primedefence

SOC-CMM assessment by a verified Silver Support Partner

SOC-CMM v2.4 assessment by a verified Silver Support Partner: maturity matrix, evidence, gaps and a board-defensible roadmap. Independent, no MDR upsell.

Large circular glass lens hovering over a grid of small nodes, with the nodes under the lens enlarged and glowing blue

Verified Silver Support Partner in the 2026 SOC-CMM report

SOC-CMM Silver Support Partner

Primedefence is listed as a Silver Support Partner in the official 2026 SOC-CMM report published by SOC-CMM, with verified support since November 2023. This is not a self-declaration: it can be checked directly in the Silver Support Partners section of the report. Northwave, Group-IB and NVISO appear as peer partners in other categories; we are the only Spanish-speaking consultancy listed at that level.

  • Verifiable in the Silver Support Partners section of the 2026 SOC-CMM report.
  • LRQA acts as the official certification body for the SOC-CMM programme.
  • Security teams at Telefónica, Claro, Alicorp and other listed companies have used our diagnostic.
  • Partner status applies to Primedefence as a consultancy; it does not imply automatic certification of the client SOC.

What the assessment includes

Structured interviews, evidence review, domain scoring, executive heatmap, prioritized gaps, 30/90/180/365 roadmap and a stakeholder readout. Final deliverable: a ~60-page executive report, the SOC-CMM v2.4 Excel matrix, a per-domain heatmap and a 90-minute readout with the CISO and sponsor. The 2026 report shows that self-assessments tend to overestimate maturity by an average of 0.6 maturity points compared with third-party assessments; that is why answers must be checked against evidence.

PhaseWhat is reviewedOutput
ScopeSOC, services, geographies, stakeholders and regulatory pressure.Scope and assessment criteria.
EvidenceCharter, metrics, playbooks, sources, roles, services and reports.Map of sufficient, weak or missing evidence.
ScoringMaturity by domain and aspect, with calibration.Defensible matrix and heatmap.
RoadmapGaps, dependencies, quick wins and structural changes.30/90/180/365 plan.

Who it is for

CISOs, SOC leaders, IT leadership and organizations consuming internal or outsourced SOC services that need to defend investment, prepare audit conversations, respond to regulatory pressure or compare maturity against realistic targets.

Independence

We do not sell MDR or operate your SOC. That independence avoids conflict of interest and makes the diagnosis defensible in board, audit and procurement conversations.

SOC-CMM vs Gartner, internal questionnaire and MDR-provided assessment

The most frequent procurement question is not what SOC-CMM is, but why SOC-CMM instead of the alternative the team already has at hand. This table orders the real options so the committee can choose with criteria.

FeatureSOC-CMM v2.4Gartner SOC MMInternal questionnaireMDR-provided assessment
Public and auditable modelYesNo (Gartner paywall)NoNo (vendor-proprietary)
5 domains and 27 aspectsYesPartialVariableVariable
Independent from MDR providerYesYesNo (internal)No (the vendor)
Annual global benchmarkYes (~200 SOCs in 2026)Not publicNoNo
Formal optional certificationYes (LRQA)NoNoNo
Defensible for NIS2, DORA, ISO 27001Yes, as evidence of capabilityLimitedNot sufficientLimited

What a SOC-CMM assessment typically moves in 6 months

Ranges derived from the 2026 SOC-CMM report and Primedefence's assessment practice. These are not guarantees: outcomes depend on executive commitment and on the actual closure of gaps in the roadmap. We publish them because this is what we typically discuss with the committee after the first cycle.

MetricTypical starting stateState at roadmap closure
Reported MITRE ATT&CK coverage~45%~60% with validation
Maturity in Business domain1.8 - 2.52.5 - 3.2
Maturity in Process domain2.0 - 2.82.8 - 3.5
Documented detection evidencePartial, scatteredTraceable per use case
Board reportingAd hocCadence, metrics and owners defined
Self-assessment bias+0.6 points above realCross-checked against evidence

Risks the assessment reduces

The 2026 report identifies lack of time (54%), missing evidence (39%), insufficient expertise (34%) and management commitment (32%) as common blockers. An independent assessment does not remove those issues, but it orders them and prevents optimistic scoring without traceability.

  • Separate perception from evidence.
  • Find strong and weak domains without misleading averages.
  • Identify governance, people, process, technology and service gaps.
  • Turn findings into budget and improvement decisions.

Frequently asked questions

Independent by design

Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

Independent SOC-CMM assessment