LearnCTEM.com, Best CTEM Learning Platform
CTEM Basics

How to Start a CTEM Program: A 30/60/90-Day Roadmap

Start CTEM small and prove the loop before scaling. Pick one important business service, run all five stages within 30 days, publish a one-page report, run a second cycle in the next 30 days, then scale to more services in days 60 to 90 using the same operating model.

Last updated: July 24, 2026

A red arch gateway on a red grid representing the entry into a 30/60/90-day CTEM starting journey.

Quick answer

Direct answer

Days 1-30: run a first cycle on one service. Days 31-60: run a second cycle and lock in the operating model. Days 61-90: scale to two more services and formalize metrics.

What you will learn

  • A 30/60/90-day plan for starting a CTEM program
  • How to pick the first business service to scope
  • What to do in each 30-day block
  • How to prove early value to leadership
  • Common early-stage mistakes and how to avoid them

Explanation

Rule zero

Start with one business service. Widening scope before the loop is stable is the most common way early CTEM programs stall.

Before day one: pick the first service

The first service should score well on three criteria: it matters to the business, it has data you can actually pull, and it has an owner who will engage. If it is also visible to leadership, that helps with sustained support. Do not pick a service just because it is easy; ease alone will not create the story you need for cycle two.

CriterionWhyWhat good looks like
Business importanceCreates a clear risk storyCustomer-facing, revenue-generating, or regulated
Data availabilityDiscovery needs signalScanner, cloud, and identity data are already flowing
Engaged ownerMobilize needs a partnerBusiness owner meets with security regularly
Bounded surfaceFits in one cycleA handful of assets, not the entire platform

Days 1 to 30: run a first cycle

The first 30 days follow the five-stage loop end to end on the chosen service. See How CTEM Works in Real Life for a day-by-day scenario. The goal is not perfection; it is to close the loop once with evidence.

DaysStageOutput
1 to 3ScopeOne-page scope brief
3 to 8DiscoverExposure register
8 to 11PrioritizeRanked short list of top exposures
11 to 14ValidateEvidence for each priority exposure
14 to 21MobilizeClosed tickets with evidence
21 to 30Report and retrospectiveOne-page report and top three improvements

Days 31 to 60: run cycle two and lock the model

The second cycle on the same service is where the operating model becomes real. Time to closure should drop. The register should carry over. Retrospective improvements should be applied. This is also when the program formalizes:

  • A written cadence for each stage.
  • An escalation ladder.
  • The minimum viable metric set from CTEM Metrics and KPIs.
  • A one-page reporting template for the business owner.
  • A named program manager, even if part-time.

Days 61 to 90: scale to more services

Add two more services in the third month. Do not add more until the second cycle on the first service completes on time. Scaling too early replays the boil-the-ocean problem. What scales:

ElementHow it scales
Exposure registerSame schema, more rows, tagged by service
CadenceSame weekly rhythm; more services in parallel
Ownership mapExtend RACI to new services' owners
ReportingSame template per service, plus a rolled-up view for leadership
ValidationSame methods; may need a partner if internal capacity is limited

How to prove early value

Leadership judges early CTEM by whether the loop closed on something real. Show:

  • The critical exposures closed with evidence on the first service.
  • The mean age at closure and how it compares to the previous approach.
  • One clear risk story that would have been ignored under the old process.
  • The specific operational improvements the retrospective produced.

Common early-stage mistakes

MistakeWhy it happensHow to avoid
Scoping the whole environmentPressure to be comprehensivePick one service; treat the rest as future scope
Buying a platform firstVendor pitch pressureProve the loop with existing tools; buy later if a real gap remains
Skipping ValidationTime pressureValidation is non-negotiable; nothing goes to Mobilize without it
No named program managerAssumed the security lead can do it allNominate a program manager even if part-time
Reporting activity metricsEasier to producePublish outcome metrics from cycle one

Sponsor conversation script

When pitching CTEM to a sponsor, keep it short: the problem is signal, not data. We already have thousands of findings. CTEM turns those into a small ranked list of exposures that are reachable, exploitable, tied to important assets, and owned. We will prove it on one service in 30 days and report the result. If it works, we will scale.

Once the program is running, deepen with the CTEM Framework, Roles and Responsibilities, and Metrics and KPIs.

How to apply this

  • Pick one business service that meets all four selection criteria
  • Draft a 30-day plan mirroring the day-by-day table above
  • Publish a one-page scope brief before day three
  • Set a maximum of five items on the first ranked list
  • Book the day-30 report review with your sponsor before day one

Common mistakes

  • Scoping the entire environment on the first cycle
  • Buying a new platform before running one cycle
  • Skipping validation to save time
  • Delaying the retrospective until things go wrong
  • Reporting activity metrics instead of the closed loop

Key takeaways

  • Start small, prove the loop, then scale in 30-day blocks.
  • Cycle one closes the loop; cycle two locks the model; days 60 to 90 scale.
  • You do not need to buy a new platform to start.
  • A sponsor senior enough to unstick Mobilize is essential.
  • The retrospective is what turns cycles into a program.

Frequently asked questions

No. Most organizations already own the tools needed for the first cycle: a vulnerability scanner, a cloud posture tool, an identity governance tool, and a ticketing system. Start with what you have.

Related pages

Next step

Next: CTEM metrics and KPIs

Set up the metric set the sponsor will see after day 30.

Author

LearnCTEM Editorial Team

Practitioners and educators writing plain-English guides on Continuous Threat Exposure Management.

Reviewed by

Senior CTEM Practitioner Panel

Reviewed for accuracy against public CTEM guidance and real-world program experience.

Sources and further reading

  • Gartner, Implement a Continuous Threat Exposure Management (CTEM) Program (2022). Frames the phased adoption model used in this plan.
  • NIST SP 800-40, Guide to Enterprise Patch Management Planning. Public guidance aligned with CTEM Mobilize practices.