primedefence

Services: independent SOC and AI assurance

SOC-CMM assessment, provider selection, AI Assurance and enterprise private inference. Compare the scope and deliverables of each service.

Independent advisor reviewing SOC maturity evidence and provider evaluation scorecards in a dark navy boardroom

SOC Assurance: how mature is your SOC

Independent SOC-CMM assessment against Rob van Os' standard, cited by MITRE. 5 domains, ~26 aspects, a senior-consultant-signed matrix and a 12-month roadmap defensible before the board. The report maps to NIS2, DORA and ENS when the context requires it. The entry point is the SOC-CMM assessment; the SOC-CMM roadmap turns the matrix into a plan and continuous maturity sustains it quarter after quarter.

  • Single-entity SOC-CMM assessment, the anchor service.
  • Multi-entity SOC-CMM assessment for groups and holdings.
  • Annual maturity re-baseline as a recurring subscription.
  • Express diagnostic as a low-cost entry point.
  • Threat-informed defense: intelligence, hunting, detection and MITRE ATT&CK coverage.

SOC Sourcing & Oversight: who should run your SOC

SOC outsourcing from the buyer's side. We design and score the RFP, assess every MSSP or MDR against the SOC-CMM and help you hold them to it. We advise the buyer, never bid for the contract, and our shortlist never includes group entities. You decide and sign; the contract is direct between buyer and provider. The full process is described in MSSP and MDR selection; when the assessment recommends building instead of buying, talent and people designs the team and the hiring plan.

  • Build-vs-buy strategy and target operating model.
  • RFP design and management with a weighted scorecard.
  • Every provider assessed with SOC-CMM, not with marketing.
  • Support negotiating enforceable SLAs and KPIs.
  • Independent provider performance review, annual.

AI Assurance: are you ready for AI regulation

EU AI Act conformity for high-risk AI and Ley 31814 readiness for Peru with the same methodology. System inventory, Annex III classification, technical evidence, risk management and roadmap. ISO/IEC 42001 preparation is delivered as readiness, not certification. The full scope, frameworks and deliverables are in AI Assurance.

  • AI inventory and Annex III classification as the entry wedge.
  • EU AI Act readiness for high-risk systems.
  • Ley 31814 readiness for Peru and LATAM.
  • ISO/IEC 42001 preparation as readiness, no certificate issued.

How the assurance services connect

The assurance services connect assessment with improvement decisions. The SOC-CMM assessment produces the maturity matrix and answers the opening question: how mature is your SOC, and on what evidence. The SOC-CMM roadmap orders the gaps into a 12-month plan the board can approve and fund. From there, two paths open. If the answer is build, talent and people turns the people domain into an org chart, role profiles and a hiring plan. If the answer is buy, MSSP and MDR selection scores the market from the buyer's side with the same SOC-CMM engine. Continuous maturity keeps the improvement on a quarterly cadence with comparable evidence, and AI Assurance covers the risk that is no longer SOC-only: the AI your organization buys, integrates and deploys.

Where to start

If you have never measured your SOC against the SOC-CMM, start with the express diagnostic or the single-entity assessment: within weeks you have a baseline, a matrix and priorities. If you already have a baseline, the roadmap and the continuous maturity cadence make the diagnostic you already paid for earn its keep. And if your immediate decision is about a provider or AI regulation, MSSP or MDR selection and AI assurance work as independent entry points, with no assessment required first. If you need model execution under defined data and operating requirements, private inference has a separate entry point and implementation scope. Each proposal defines its deliverables and responsibilities.

Why the buyer side matters in MSSP selection

In MSSP selection, examine the interests of the party evaluating candidates. Primedefence advises the buyer and does not bid to operate the SOC. Private inference implementation has a separate scope and is not presented as independent assessment of our own deployment.

Who publishes the guideTypical conflictPrimedefence position
MSSP or MDR providerWants to win the RFPAdvises the buyer, does not bid
Comparison or directory siteAffiliate and advertisingEvaluation paid for by the buyer
Reseller or VARProvider commissionNo money from the provider side
PrimedefenceImplements private inference under a separate, disclosed scopeScores the candidate with SOC-CMM and does not bid

Private inference for businesses

Define model execution around your data, architecture and operating requirements. Private inference establishes scope, quality and capacity tests, and deployment responsibilities. Implementation has a separate scope from independent assessment.

Frequently asked questions

A clear scope for each decision

Define the objective, deliverables and responsibilities before work begins. Independent assessment and private inference implementation have distinct scopes; reviewing our own deployment is not presented as independent assessment.

Independent SOC-CMM assessment