SOC-CMM 2026: the complete guide to the five domains, continuous scoring and certification
What SOC-CMM v2.4 measures, how it scores maturity and capability, what the 2026 benchmark data shows, and how to turn the questionnaire into a board-defensible roadmap and a certification path.
What the SOC-CMM is, and what it is not
SOC-CMM, the Security Operations Center Capability Maturity Model, is the public framework for measuring how mature and how capable a security operations center really is. It assesses a SOC across five domains and turns the result into a matrix you can defend, rather than a single optimistic number. After nearly a decade in the field it has become the de facto global standard for SOC capability maturity assessment, and the model and its tooling remain free to download from soc-cmm.com.
It is just as important to be clear about what the model is not. SOC-CMM is not a regulatory certificate and it does not replace NIS2, DORA or ISO 27001. Those frameworks define obligations; SOC-CMM measures the operational capability behind detection, response, reporting and continuous improvement. The two are complementary: the regulation says what must be done, the maturity model shows how well, and with what evidence, it is actually being done.
The model is used in two modes, self-assessment and independent third-party assessment, and the gap between them is the single most important thing to understand before trusting a score. An unchallenged self-assessment reliably flatters governance and services. An independent assessment returns the honest picture a board, an auditor or a regulator can act on.
Where it comes from: an academic model, not a vendor's
SOC-CMM was created by Rob van Os, MSc, and released in 2016 together with its first model and assessment tool. It did not start life as marketing. It began as academic research: a Master's thesis for the Master of Information Security at Lulea University of Technology, built with a Design Science Research approach that combined scientific method with practical testing against real security operations centers.
That origin explains why the model is trusted. Because no vendor decides what is measured or how it is scored, the result is not biased toward any particular stack. The project, based in the Netherlands, has kept the model free, open and revisable, and SOC-CMM is a registered trademark. The same independence is why it is cited as an operational reference by MITRE in the Eleven Strategies of a World-Class Cybersecurity Operations Center, by the United Kingdom NCSC and by ENISA.
The five domains and what they cover
SOC-CMM organizes the assessment into five domains. Splitting the SOC this way stops a diagnosis from being distorted by a single strong area: a SOC with excellent tooling and no process is not a mature SOC, and the matrix makes that visible at a glance.
| Domain | What it covers | Example aspects |
|---|---|---|
| Business | Strategy, governance and reason to exist | Business drivers, customers, charter, governance, privacy |
| People | Roles, staffing, knowledge and training | Roles, people management, knowledge management, training |
| Process | How detection and response are run and improved | SOC management, operations, reporting, use case management, detection, automation |
| Technology | Detection platforms, coverage and automation | SIEM, log, network and endpoint monitoring, security automation |
| Services | The service catalogue and what clients receive | Monitoring, incident management, threat intelligence, threat hunting, forensics, vulnerability management |
Three of these domains, Business, People and Process, are scored for maturity alone. The Technology and Services domains are scored for both maturity and capability, because a platform or a service can be perfectly well governed and still cover almost nothing of relevance. That distinction is central to the model and worth its own section.
Maturity and capability: two questions, not one
Maturity asks how well a practice is established, documented and governed. Capability asks how much it actually covers. Conflating the two is the classic error in SOC self-assessment. A team can run a top-tier EDR (high capability) with no documented process, no tuning cycle and no ownership around it (low maturity). Another team can operate a beautifully governed monitoring service (high maturity) that watches only a fraction of the relevant attack surface (low capability).
By scoring both for Technology and Services, SOC-CMM refuses to let either illusion stand. This is also what makes the model honest about outsourcing: applied to an MSSP or MDR service, the same two questions reveal whether the contract you pay for delivers real coverage or just a well-packaged dashboard.
How continuous 0 to 5 scoring works
SOC-CMM inherits the 0 to 5 maturity idea from established models such as CMMI and ISO/IEC 15504, but applies it on a continuous scale rather than in discrete steps. A capability that is present but inconsistent scores 1.5 or 2.0 depending on the evidence, not rounded down to nothing or up to a level it has not earned. That removes the all-or-nothing bias and, crucially, lets a SOC show real movement between assessment cycles: climbing Process from 2.4 to 2.8 in a year is measurable, defensible progress.
The scale anchors. 0 nonexistent, 1 initial, 2 repeatable, 3 defined, 4 managed, 5 optimizing. The half-point values reflect partial progress backed by evidence, not opinion.
Per-aspect scores roll up into a per-domain average, and the domains roll up into an overall picture. But the matrix is always more useful than the headline number: a global 2.5 can hide a Technology at 4 sitting next to a People at 1, and the key-person dependency that comes with it.
What the 2026 benchmark data shows
The SOC-CMM project publishes an annual report built on an international dataset of assessments. The 2026 edition, using model version 2.4, gives three things every assessment should be read against: where SOCs really sit, where improvement is hardest, and how badly self-assessment misleads.
On the last point the number is stark: self-assessed scores run about 0.6 maturity points higher than third-party scores across almost every element. That single figure is the strongest argument for an independent read whenever a score will support a board decision, an audit or a certification.
| Domain | 2026 international average | Reading |
|---|---|---|
| Business | 2.5 | Charter, stakeholders and governance: the most underestimated block |
| People | 2.3 | Roles, training and individual dependency are the critical levers |
| Process | 2.3 | Where measurable operations are won or lost |
| Technology | 2.7 | Usually the highest domain; never proof of overall maturity |
| Services | 2.2 | Incident management, threat intelligence and threat hunting are the hardest aspects |
The report also flags effective SOC governance as the single hardest improvement topic, reported MITRE ATT&CK coverage rising to around 60 percent from 45 percent the year before, and roughly 57 percent of SOCs still operating without a formal AI adoption strategy. One caution travels with all of these figures: averages are a reference, not a target. A mid-size bank's SOC and a global MSSP do not need the same numbers, and the report explicitly warns against treating the highest-scoring region as an automatic goal.
From model to certificate: the certification scheme
Assessment tells you where you stand. For organizations that need a formal, auditable credential, SOC-CMM also operates a certification scheme, documented at certification.soc-cmm.com. It uses a dedicated certification model of five domains and twenty elements, with significant overlap with the assessment model so a SOC can move between the two. It differs in two deliberate ways: Technology is assessed from a platform perspective rather than tool by tool, and threat intelligence becomes a mandatory component, so a certified SOC can prove it understands what it is defending against.
Certification is awarded at one of three levels, each building on the one below and mapped directly to the maturity scale.
| Level | Requirement | What it signals |
|---|---|---|
| 1. Defined | Maturity level 3 across all domains | A standardized, reliable and repeatable way of working |
| 2. Validated | Maturity level 4 across all domains, plus all Defined controls | Services that are measured and quality-controlled, with validated detection rules |
| 3. Risk-driven | All Defined and Validated controls, plus risk-alignment and threat-intelligence controls | Operations aligned to risk, with threat intelligence built into service delivery |
The scheme behind these levels defines 127 controls, most derived from the assessment tool's questions but written far more prescriptively. Organizations can scope out specific components under a defined set of rules, but the mandatory portion grows at each level: the higher the certification, the less can be excluded. The audit itself runs in stages.
- 1.Preparation: self-assessment, gap analysis against the target level and review of the scheme, alone or with an official support partner.
- 2.Documentation audit: an auditor checks the required documentation against the scheme for completeness and quality.
- 3.Implementation audit: the auditor verifies that services, processes and procedures actually exist and work, including an on-site visit.
- 4.Validation and certificate: the auditor submits findings to the SOC-CMM foundation, an appointed reviewer validates them, and the certificate is issued and listed.
From questionnaire to a board-defensible roadmap
A score is not the deliverable. The point of an assessment is the sequence of decisions it enables, and the discipline that gets you there is the same every time.
- 1.Diagnostic: workshops per domain with the real owners, procedure review, and sampling of tickets, runbooks and detection rules so answers are checked against evidence.
- 2.Calibration: continuous scoring backed by that evidence and passed through more than one set of eyes, then compared against the sector benchmark.
- 3.Roadmap: six to twelve prioritized actions, each with a KPI, an owner, an effort estimate and its dependencies, separating quick wins from structural change.
- 4.Close: a board presentation built on a risk narrative, not a list of numbers, with the investment, the deadline and the exit metric the board is actually being asked to approve.
Then it repeats. Maturity is not static: after staff changes, mergers or platform migrations it can stagnate or fall. A reassessment every 12 to 18 months, annual under regulated frameworks such as SBS, DORA or NIS2, is what keeps the matrix alive and forces closure of the previous cycle's actions.
Sources
This guide draws on the official SOC-CMM publications and the project's 2026 report. SOC-CMM is a registered trademark of its author and is referenced here for educational purposes; Primedefence is an independent assessor and is not the owner of the standard.
- SOC-CMM, official site, model and 2026 report: https://www.soc-cmm.com
- SOC-CMM, about and origin (Rob van Os, 2016): https://certification.soc-cmm.com/about
- SOC-CMM certification, introduction and model: https://certification.soc-cmm.com/introduction
- SOC-CMM certification levels: https://certification.soc-cmm.com/introduction/certification-levels
- SOC-CMM certification process: https://certification.soc-cmm.com/introduction/certification-process
- SOC-CMM certification scheme: https://certification.soc-cmm.com/introduction/certification-scheme
- MITRE, Eleven Strategies of a World-Class Cybersecurity Operations Center: https://www.mitre.org/news-insights/publication/11-strategies-world-class-cybersecurity-operations-center
Frequently asked questions
How long does a full SOC-CMM assessment take?
Four to six weeks for a mid-sized SOC, depending on the entities in scope and how readily evidence is available. Group multi-entity assessments can extend to eight to ten weeks.
Do you need a specific tool to run SOC-CMM?
No. The SOC-CMM assessment tool is published free by soc-cmm.com. The value lies in method and evidence discipline, not in a platform; a serious report simply states the model version it used.
What is the difference between a SOC-CMM assessment and certification?
An assessment measures maturity and capability and produces a scored matrix and roadmap. Certification is a separate, formal scheme with an auditor, an on-site implementation audit and validation by the SOC-CMM foundation, awarded at one of three levels: Defined, Validated or Risk-driven.
How often should the SOC be re-scored?
Every 12 to 18 months as a rule, and annually under regulated frameworks such as SBS, DORA or NIS2. Reassessment is what turns a one-off score into measurable, governed improvement.

Written by
Daute DelgadoCEO & Co-founder, Primedefence
Daute Delgado is CEO and co-founder of Primedefence. He spent more than a decade defending airlines, managed SOCs and international organizations, first as an operator and later leading security teams.
View full profileNeed an independent SOC-CMM assessment?
Book an express diagnostic with a senior assessor. No product sales, no SOC operation.



