The CTEM framework is a five stage lifecycle for reducing exploitable exposure continuously: scope, discover, prioritise, validate and mobilise. Gartner defined it as a repeating loop rather than a linear project, because exposure is a moving target. This guide covers each stage technically: what it does, the tooling categories involved, and what to measure
Why it is a loop, not a line
The five stages repeat. Mobilisation feeds back into scope because remediating one area, and discovering new assets, both change what matters in the next cycle. A one off assessment structured around these five headings is not CTEM. The continuous re-entry is the defining property. Each cycle should leave measurably less exploitable exposure within scope than the last.
Scoping defines the boundary of the cycle in business terms, not technical convenience. The primary technique is crown jewel analysis: identifying the assets, data stores, identities and third party connections whose compromise produces material impact. Scope also captures the threat context, which adversaries and techniques are relevant to the sector. Good scoping is narrow at first and expands as the program matures. Trying to scope the entire estate in cycle one produces noise, not focus. Measure: scope tied to documented business impact, agreed with asset owners, revisited each cycle.
Discovery enumerates assets and weaknesses within scope. It draws on multiple tooling categories:
EASM for internet facing assets, via passive DNS, certificate transparency, ASN enumeration and external scanning.
CAASM for internal asset correlation from cloud APIs, EDR, CMDB and identity providers
Vulnerability scanning for known CVEs
Cloud security posture for IaaS and PaaS misconfigurations.
Identity discovery for accounts, entitlements and over permissioned roles, an increasingly central part of the attack surface.
Measure: coverage as a proportion of the in scope estate under continuous discovery, and time to detect new or changed assets.
Prioritisation ranks discovered weaknesses by exploitation likelihood and consequence. Mature prioritisation blends:
CVSS for base severity.
EPSS for modelled exploitation probability.
CISA KEV and threat intelligence for confirmed active exploitation.
Reachability and attack path analysis for accessibility and chaining.
Business impact from scoping.
Findings are mapped to adversary techniques in MITRE ATT&CK where possible, so prioritisation reflects plausible attacker behaviour rather than abstract severity.
Measure: ratio of prioritised exposures to total discovered findings. A healthy program prioritises a small fraction, not the whole inventory
Validation proves which prioritised exposures are genuinely exploitable, using:
Penetration testing for manual, context aware exploitation.
Breach and Attack Simulation for automated, repeatable control testing against known techniques.
Attack path validation for confirming an end to end chain from entry point to impact.
Purple teaming for testing detection and response alongside exploitability.
This is the stage most programs under invest in, and the stage that removes unexploitable findings from the queue. Validation ideally involves accredited testers for the manual component, so exploitability is confirmed rather than assumed.
Measure: percentage of prioritised exposures validated before remediation, and validation false positive rate against scanner output.
Mobilisation converts validated exposures into completed remediation. It requires:
.Routing findings into ticketing and workflow systems with clear ownership.
.Remediation SLAs differentiated by exposure tier. Closure tracking and verification that the fix held.
.Reporting that expresses exposure reduction over time and maps to control frameworks such as PCI DSS, ISO 27001, NIST and DORA.
Mobilisation output feeds back into the next scoping cycle. Learnings about recurring exposure types inform future scope.
Measure: mean time to remediate by tier, closure verification rate, and recurrence rate of remediated exposures.
Common failure modes
For the boundary between discovery and the wider program, see the attack surface management guide. For the contrast with periodic scanning, see CTEM vs vulnerability management.
Clarifying the framework
What are the five stages of CTEM?
Scope, discover, prioritise, validate and mobilise, run as a continuous loop.
Who defined the CTEM framework?
Gartner defined CTEM as a five stage programmatic approach to continuous exposure reduction.
Which stage is most often done poorly?
Validation. Many programs skip proving exploitability and prioritise on severity scores alone, which misallocates remediation effort.
Crossbow runs all five stages as a managed program, with validation performed by a CREST accredited testing team. See the CTEM programme or the VAPT services behind the validation stage.


