primedefence
SOC-CMM logo

SOC-CMM: the global standard for SOC maturity.

The SOC-CMM is the free, open framework for measuring how mature and capable a security operations center really is. Created by Rob van Os in 2016 and cited by MITRE, the NCSC and ENISA, it is the de facto global standard.

What SOC-CMM is, in one minute

SOC-CMM measures a SOC across five domains and turns the result into a defensible maturity matrix, not a single optimistic number. It is used for self-assessment and, far more reliably, for independent third-party assessment.

It is not a regulation and does not replace NIS2, DORA or ISO 27001. Those define obligations; the SOC-CMM measures the operational capability behind them.

It has been free and open since its first release in 2016, published under a Creative Commons CC BY-SA 4.0 licence, and it scores maturity on a continuous 0 to 5 scale.

Inside the model: five domains, 27 aspects

The SOC-CMM measures a security operations center across these five domains. Every domain breaks down into aspects, each scored on its own. Business, people and process are scored for maturity; technology and services are scored for maturity and capability.

Scored for maturity Scored for maturity and capability

Business

Maturity

Business drivers
Customers
Charter
Governance
Privacy & policy

People

Maturity

Employees
Roles & hierarchy
People management
Knowledge management
Training & education

Process

Maturity

SOC management
Operations & facilities
Reporting
Use case management
Detection engineering

Technology

Maturity + capability

SIEM / UEBA
EDR
NDR
SOAR

Services

Maturity + capability

Security monitoring
Incident management
Security analysis
Threat intelligence
Threat hunting
Vulnerability management
Log management

Independent by origin

The model began as academic research, a Master's thesis at Luleå University of Technology, built with a Design Science Research approach. Because no vendor decides what is measured, the result is not biased toward any stack. That independence is why it is referenced by MITRE, the NCSC and ENISA. And it stays independent in practice: applied by a partner that sells no tooling and operates no SOC, that independence is preserved, so the finding answers to your interest alone.

A magnifying glass over data charts, independent scrutiny of evidence

SOC-CMM, frequently asked

Who created the SOC-CMM?

Rob van Os (MSc). He developed it as a Master's thesis at Lulea University of Technology and released the first model and tool in 2016.

Is the SOC-CMM free to use?

Yes. The assessment model and supporting publications are free and openly available from soc-cmm.com. The project also offers paid professional services: training, advisory support and a formal certification scheme. SOC-CMM is a registered trademark.

Is SOC-CMM the same as NIST, ISO 27001 or CMMI?

No. CMMI contributed the maturity-level idea, and NIST or ISO 27001 define controls and obligations. The SOC-CMM is purpose-built to measure how a SOC operates across five domains. They are complementary, not interchangeable.

What does Primedefence do with the SOC-CMM?

We apply it as an independent assessor and Silver Support Partner: we measure your SOC against the model, produce board- and regulator-ready evidence and a roadmap, and support the readiness path toward formal certification with LRQA as the certifying body. We do not own the standard and we do not sell tooling.

Measure your SOC against the standard.

An independent SOC-CMM assessment, scored across the five domains and ready for your board and your regulator.

Request a SOC-CMM assessment