Blog Details Banner Image
Blog

The Gartner CTEM Framework and Lifecycle Explained

Date Icon
July 30, 2026
Category Icon
Category :

The Gartner CTEM Framework and Lifecycle Explained

The CTEM framework is a five stage lifecycle for reducing exploitable exposure continuously: scope, discover, prioritise, validate and mobilise. Gartner defined it as a repeating loop rather than a linear project, because exposure is a moving target. This guide covers each stage technically: what it does, the tooling categories involved, and what to measure


Why it is a loop, not a line

The five stages repeat. Mobilisation feeds back into scope because remediating one area, and discovering new assets, both change what matters in the next cycle. A one off assessment structured around these five headings is not CTEM. The continuous re-entry is the defining property. Each cycle should leave measurably less exploitable exposure within scope than the last.

  • Stage 1: Scope

Scoping defines the boundary of the cycle in business terms, not technical convenience. The primary technique is crown jewel analysis: identifying the assets, data stores, identities and third party connections whose compromise produces material impact. Scope also captures the threat context, which adversaries and techniques are relevant to the sector. Good scoping is narrow at first and expands as the program matures. Trying to scope the entire estate in cycle one produces noise, not focus. Measure: scope tied to documented business impact, agreed with asset owners, revisited each cycle.

  • Stage 2: Discover

Discovery enumerates assets and weaknesses within scope. It draws on multiple tooling categories:

EASM for internet facing assets, via passive DNS, certificate transparency, ASN enumeration and external scanning.

CAASM for internal asset correlation from cloud APIs, EDR, CMDB and identity providers

Vulnerability scanning for known CVEs

Cloud security posture for IaaS and PaaS misconfigurations.

Identity discovery for accounts, entitlements and over permissioned roles, an increasingly central part of the attack surface.

Measure: coverage as a proportion of the in scope estate under continuous discovery, and time to detect new or changed assets.

  • Stage 3: Prioritise

Prioritisation ranks discovered weaknesses by exploitation likelihood and consequence. Mature prioritisation blends:

CVSS for base severity.

EPSS for modelled exploitation probability.

CISA KEV and threat intelligence for confirmed active exploitation.

Reachability and attack path analysis for accessibility and chaining.

Business impact from scoping.

Findings are mapped to adversary techniques in MITRE ATT&CK where possible, so prioritisation reflects plausible attacker behaviour rather than abstract severity.

Measure: ratio of prioritised exposures to total discovered findings. A healthy program prioritises a small fraction, not the whole inventory

  • Stage 4: Validate

Validation proves which prioritised exposures are genuinely exploitable, using:

Penetration testing for manual, context aware exploitation.

Breach and Attack Simulation for automated, repeatable control testing against known techniques.

Attack path validation for confirming an end to end chain from entry point to impact.

Purple teaming for testing detection and response alongside exploitability.

This is the stage most programs under invest in, and the stage that removes unexploitable findings from the queue. Validation ideally involves accredited testers for the manual component, so exploitability is confirmed rather than assumed.

Measure: percentage of prioritised exposures validated before remediation, and validation false positive rate against scanner output.

  • Stage 5: Mobilise

Mobilisation converts validated exposures into completed remediation. It requires:

.Routing findings into ticketing and workflow systems with clear ownership.

.Remediation SLAs differentiated by exposure tier. Closure tracking and verification that the fix held.

.Reporting that expresses exposure reduction over time and maps to control frameworks such as PCI DSS, ISO 27001, NIST and DORA.

Mobilisation output feeds back into the next scoping cycle. Learnings about recurring exposure types inform future scope.

Measure: mean time to remediate by tier, closure verification rate, and recurrence rate of remediated exposures.

Common failure modes

  • Running the five stages once and calling it CTEM. Without the loop, it is an assessment.
  • Skipping validation and remediating on CVSS alone, which wastes effort on unexploitable findings.
  • Scoping too broadly in cycle one, producing noise instead of focus
  • Measuring open finding counts instead of exposure reduction.

For the boundary between discovery and the wider program, see the attack surface management guide. For the contrast with periodic scanning, see CTEM vs vulnerability management.

Clarifying the framework

What are the five stages of CTEM?

Scope, discover, prioritise, validate and mobilise, run as a continuous loop.

Who defined the CTEM framework?

Gartner defined CTEM as a five stage programmatic approach to continuous exposure reduction.

Which stage is most often done poorly?

Validation. Many programs skip proving exploitability and prioritise on severity scores alone, which misallocates remediation effort.

Crossbow runs all five stages as a managed program, with validation performed by a CREST accredited testing team. See the CTEM programme or the VAPT services behind the validation stage.

Contact us

Get Cybersec

Cybersecurity processes are required to be baked into an organizations day-to-day processes for seamless adoption. Identify what is best for you.
We can help. Connect with us – we always love having a chat.

Let's Discuss together.

Have any queries ?
explore@crossbowsec.com