Independent MSSP and MDR selection
Independent MSSP and MDR selection on the buyer side: we score the market with the same SOC-CMM engine as our assessments and never bid for the contract.

Three formats
We pick the format by size and urgency, from a full formal process to a recurring review of the provider you already have.
| Format | For whom | What it includes |
|---|---|---|
| Full RFP | Regulated or large buyer | Formal eight-phase process, from requirements to award |
| Lighter advisory | Mid-market | Shortlist and structured evaluation, no formal RFP |
| Performance review | Buyers with a provider | Periodic re-scoring of the provider against the SLAs |
How we score
We apply the SOC-CMM engine to the provider: coverage, detection, response, reporting and fit with your regulatory context. The result is a defensible comparison, not a preference.
- Requirements and weighted criteria set with your team
- Consistent evaluation of every candidate
- Traceable comparison for procurement and the board
- A reasoned recommendation, with its risks
Why buyer-side
We advise the buyer and never bid for the contract. Our shortlist takes no money from any provider, so the recommendation answers to your interest and your context, not ours.
What the 2026 report says about MSSPs
The SOC Maturity Report 2026, SOC-CMM® offers a figure every buyer should read carefully: MSSP SOCs are the most mature SOC type in the study, and all of them use analyst tiering. The optimistic reading is that outsourcing can buy real operational maturity. The prudent reading is that an average hides variance: the category does not protect you, the specific provider that signs does. That is why we score every candidate with the same SOC-CMM engine we use in every assessment, and ask for independent validation evidence, now the emerging differentiator between providers competing on maturity rather than price alone.
NIS2 drives outsourcing, not accountability
The NIS2 directive widens the regulated perimeter in Europe and pushes many essential and important entities to cover detection and response through an MSSP or an MDR. What the directive does not let you outsource is accountability: the management body still answers for risk-management measures, on-time notifications and provider oversight. Choosing well is the first obligation; checking the contract is honored, the second. If you are still comparing service models, the MSSP vs MDR vs SOC-as-a-Service comparison breaks down what each contract actually covers.
The recurring review
Once the provider is chosen, we periodically re-score whether it delivers against the SLAs. It is the part that keeps the provider accountable and your board informed.
The selection process, phase by phase
The full RFP runs in eight phases. Each leaves a deliverable, so procurement and the board can follow and defend the decision.
| Phase | What happens |
|---|---|
| 1. Scope | Need, regulatory context and success criteria |
| 2. Requirements | Functional and service requirements, weighted with your team |
| 3. Market | A long list of candidate providers |
| 4. RFP | A brief and questions aligned to the SOC-CMM engine |
| 5. Evaluation | Consistent scoring of every response |
| 6. Demonstrations | Tests and validation of claims |
| 7. Short list | A traceable comparison and due diligence |
| 8. Recommendation | A reasoned recommendation, with its risks |
Who it is for
Buyers about to outsource detection and response who want to choose well, and buyers who already have a provider and need to check it delivers. Finance, insurance, healthcare, public sector and multi-entity groups.
Frequently asked questions
Independent by design
Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

