yet been validated against a large sample of real organizations. The scoring structure and level descriptors were developed through structured analysis of offensive security program patterns across organizations of varying sizes and maturity levels.

Empirical validation, comparing self-assessed coordinates to independent expert assessments, is planned for a future release. Organizations willing to participate in validation research can contact the author directly. Participation is anonymous and voluntary.

Planned work includes crosswalks to common frameworks, additional tabletop and implementation guidance, and deeper guidance for the T4/T5 and G4/G5 transitions.