primedefence

Services: independent SOC and AI assurance

Independent SOC and AI assurance services: SOC maturity with SOC-CMM, buyer-side MSSP and MDR selection and AI readiness. We never bid for the contract.

Independent advisor reviewing SOC maturity evidence and provider evaluation scorecards in a dark navy boardroom

SOC Assurance: how mature is your SOC

Independent SOC-CMM assessment against Rob van Os' standard, cited by MITRE. 5 domains, ~26 aspects, a senior-consultant-signed matrix and a 12-month roadmap defensible before the board. The report maps to NIS2, DORA and ENS when the context requires it. The entry point is the SOC-CMM assessment; the SOC-CMM roadmap turns the matrix into a plan and continuous maturity sustains it quarter after quarter.

  • Single-entity SOC-CMM assessment, the anchor service.
  • Multi-entity SOC-CMM assessment for groups and holdings.
  • Annual maturity re-baseline as a recurring subscription.
  • Express diagnostic as a low-cost entry point.
  • Threat-informed defense: intelligence, hunting, detection and MITRE ATT&CK coverage.

SOC Sourcing & Oversight: who should run your SOC

SOC outsourcing from the buyer's side. We design and score the RFP, assess every MSSP or MDR against the SOC-CMM and help you hold them to it. We advise the buyer, never bid for the contract, and our shortlist never includes group entities. You decide and sign; the contract is direct between buyer and provider. The full process is described in MSSP and MDR selection; when the assessment recommends building instead of buying, talent and people designs the team and the hiring plan.

  • Build-vs-buy strategy and target operating model.
  • RFP design and management with a weighted scorecard.
  • Every provider assessed with SOC-CMM, not with marketing.
  • Support negotiating enforceable SLAs and KPIs.
  • Independent provider performance review, annual.

AI Assurance: are you ready for AI regulation

EU AI Act conformity for high-risk AI and Ley 31814 readiness for Peru with the same methodology. System inventory, Annex III classification, technical evidence, risk management and roadmap. ISO/IEC 42001 preparation is delivered as readiness, not certification. The full scope, frameworks and deliverables are in AI Assurance.

  • AI inventory and Annex III classification as the entry wedge.
  • EU AI Act readiness for high-risk systems.
  • Ley 31814 readiness for Peru and LATAM.
  • ISO/IEC 42001 preparation as readiness, no certificate issued.

How the six services connect

The services are not a loose catalogue: they form a sequence with one decision at the center. The SOC-CMM assessment produces the maturity matrix and answers the opening question: how mature is your SOC, and on what evidence. The SOC-CMM roadmap orders the gaps into a 12-month plan the board can approve and fund. From there, two paths open. If the answer is build, talent and people turns the people domain into an org chart, role profiles and a hiring plan. If the answer is buy, MSSP and MDR selection scores the market from the buyer's side with the same SOC-CMM engine. Continuous maturity keeps the improvement on a quarterly cadence with comparable evidence, and AI Assurance covers the risk that is no longer SOC-only: the AI your organization buys, integrates and deploys.

Where to start

If you have never measured your SOC against the SOC-CMM, start with the express diagnostic or the single-entity assessment: within weeks you have a baseline, a matrix and priorities. If you already have a baseline, the roadmap and the continuous maturity cadence make the diagnostic you already paid for earn its keep. And if your immediate decision is about a provider or AI regulation, MSSP or MDR selection and AI assurance work as independent entry points, with no assessment required first. The same rule applies in every case: a fee paid by the buyer and a signed report your board can read without technical translation.

Why the buyer side matters in MSSP selection

Most firms that assess SOCs also operate one, resell tooling or attach an MDR contract, so they grade a business they are part of. On the assurance brand we operate no SOC and resell no tooling, so the maturity score measures your SOC, not our sales pipeline.

Who publishes the guideTypical conflictPrimedefence position
MSSP or MDR providerWants to win the RFPAdvises the buyer, does not bid
Comparison or directory siteAffiliate and advertisingEvaluation paid for by the buyer
Reseller or VARProvider commissionNo money from the provider side
PrimedefenceNone disclosedScores the candidate with SOC-CMM

Frequently asked questions

Independent by design

Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

Independent SOC-CMM assessment