SOC-CMM assessment by a verified Silver Support Partner
SOC-CMM v2.4 assessment by a verified Silver Support Partner: maturity matrix, evidence, gaps and a board-defensible roadmap. Independent, no MDR upsell.

Verified Silver Support Partner in the 2026 SOC-CMM report

Primedefence is listed as a Silver Support Partner in the official 2026 SOC-CMM report published by SOC-CMM, with verified support since November 2023. This is not a self-declaration: it can be checked directly in the Silver Support Partners section of the report. Northwave, Group-IB and NVISO appear as peer partners in other categories; we are the only Spanish-speaking consultancy listed at that level.
- Verifiable in the Silver Support Partners section of the 2026 SOC-CMM report.
- LRQA acts as the official certification body for the SOC-CMM programme.
- Security teams at Telefónica, Claro, Alicorp and other listed companies have used our diagnostic.
- Partner status applies to Primedefence as a consultancy; it does not imply automatic certification of the client SOC.
What the assessment includes
Structured interviews, evidence review, domain scoring, executive heatmap, prioritized gaps, 30/90/180/365 roadmap and a stakeholder readout. Final deliverable: a ~60-page executive report, the SOC-CMM v2.4 Excel matrix, a per-domain heatmap and a 90-minute readout with the CISO and sponsor. The 2026 report shows that self-assessments tend to overestimate maturity by an average of 0.6 maturity points compared with third-party assessments; that is why answers must be checked against evidence.
| Phase | What is reviewed | Output |
|---|---|---|
| Scope | SOC, services, geographies, stakeholders and regulatory pressure. | Scope and assessment criteria. |
| Evidence | Charter, metrics, playbooks, sources, roles, services and reports. | Map of sufficient, weak or missing evidence. |
| Scoring | Maturity by domain and aspect, with calibration. | Defensible matrix and heatmap. |
| Roadmap | Gaps, dependencies, quick wins and structural changes. | 30/90/180/365 plan. |
Who it is for
CISOs, SOC leaders, IT leadership and organizations consuming internal or outsourced SOC services that need to defend investment, prepare audit conversations, respond to regulatory pressure or compare maturity against realistic targets.
Independence
We do not sell MDR or operate your SOC. That independence avoids conflict of interest and makes the diagnosis defensible in board, audit and procurement conversations.
SOC-CMM vs Gartner, internal questionnaire and MDR-provided assessment
The most frequent procurement question is not what SOC-CMM is, but why SOC-CMM instead of the alternative the team already has at hand. This table orders the real options so the committee can choose with criteria.
| Feature | SOC-CMM v2.4 | Gartner SOC MM | Internal questionnaire | MDR-provided assessment |
|---|---|---|---|---|
| Public and auditable model | Yes | No (Gartner paywall) | No | No (vendor-proprietary) |
| 5 domains and 27 aspects | Yes | Partial | Variable | Variable |
| Independent from MDR provider | Yes | Yes | No (internal) | No (the vendor) |
| Annual global benchmark | Yes (~200 SOCs in 2026) | Not public | No | No |
| Formal optional certification | Yes (LRQA) | No | No | No |
| Defensible for NIS2, DORA, ISO 27001 | Yes, as evidence of capability | Limited | Not sufficient | Limited |
What a SOC-CMM assessment typically moves in 6 months
Ranges derived from the 2026 SOC-CMM report and Primedefence's assessment practice. These are not guarantees: outcomes depend on executive commitment and on the actual closure of gaps in the roadmap. We publish them because this is what we typically discuss with the committee after the first cycle.
| Metric | Typical starting state | State at roadmap closure |
|---|---|---|
| Reported MITRE ATT&CK coverage | ~45% | ~60% with validation |
| Maturity in Business domain | 1.8 - 2.5 | 2.5 - 3.2 |
| Maturity in Process domain | 2.0 - 2.8 | 2.8 - 3.5 |
| Documented detection evidence | Partial, scattered | Traceable per use case |
| Board reporting | Ad hoc | Cadence, metrics and owners defined |
| Self-assessment bias | +0.6 points above real | Cross-checked against evidence |
Risks the assessment reduces
The 2026 report identifies lack of time (54%), missing evidence (39%), insufficient expertise (34%) and management commitment (32%) as common blockers. An independent assessment does not remove those issues, but it orders them and prevents optimistic scoring without traceability.
- Separate perception from evidence.
- Find strong and weak domains without misleading averages.
- Identify governance, people, process, technology and service gaps.
- Turn findings into budget and improvement decisions.
Frequently asked questions
Independent by design
Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

