primedefence
MSSP selectionPlaybook

Independent MSSP and MDR selection: the buyer-side playbook

An eight-step, evidence-led process for choosing and overseeing an MSSP or MDR provider from the buyer's side.

By Daute Delgado Updated 2026-06-12 6 min read

Why does MSSP selection need an independent process?

Most MSSP and MDR selections fail before the RFP is written. The buyer starts from a vendor list, sits through demonstrations, and lets the most persuasive pitch define the requirements. The result is a provider chosen on chemistry and price, with a scope that mirrors the vendor's catalogue rather than the buyer's actual gaps.

The same optimism bias that distorts internal maturity scoring distorts procurement. SOC-CMM 2026 report data shows self-assessments overestimate maturity by roughly 0.6 points on the 0-5 scale. A team that believes it is stronger than it is will buy the wrong service: too narrow where it is weak, redundant where it is already capable. An independent, third-party view of the current state corrects the baseline before money moves.

This playbook sets out eight steps. Each one produces a documented artifact: a requirements catalogue, a long-list with exclusion criteria, a scorecard, a Proof of Value report, a contract annex, a signed recommendation. Regulators reviewing third-party ICT decisions under DORA and NIS2 ask for exactly this trail.

Steps 1 and 2: requirements from maturity gaps, then the long-list

Step 1 is to translate SOC-CMM findings into concrete service requirements. The 2026 domain averages explain why this matters: Technology scores around 2.7 while Services sits at 2.2 and People at 2.3. Many organizations do not need more tooling from an MSSP; they need sustained operating discipline, coverage outside business hours, and documented service delivery. The maturity profile tells you which.

  • Use cases and log sources: which detection scenarios the provider must cover, fed by which of your sources.
  • Service levels expressed in detection and response terms, not just ticket acknowledgement.
  • Geography, data residency and working languages, including the language of board-facing reports.
  • Integrations with your SIEM, ticketing and identity stack, with ownership of each interface stated.
  • Exit conditions defined as requirements from day one: handover, data return, runbook portability.

Step 2 builds the long-list: 8 to 12 candidates filtered by explicit exclusion criteria such as no presence in your jurisdiction, no support for a mandatory log source, or no verifiable references in your sector. Write the exclusions down. A long-list without documented criteria is the first thing an auditor will challenge.

Steps 3 and 4: ask capability questions and maturity questions

Capability is whether a service element exists and how well it is designed. Maturity is how consistently it is performed, measured and improved. The SOC-CMM separates the two, and your pre-filter questionnaire (step 3) and detailed RFP to the 3 or 4 finalists (step 4) should as well. Every provider will pass the capability test on paper. The differences appear under maturity questions.

  • Show service-level performance for the last 12 months for a client of our size and sector, not a marketing average.
  • How often are detection runbooks reviewed, by whom, and where is the change history?
  • What is analyst attrition over the last year, and will we have a named team or a pooled first tier?
  • What is the detection engineering cadence: new and tuned use cases delivered per quarter, with examples?
  • If you claim ATT&CK coverage, which techniques exactly, and how was coverage validated? Self-reported figures around the 60% average mean little without the technique list.
  • Provide a redacted incident report and a redacted monthly report as delivered to a real client.

Step 5: an evidence-based scoring matrix

Score only what is evidenced. A claim without an artifact behind it scores zero. Two raters score independently, divergences above one point are discussed and resolved in writing, and the weighted matrix is shared with the steering committee before responses arrive, so weights cannot be adjusted to favor a preferred vendor afterwards.

CriterionWeightEvidence required (not the pitch)
Detection and response capability25%Sample alerts, runbook excerpts, use-case catalogue mapped to your requirements
Operational maturity20%12 months of SLA performance, runbook change history, staffing and attrition data
Integration and onboarding15%Onboarding plan with milestones, reference call with a comparable client
Language and reporting10%Redacted reports in your working languages, board-level sample
Commercials15%Three-year total cost of ownership including onboarding and exit costs
Exit and portability15%Draft exit annex: handover period, data return formats, runbook ownership

Step 6: Proof of Value with predefined metrics

Run a Proof of Value with 2 or 3 finalists on a realistic slice of your environment. The metrics are defined and agreed before the PoV starts. A PoV whose success criteria are written afterwards proves nothing; it only generates material for the vendor's case study.

  • Time from log source connection to first validated detection.
  • False positive rate and escalation quality on injected test scenarios.
  • Responsiveness and substance of analyst communication during the exercise.
  • Readability of the resulting report by a non-technical executive, tested by actually giving it to one.

Step 7: contract SLAs that map to outcomes, and exit clauses

Negotiate the contract against the same outcome metrics used in the PoV. An SLA that measures time-to-acknowledge tells you how fast a ticket changes state. It tells you nothing about whether a real intrusion would be detected and contained. Each contractual service level should map to a metric you can independently verify from your own data, with service credits attached and an audit right over the provider's reported figures.

Response SLA is not detection SLA. The most expensive confusion in MSSP contracts: a 15-minute response SLA usually means a ticket was acknowledged in 15 minutes. Detection performance, triage quality and containment are separate obligations. If the contract only defines response, the provider can meet every SLA during a breach it never detected.

  • Exit and handover period long enough to transition without coverage gaps, with provider cooperation obligations stated.
  • Return of logs and case data in open, documented formats, with retention guaranteed through the transition.
  • Ownership and transfer of runbooks and detection content developed for you during the contract.
  • Reversibility tested on paper before signature: walk the exit scenario with the provider and record the answers.

Step 8: ongoing supervision with SOC-CMM re-assessment

Signature is the start of supervision, not the end of the project. DORA (Regulation (EU) 2022/2554) makes ICT third-party risk management a continuing obligation for financial entities, and NIS2 (Directive (EU) 2022/2555) extends supply chain security duties to essential and important entities. Both expect you to demonstrate that the outsourced capability is monitored, not just contracted.

The practical mechanism is a periodic independent SOC maturity assessment of the outsourced scope against the SOC-CMM, the model created by Rob van Os in 2016, now at version 2.4, covering five domains and 27 aspects on a continuous 0-5 scale. Assessing the provider-operated service with the same yardstick used for your internal baseline gives the board a single trend line: is the maturity you bought actually being delivered, and is it improving year over year? The eighth step closes the loop: documented decision, signed recommendation, and a scheduled re-assessment date before the first renewal conversation.

Frequently asked questions

How long does a full independent selection take?

Six to ten weeks for a mid-size organization, from requirements workshop to signed recommendation. Adding a Proof of Value with two or three finalists typically extends the process to around twelve weeks. The schedule compresses if the SOC-CMM maturity assessment that feeds step 1 already exists; it lengthens if requirements have to be built from scratch.

Who should sign the scoring matrix and the final recommendation?

The CISO and the procurement lead sign the scorecard, and the recommendation to the board carries both signatures. Where an independent advisor supports the process, their review of the scoring is documented as well. The point is accountability: a regulator or internal auditor reviewing the decision should find named owners for the weights, the scores and the conclusion.

Should the incumbent MSSP be invited to the RFP?

Only if the decision is genuinely open. If the organization has already decided to leave, inviting the incumbent adds noise, consumes evaluation effort and creates commercial friction during the remaining contract term. If the incumbent participates, it is scored on the same evidence requirements as everyone else, including twelve months of its own delivered SLA performance, which it should be able to produce faster than any competitor.

What does ongoing supervision of an MSSP look like in practice?

Three layers. Monthly: service reviews against the contractual outcome metrics, using your own data where possible rather than the provider's self-reported figures. Quarterly: review of detection content changes and staffing on your account. Annually: an independent SOC-CMM maturity assessment of the outsourced scope, producing a 0-5 scored trend the board can read next to the internal baseline. This is also the evidence trail DORA and NIS2 supervision expects.

Daute Delgado

Written by

Daute Delgado

CEO & Co-founder, Primedefence

Daute Delgado is CEO and co-founder of Primedefence. He spent more than a decade defending airlines, managed SOCs and international organizations, first as an operator and later leading security teams.

View full profile

Need an independent SOC-CMM assessment?

Book an express diagnostic with a senior assessor. No product sales, no SOC operation.

Talk to an assessor

Related articles