Skip to main content
CR-CMM · AI Resilience Extension · Coming October 2026

Is your AI as resilient as the rest of your organization?

The CR-CMM AI Resilience Extension helps you assess how well your AI systems and agents can withstand, contain and recover from disruption, using the same maturity model you already apply to the rest of your organization.

Planned release

October 2026

The download is planned for October 2026. Register now and we'll send it to you as soon as it's released.

Delivered as an Excel workbook. It extends the CR-CMM, it doesn't replace it.
Why now

Why AI resilience, and why now

Generative and agentic AI now sit inside critical business workflows. Regulations such as DORA and the EU AI Act expect the same resilience discipline for AI that organizations already apply elsewhere.

Most organizations have an AI strategy. What they lack is evidence: which specific controls prove that their AI can withstand an attack, stay within its mandate, and recover cleanly when something goes wrong. A maturity score alone doesn't answer that question. The AI Resilience Extension does.

What's inside
  • 70+ assessment questions to evaluate your AI resilience posture across the CR-CMM practices.
  • A ready-to-use self-assessment: set your current and target maturity for each practice and see the gaps immediately.
  • An automatic dashboard showing where you stand, the size of each gap, and what to implement next.
  • Baseline and advanced questions: start with the essentials, then harden further as you mature.
  • Full traceability from each question to the recognised AI security controls and threat sources behind it.
Two sides of AI resilience

Two sides of AI resilience

Resilience of AI

Your AI as the asset at risk: poisoned data and context, hijacked reasoning, compromised agent identities, and agents that re-infect a clean environment after recovery.

Resilience against AI

AI as the attacker's weapon: machine-speed attacks on your existing infrastructure, and compromised AI orchestration used as a foothold into the rest of the business.

How it works

How it works

  1. 1

    Set the goal

    The CR-CMM defines which resilience practice applies and how mature it needs to be, from Initial to Optimized.

  2. 2

    Keep agents governed

    A Zero Trust lens for AI agents across five dimensions (identity, behaviour, data, segmentation and incident response) keeps each agent within its mandate and limits the damage if it is compromised.

  3. 3

    Select the right depth

    The Cloud Security Alliance's AI Security Maturity Model translates your maturity goal into how much AI control depth you need.

  4. 4

    Implement testable controls

    Each question traces to controls in the CSA AI Controls Matrix, so your teams know what to implement and auditors know what to test.

Threat evidence from CSA MAESTRO, the OWASP Top 10 for LLM and Agentic AI, and MITRE ATLAS shows where attacks land, what they look like, and that they are seen in the wild.

Maturity model

Five maturity levels

LevelNameWhat it means for your AI
1InitialNo AI-specific resilience controls. AI incidents stay invisible until they hit the business.
2RepeatableThe foundations: an inventory of AI systems and agents, with baseline monitoring.
3DefinedDefined AI controls applied consistently across teams.
4ManagedAI controls enforced and automated, including behaviour-based detection and automated containment.
5OptimizedAI controls continuously tested and improved.
Risk coverage

Real AI risks it helps you address

Shadow agents

AI agents running with real privileges that nobody has registered or owns.

Unauthorised autonomous action

An agent doing something it was never meant to do, hidden in normal traffic.

Persistent context poisoning

A compromised agent that survives recovery and re-infects a clean environment.

Logic hijacking

An attacker steering an agent's reasoning and decisions.

Command injection

Hostile instructions reaching an agent through its data and tools.

Alignment

Aligned with the standards you already work with

EU AI ActDORAISO/IEC 42001NIST AI 600-1CSA AI Controls MatrixOWASPMITRE ATLAS

Who it's for: CISOs, cyber resilience and AI security leaders, risk and compliance teams, internal auditors, and anyone who needs to show the board or a regulator that their AI is under control.

Register now

Register for early access

The AI Resilience Extension is in its final stage of development and is planned for release in October 2026. Register now and we'll email it to you as soon as it's available.

Fields marked with an asterisk are required. You can also volunteer for the pilot group to test the extension before release.
FAQ

Frequently asked questions

When will it be available?▾
The release is planned for October 2026. Everyone who registers will receive it by email as soon as it's published.
Do I need the CR-CMM to use it?▾
It extends the CR-CMM and uses the same practices and maturity levels, so you'll get the most from it alongside a CR-CMM assessment.
How many questions are there?▾
More than 70, split into baseline questions for the essentials and advanced questions for organizations aiming higher.
What format is it?▾
An Excel workbook with the question set, a self-assessment and an automatic dashboard.
Is it free?▾
Yes, like the CR-CMM, the AI Resilience Extension is free to use under the CR-CMM's published licensing terms.
Credits

Credits

The AI Resilience Extension is led by Lukasz Guzdziol, AI Resilience Lead, CR-CMM, with Surendra Narang, Community Lead, CR-CMM, and the support of the CR-CMM community.