
SOC-CMM: the global standard for SOC maturity.
The SOC-CMM is the free, open framework for measuring how mature and capable a security operations center really is. Created by Rob van Os in 2016 and cited by MITRE, the NCSC and ENISA, it is the de facto global standard.
What SOC-CMM is, in one minute
SOC-CMM measures a SOC across five domains and turns the result into a defensible maturity matrix, not a single optimistic number. It is used for self-assessment and, far more reliably, for independent third-party assessment.
It is not a regulation and does not replace NIS2, DORA or ISO 27001. Those define obligations; the SOC-CMM measures the operational capability behind them.
It has been free and open since its first release in 2016, published under a Creative Commons CC BY-SA 4.0 licence, and it scores maturity on a continuous 0 to 5 scale.
Inside the model: five domains, 27 aspects
The SOC-CMM measures a security operations center across these five domains. Every domain breaks down into aspects, each scored on its own. Business, people and process are scored for maturity; technology and services are scored for maturity and capability.
Business
Maturity
People
Maturity
Process
Maturity
Technology
Maturity + capability
Services
Maturity + capability
Independent by origin
The model began as academic research, a Master's thesis at Luleå University of Technology, built with a Design Science Research approach. Because no vendor decides what is measured, the result is not biased toward any stack. That independence is why it is referenced by MITRE, the NCSC and ENISA. And it stays independent in practice: applied by a partner that sells no tooling and operates no SOC, that independence is preserved, so the finding answers to your interest alone.

Go deeper
What is the SOC-CMM
The plain-language answer: scope, the five domains and what an assessment yields.
The SOC-CMM model
Domains, aspects, and how maturity and capability are scored 0 to 5.
SOC-CMM certification
The three levels, the audit process and the certification scheme.
SOC statistics 2026
Benchmarks from the SOC Maturity Report 2026: regions, domains, AI and budget.
Request an assessment
An independent SOC-CMM assessment, scored and board-ready.
SOC-CMM, frequently asked
Who created the SOC-CMM?
Rob van Os (MSc). He developed it as a Master's thesis at Lulea University of Technology and released the first model and tool in 2016.
Is the SOC-CMM free to use?
Yes. The assessment model and supporting publications are free and openly available from soc-cmm.com. The project also offers paid professional services: training, advisory support and a formal certification scheme. SOC-CMM is a registered trademark.
Is SOC-CMM the same as NIST, ISO 27001 or CMMI?
No. CMMI contributed the maturity-level idea, and NIST or ISO 27001 define controls and obligations. The SOC-CMM is purpose-built to measure how a SOC operates across five domains. They are complementary, not interchangeable.
What does Primedefence do with the SOC-CMM?
We apply it as an independent assessor and Silver Support Partner: we measure your SOC against the model, produce board- and regulator-ready evidence and a roadmap, and support the readiness path toward formal certification with LRQA as the certifying body. We do not own the standard and we do not sell tooling.
Measure your SOC against the standard.
An independent SOC-CMM assessment, scored across the five domains and ready for your board and your regulator.
