primedefence

Independent MSSP and MDR selection

Independent MSSP and MDR selection on the buyer side: we score the market with the same SOC-CMM engine as our assessments and never bid for the contract.

Independent buyer-side MSSP and MDR selection scored with the SOC-CMM engine

Three formats

We pick the format by size and urgency, from a full formal process to a recurring review of the provider you already have.

FormatFor whomWhat it includes
Full RFPRegulated or large buyerFormal eight-phase process, from requirements to award
Lighter advisoryMid-marketShortlist and structured evaluation, no formal RFP
Performance reviewBuyers with a providerPeriodic re-scoring of the provider against the SLAs

How we score

We apply the SOC-CMM engine to the provider: coverage, detection, response, reporting and fit with your regulatory context. The result is a defensible comparison, not a preference.

  • Requirements and weighted criteria set with your team
  • Consistent evaluation of every candidate
  • Traceable comparison for procurement and the board
  • A reasoned recommendation, with its risks

Why buyer-side

We advise the buyer and never bid for the contract. Our shortlist takes no money from any provider, so the recommendation answers to your interest and your context, not ours.

What the 2026 report says about MSSPs

The SOC Maturity Report 2026, SOC-CMM® offers a figure every buyer should read carefully: MSSP SOCs are the most mature SOC type in the study, and all of them use analyst tiering. The optimistic reading is that outsourcing can buy real operational maturity. The prudent reading is that an average hides variance: the category does not protect you, the specific provider that signs does. That is why we score every candidate with the same SOC-CMM engine we use in every assessment, and ask for independent validation evidence, now the emerging differentiator between providers competing on maturity rather than price alone.

NIS2 drives outsourcing, not accountability

The NIS2 directive widens the regulated perimeter in Europe and pushes many essential and important entities to cover detection and response through an MSSP or an MDR. What the directive does not let you outsource is accountability: the management body still answers for risk-management measures, on-time notifications and provider oversight. Choosing well is the first obligation; checking the contract is honored, the second. If you are still comparing service models, the MSSP vs MDR vs SOC-as-a-Service comparison breaks down what each contract actually covers.

The recurring review

Once the provider is chosen, we periodically re-score whether it delivers against the SLAs. It is the part that keeps the provider accountable and your board informed.

The selection process, phase by phase

The full RFP runs in eight phases. Each leaves a deliverable, so procurement and the board can follow and defend the decision.

PhaseWhat happens
1. ScopeNeed, regulatory context and success criteria
2. RequirementsFunctional and service requirements, weighted with your team
3. MarketA long list of candidate providers
4. RFPA brief and questions aligned to the SOC-CMM engine
5. EvaluationConsistent scoring of every response
6. DemonstrationsTests and validation of claims
7. Short listA traceable comparison and due diligence
8. RecommendationA reasoned recommendation, with its risks

Who it is for

Buyers about to outsource detection and response who want to choose well, and buyers who already have a provider and need to check it delivers. Finance, insurance, healthcare, public sector and multi-entity groups.

Frequently asked questions

Independent by design

Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

Independent SOC-CMM assessment