Version 2.2, August 2026

Following is the process of becoming a FIRST Full Member (teams only). Applying team is the ‘candidate.’
Candidate representative(s) to create a profile for the FIRST Portal and completes/submits the Membership Interest Form. Once validated by the Secretariat, the candidate and sponsors will be sent to the application.
Candidate completes the Security Incident Management Maturity Model (SIM3) self-assessment and reviews results with the primary sponsor.
Candidate contacts the primary sponsor to schedule the site visit (in person or virtual). Review the Site Visit template report to prepare the requested materials/documents in Annex 2. The primary sponsor drafts a report using the template at Annex 7. Any area of the report that does not apply should be explained.
The Candidate must complete the FIRST Membership Application Form on FIRST Portal.
Information provided in the application form will be used to update the teams profile in the FIRST Portal. By applying to FIRST, the candidate agrees to review this information annually for accuracy and provide regular updates to team details and confirm team members.
Both sponsors review the application form including the SIM3 score and site visit report. Sponsors upload their letters of support recommending the team. Sponsors can use the template at Annex 4.
Once all boxes on the application are checked, sponsor or candidate submit the Application Form.
The review process begins on the 1st of the month following submission:
Estimated duration of review period – 3-4 weeks
If any issues or objections are identified, the FIRST Secretariat takes this back to the Candidate and the Sponsors for resolution. If needed, the process loops back to step 7. Rejected teams have the right to re-apply at any time.
The checklist below corresponds with the Full Member Application Form on the FIRST website.
| Item | Mandatory/Optional |
|---|---|
| A brief statement of why the Team would like to join FIRST and how it plans to participate – application letter | Mandatory |
| Primary Sponsor – FIRST full member – uploaded on the portal | Mandatory |
| Primary Sponsor Sponsoring Letter – uploaded on the portal | Mandatory |
| Secondary Sponsor – FIRST full member – uploaded on the portal | Mandatory |
| Secondary Sponsor Sponsoring Letter – uploaded on the portal | Mandatory |
| Site Visit Report and SIM3 Assessment – uploaded on the portal | Mandatory |
Team Information
|
Mandatory (optional where indicated) |
Team Members
|
Mandatory (optional where indicated) |
Contact Information
|
Mandatory (optional where indicated) |
Constituency
|
Mandatory (optional where indicated) |
Services based on FIRST Services Framework
|
Mandatory to acknowledge what applies |
Information Handling Policies
|
Mandatory (optional where indicated) |
Cryptography
|
Optional |
FIRST Mailing Lists
|
Mandatory (optional where indicated) |
Invoice Information
|
Optional |
The Primary Sponsor visits the Candidate’s premises, with the goal of verifying if the Candidate meets the FIRST membership requirements. The Site Visit can be performed virtually instead of in-person, using videoconferencing tools (audio only is not permitted). The Secondary Sponsor is welcome to participate in the Site Visit, either in person or online.
During the Site Visit the Sponsor(s) review the Candidate’s organization, processes, tools, systems, premises, etcetera, to gain a thorough understanding on the Candidate’s readiness to become a full member of FIRST. This understanding is necessary to enable the Sponsors to support the Candidate’s application.
The organization of the Site Visit is up to the Primary Sponsor. The following 6 items are the ingredients:
1 – Mandatory – The Candidate is evaluated against a subset of SIM3 parameters
The 11 mandatory parameters to review are O-1, O-2, O-3, O-4, O-5, O-10, H-1, H-2, H-7, P-1, P-11. The baseline is set to minimum levels that must be met by Candidate are shown in Annex 3. The online tool is tailored to facilitate this process and a link is accessible in your online application form.
2 – Optional – Discussion of the remaining SIM3 parameters Optional, but strongly encouraged
Such a discussion (the same tool can be used as basis) will be beneficial both for the Candidate and their understanding on how to further advance their team maturity, but also for the Sponsor(s) to gain deeper understanding of the Candidate. (See Annex 3 for all SIM3 parameters)
Note: the current version of SIM3 still focuses on CSIRTs of all kinds. Some potential members, like PSIRTs, will fall more or less outside that categorization – in that case, still most SIM3 parameters will apply, and the discussion will still be beneficial, but enough flexibility needs to be exercised by the Sponsor(s).
3 – Mandatory – Candidate and Sponsors to assess the Full Member Application Form
This is to see if Candidate has supplied or can supply all the necessary information and discuss where needed. PGP/GPG keys and the usage of PGP/GPG inside the FIRST community are part of the discussion.
4 – Optional – Sponsor(s) to discuss TLP and the FIRST Code of Ethics with Candidate Optional, but strongly encouraged.
Neither are mandatory, however FIRST strongly recommends to all their members to respect and support both.
5 – Mandatory – Sponsor(s) to assess whether Candidate is in the position to become a full member of FIRST and be an asset to the FIRST community
Sponsors, to their best professional judgment, must assess whether Candidate has the values to become a full member of FIRST and will be able to bring value to the FIRST community. The matter of "trust", basics to how the FIRST community functions, must be thoroughly discussed with the Candidate.
6 – Optional – Sponsor(s) to assess with Candidate its security and confidentiality situation Optional, but strongly encouraged
Sponsor(s) are strongly encouraged to assess together with Candidate the security/confidentiality situation that Candidate is in – regarding premises, access control, separate room(s), network, and system security, etcetera – both physical security and cybersecurity wise.
There are no absolute rules to give here, as much also depends on the kind of environment that Candidate is in. For a university CSIRT the reasonable demands will differ from those for a bank or government team. The end goal is to ensure that the Candidate has a reasonable ability to keep FIRST information confidential. Sponsor(s) can help Candidate in this regard, also to increase the awareness of Candidate (and their governance) for these issues. In the case that Sponsor(s) have grave concerns about such issues, that Candidate cannot take away, these must be highlighted in the Site Report.
After the Site Visit the Primary Sponsor writes a Site Visit report which is part of the FIRST full member application process. This report must include the result of the assessment of the required subset of SIM3 parameters. The report is shared with the Secondary Sponsor and Candidate for comments and discussion.
7 - Sponsor to draft a Site Visit report
A sample template is available on Annex 7
The following first table is derived from SIM3 and primarily targeted at cybersecurity incident management teams (CSIRTs, NCSCs, CDCs, CIRTs, etc.).
A second version of this table, but limited to only the 11 required parameters, and aimed at PSIRTs, and is further down in this Annex.

| Parameter | Description | Required level |
|---|---|---|
| O – "Organization" Parameters | ||
| O-1 MANDATE |
Description: The CSIRT’s assignment as derived from upper management. | 3 |
| O-2 CONSTITUENCY |
Description: Who the CSIRT functions are aimed at CONSTITUENCY the "clients" of the CSIRT. | 3 |
| O-3 AUTHORITY |
Description: What the CSIRT can do towards their constituency in order to accomplish their role. | 3 |
| O-4 RESPONSIBILITY |
Description: What the CSIRT is expected to do towards their constituency in order to accomplish their role. | 3 |
| O-5 SERVICE DESCRIPTION |
Description: Describes what the CSIRT service is and how to reach it. Minimum requirement: Contains the CSIRT contact information, service windows, concise description of the CSIRT services offered and the CSIRT’s policy on information handling and disclosure. | 3 |
| O-7 SERVICE LEVEL DESCRIPTION |
Description: Describes the level of service to be expected from the CSIRT. Minimum requirement: Specifies the speed of reaction to incoming incident reports and reports from constituents and from peer CSIRTs. For the latter a human reaction within two working days is the minimum expected. | - |
| O-8 INCIDENT CLASSIFICATION |
Description: The availability and application of an incident classification scheme to recorded incidents. Incident classifications usually contain at least "types" of incidents or incident categories. However, they may also include the "severity" of incidents. | - |
| O-9 INTEGRATION IN EXISTING CSIRT SYSTEMS |
Description: Describes the CSIRT's level of membership of a well-established CSIRT co-operation, either directly or through an "upstream" CSIRT of which it is a customer/client. This is necessary to participate and integrate in the trans-national/worldwide CSIRT system(s). | - |
| O-10 ORGANIZATIONAL FRAMEWORK |
Description: Fits O-1 to O-9 together in a coherent framework document serving as the controlling document for the CSIRT. Minimum requirement: Describes the CSIRT’s mission and parameters O-1 to O-9. note: for FIRST application, change "O-1 to O-9" into "O-1 to O-5" |
3 |
| O-11 SECURITY POLICY |
Description: Describes the security framework within which the CSIRT operates. This can be part of a bigger framework, or the CSIRT can have their own security policy. | - |
| H – "Human" Parameters | ||
| H-1 CODE OF CONDUCT/ PRACTICE/ ETHICS |
Description: A set of rules or guidelines for the CSIRT members on how to behave professionally, potentially also outside work. Clarification: E.g. the FIRST Code of Ethics. Behavior outside work is relevant, because it can be expected of CSIRT members that they behave responsibly in private as well where computers and security are concerned. | 2 |
| H-2 PERSONNEL RESILIENCE |
Description: How CSIRT staffing is ensured during illness, holidays, people leaving, etc. Minimum requirement: three (part-time or full-time) CSIRT members. | 2 |
| H-3 SKILLSET DESCRIPTION |
Description: Describes the skills needed on the CSIRT job(s). | - |
| H-4 INTERNAL TRAINING |
Description: Internal training (of any kind) available to train new members and to improve the skills of existing ones. | - |
| H-5 (EXTERNAL) TECHNICAL TRAINING |
Description: Program to allow staff to get job-technical training externally – like FIRST training, TRANSITS, ENISA CSIRT Training, or commercial training programs (CERT/CC, SANS, etc.) | - |
| H-6 (EXTERNAL) COMMUNICATION TRAINING |
Description: Program to allow staff to get (human) communication/presentation training externally. | - |
| H-7 EXTERNAL NETWORKING |
Description: Going out and meeting other CSIRTs. Contributing to the CSIRT system when feasible. | 2 |
| T – "Tools" Parameters | ||
| T-1 IT RESOURCES LIST |
Description: Describes the hardware, software, etc. commonly used in the constituency, so that the CSIRT can provide targeted advice. | - |
| T-2 INFORMATION SOURCES LIST |
Description: Where does the CSIRT get their vulnerability/threat/scanning information from. | - |
| T-3 CONSOLIDATED E-MAIL SYSTEM |
Description: When all CSIRT mail is (at least) kept in one repository open to all CSIRT members, we speak of a consolidated e-mail system. | - |
| T-4 INCIDENT TRACKING SYSTEM |
Description: A trouble ticket system or workflow software used by the CSIRT to register incidents and track their workflow. Clarification: RTIR, AIRT, OTRS, trouble ticket systems in general. | - |
| T-5 RESILIENT PHONE |
Description: The phone system available to the CSIRT is resilient when its uptime and time-to-fix service levels meet or exceed the CSIRT’s service requirements. Clarification: Mobile phones are the easiest fallback mechanism for when a team’s landlines are out of order. Minimum requirement: Fallback mechanism for the case of phone system outages | - |
| T-6 RESILIENT E-MAIL |
Description: The e-mail system available to the CSIRT is resilient when its uptime and time-to-fix service levels meet or exceed the CSIRT’s service requirements. | - |
| T-7 RESILIENT INTERNET ACCESS |
Description: The Internet access available to the CSIRT is resilient when its uptime and time-to-fix service levels meet or exceed the CSIRT’s service requirements. | - |
| T-8 INCIDENT PREVENTION TOOLSET |
Description: A collection of tools aimed at preventing incidents from happening in the constituency. The CSIRT operates or uses these tools or has access to the results generated by them. Clarification: e.g. IPS, virus scanning, spam filters, port scanning. If not applicable as for a purely coordinating CSIRT, choose -1 as Level and will be omitted from "scoring". | - |
| T-9 INCIDENT DETECTION TOOLSET |
Description: A collection of tools aimed at detecting incidents when they happen or are near happening. The CSIRT operates or uses these tools or has access to the results generated by them. Clarification: e.g. IDS, Quarantine nets, NetFlow analysis. | - |
| T-10 INCIDENT RESOLUTION TOOLSET |
Description: A collection of tools aimed at resolving incidents after they have happened. The CSIRT operates or uses these tools or has access to the results generated by them. Clarification: e.g. basic CSIRT tools including who is, traceroute etc.; forensic toolkits. | - |
| P – "Processes" Parameters | ||
| P-1 ESCALATION TO GOVERNANCE LEVEL |
Description: Process of escalation to upper management for CSIRTs who are a part of the same host organization as their constituency. For external constituencies: escalation to governance levels of constituents. | 3 |
| P-2 ESCALATION TO PRESS FUNCTION |
Description: Process of escalation to the CSIRT’s host organization’s press office. | - |
| P-3 ESCALATION TO LEGAL FUNCTION |
Description: Process of escalation to the CSIRT’s host organization’s legal office. | - |
| P-4 INCIDENT PREVENTION PROCESS |
Description: Describes how the CSIRT prevents incidents, including the use of the related toolset. Also, this includes the adoption of proactive services like the issuing of threat/vulnerability/patch advisories. | - |
| P-5 INCIDENT DETECTION PROCESS |
Description: Describes how the CSIRT detects incidents, including the use of the related toolset. | - |
| P-6 INCIDENT RESOLUTION PROCESS |
Description: Describes how the CSIRT resolves incidents, including the use of the related toolset. | - |
| P-7 SPECIFIC INCIDENT PROCESSES |
Description: Describes how the CSIRT handles specific incident categories, like phishing or copyright issues. Clarification: may be part of P-6. | - |
| P-8 AUDIT/FEEDBACK PROCESS |
Description: Describes how the CSIRT assesses their setup and operations by self-assessment, external or internal assessment and a subsequent feedback mechanism. Those elements considered not up-to-standard by the CSIRT and their management are considered for future improvement. | - |
| P-9 EMERGENCY REACHABILITY PROCESS |
Description: Describes how to reach the CSIRT in cases of emergency. Clarification: Often only open to fellow teams. | - |
| P-10 BEST PRACTICE E-MAIL AND WEB PRESENCE |
Description: Describes (1) the way in which generic, security related mailbox aliases @org.tld are handled by the CSIRT or by parties who know when what to report to the CSIRT – and (2) the web presence. | - |
| P-11 SECURE INFORMATION HANDLING PROCESS |
Description: Describes how the CSIRT handles confidential incident reports and/or information. Also has bearing on local legal requirements. Clarification: it is advised that this process explicitly supports the use of TLP, the Traffic Light Protocol. | 2 |
| P-12 INFORMATION SOURCES PROCESS |
Description: Describes how the CSIRT handles the various information sources available to the CSIRT (as defined in the related tool, if available – see T-2). | - |
| P-13 OUTREACH PROCESS |
Description: Describes how the CSIRT reaches out to their constituency not in regard incidents but in regard PR and awareness raising. | - |
| P-14 REPORTING PROCESS |
Description: Describes how the CSIRT reports to the management and/or the CISO of their host organization, i.e. internally. | - |
| P-15 STATISTICS PROCESS |
Description: Describes what incident statistics, based on their incident classification (see O-8), the CSIRT discloses to their constituency and/or beyond. Clarification: If not applicable as in case of an explicit choice only to report internally, choose -1 as Level and will be omitted from "scoring". | - |
| P-16 MEETING PROCESS |
Description: Defines the internal meeting process of the CSIRT. | - |
| P-17 PEER-TO-PEER PROCESS |
Description: Describes how the CSIRT works together with peer CSIRTs and/or with their "upstream" CSIRT. | - |
Below follows the PSIRT-tailored version of the above table. It is limited to only the 11 required parameters:
| Parameter | Description | Required level |
|---|---|---|
| O – "Organization" Parameters | ||
| O-1 MANDATE |
Description: The PSIRT’s assignment as derived from upper management. | 3 |
| O-2 CONSTITUENCY |
Description: Who the PSIRT functions are aimed at CONSTITUENCY the "clients" of the CSIRT. | 3 |
| O-3 AUTHORITY |
Description: What the PSIRT can do towards their constituency in order to accomplish their role. | 3 |
| O-4 RESPONSIBILITY |
Description: What the PSIRT is expected to do towards their constituency in order to accomplish their role. | 3 |
| O-5 SERVICE DESCRIPTION |
Description: Describes what the PSIRT service is and how to reach it. Minimum requirement: Contains the PSIRT contact information, service windows, concise description of the PSIRT services offered and the PSIRT’s policy on information handling and disclosure. | 3 |
| O-10 ORGANIZATIONALFRAMEWORK |
Description: Fits O-1 to O-9 together in a coherent framework document serving as the controlling document for the PSIRT. Minimum requirement: Describes the PSIRT’s mission and parameters O-1 to O-9. note: for FIRST application, change "O-1 to O-9" into "O-1 to O-5" |
3 |
| H – "Human" Parameters | ||
| H-1 CODE OF CONDUCT / PRACTICE / ETHICS |
Description: A set of rules or guidelines for the PSIRT members on how to behave professionally, potentially also outside work. Clarification: E.g. the FIRST Code of Ethics. Behavior outside work is relevant, because it can be expected of CSIRT members that they behave responsibly in private as well where computers and security are concerned. | 2 |
| H-2 PERSONNEL RESILIENCE |
Description: How PSIRT staffing is ensured during illness, holidays, people leaving, etc. Minimum requirement: three (part-time or full-time) PSIRT members. | 2 |
| H-7 EXTERNAL NETWORKING |
Description: Going out and meeting other CSIRTs. Contributing to the CSIRT/PSIRT system when feasible. | 2 |
| P – "Processes" Parameters | ||
| P-1 ESCALATION TO GOVERNANCE |
LEVEL Description: Process of escalation to upper management for PSIRTs who are a part of the same host organization as their constituency. For external constituencies: escalation to governance levels of constituents. | 3 |
| P-11 SECURE INFORMATION HANDLING |
PROCESS Description: Describes how the PSIRT handles confidential incident reports and/or information. Also has bearing on local legal requirements. Clarification: it is advised that this process explicitly supports the use of TLP, the Traffic Light Protocol. | 2 |
The below text may be included in both Sponsor Letters, and as inspiration for such letters.
When completed, the Sponsor Letter(s) should be converted into a PDF format, on letterhead (recommended), signed and uploaded to the application on the portal. Primary and Secondary Sponsor each sign their own Sponsor Letter.
1. Version history
This document was originally produced by the CERT Program at the Software Engineering Institute at Carnegie Mellon University and by the Cisco Systems PSIRT
Please note, this is a sample template for a site visit report. The sponsors can modify as needed or note if any sections of the template or not applicable to the applying team and why.
A high-level view on the process with the steps, stakeholders, and estimated duration is presented below:
| M Mandatory R Recipient (o) Optional |
Steps | Candidate | Primary Sponsor | Secondary Sponsor | FIRST Secretariat | FIRST MC | Mentor | FIRST Board | FIRST Community | Estimated Duration | |
|---|---|---|---|---|---|---|---|---|---|---|---|
| Candidate identifies two FIRST full members as Sponsors | 1 | M | M | M | (o) | (o) | (o) | 1m | Estimated duration: 5 months | ||
| Candidate submits Membership Interest Form | 2 | M | |||||||||
| Candidate performs a SIM3 self-assessment | 3 | M | (o) | 1w | |||||||
| Candidate schedules the site visit with their primary sponsor | 4 | M | (o) | (o) | 1w | ||||||
| Candidate completes the Full Member Application Form | 5 | M | (o) | (o) | (o) | 1m | |||||
| Sponsors review application and attach letters of support | 6 | M | M | 2w | |||||||
| All materials are submitted for review | 7 | M | R | (o) | 1d | ||||||
| Review and Approval Process | 8 | M | M | M | M | M | M | R | 3-4w |