primedefence

SOC-CMM assessment checklist

A practical SOC-CMM assessment checklist with domain evidence, scoping questions and self-assessment risks based on the 2026 report.

What this checklist is for

The 2026 SOC-CMM report shows that a full assessment takes effort and that the main blockers are lack of time —the most cited barrier, 54% of responses—, missing documentation or evidence, insufficient expertise and management commitment. This checklist does not replace SOC-CMM or the methodology: it prepares evidence, reduces fieldwork friction and stops a self-assessment based only on perception from turning into scoring. Used well, it shortens consultant time and improves the quality of the SOC-CMM assessment.

Checklist by SOC-CMM domain

Preparation should cover the five model domains and their aspects. Evidence does not need to be perfect before starting; missing evidence is also a finding. The important distinction is whether evidence is absent, outdated or actually demonstrates operational capability. The SOC maturity model details what each domain measures.

DomainInitial evidenceControl question
BusinessCharter, stakeholders, objectives, executive reporting, policies.Which business decisions does the SOC support?
PeopleRACI, shifts, roles, skills matrix, training, retention.Does capability depend on specific individuals?
ProcessPlaybooks, use cases, escalation, metrics, post-mortems.Is the process repeatable and measured?
TechnologySources, rules, coverage, SIEM/EDR/SOAR, technical debt.Is the tool integrated into real operations?
ServicesCatalogue, SLAs, incident management, CTI, threat hunting, vulnerabilities.Does the service have demonstrable scope and quality?

Who provides each piece of evidence — and who validates it

A checklist without owners stays half-done. Before collecting, assign who provides each block and who validates it, because evidence lives spread across SOC, IT, security, business and compliance. The split follows the same logic as assessment interviews: each block has an interlocutor and a set of verifiable evidence.

BlockWho provides itEvidence to gather
SOCHead of SOC, analysts, shift leads.Use cases, rules, playbooks, escalations and operational metrics.
IT / SecurityArchitecture, infrastructure, IAM, networks.Log sources, integrations, technical coverage and change control.
Business / ComplianceCISO, CIO, service owners, compliance.Charter, risks, SLAs, board reporting and regulatory obligations.

Questions before assigning a score

The 2026 report again warns about overestimation in self-assessment. Before assigning levels, separate three layers: what people believe happens, what evidence exists and what has been observed in operation. If those layers do not match, the gap should be documented.

  • Which model version will be used.
  • Which SOC, services and geographies are in scope.
  • Which evidence period is valid.
  • Who validates SOC, IT, business and compliance answers.
  • Which executive decision the report must support.

Evidence map: sufficient, weak, missing or outdated

Before scoring, classify each evidence item. A policy approved three years ago and never used does not carry the same weight as a live incident record. This classification reduces subjective debate during interviews and accelerates the move from diagnosis to roadmap.

StatusCriterionAssessment treatment
SufficientCurrent, traceable and used in operation.Can support scoring if it matches the assessed aspect.
WeakExists, but does not cover the full scope or is not applied consistently.Document as a partial gap.
MissingNo document, record or operational observation exists.Do not replace with opinion; prioritize as a gap.
OutdatedExists, but no longer reflects current people, stack or services.Should not support scoring without update.

How evidence translates into a 0-5 score

SOC-CMM does not assign an integer between 1 and 5: each aspect gets a continuous score between 0 and 5, and the per-domain average aggregates aspects. Preparing evidence with this in mind avoids binary have-it-or-not debates: what decides the score is whether evidence is current, used in operation and covers the full scope. The 2026 SOC-CMM report publishes per-domain international averages that serve as reference, not target. How each band is read is explained in SOC maturity levels.

Domain2026 international averageEvidence that supports a higher score
Business2.5Approved charter, stakeholders and executive reporting in use.
People2.3Skills matrix, training and coverage without dependency on specific individuals.
Process2.3Applied playbooks, metrics and traceable post-incident reviews.
Technology2.7Integrated sources, maintained rules and governed technical debt.
Services2.2Catalogue with SLAs, incident management, CTI and demonstrable threat hunting.

Common preparation mistakes

The 2026 SOC-CMM report quantifies the bias to avoid: self-assessments score on average 0.6 points per aspect above third-party assessments. Good preparation narrows that gap; poor preparation widens it. These are the errors that most distort scoring.

  • Confusing intent with capability: a policy exists, but nobody applies it in operation.
  • Accepting outdated evidence that no longer reflects current people, stack or services.
  • Filling gaps with opinion instead of declaring them as a gap.
  • Mixing different scopes or evidence periods within a single aspect.
  • Scoring high on Technology and assuming global maturity when People or Process lag behind.

Preparation timeline

Preparation is split into short blocks so operations are not paused. A Quick Assessment usually closes in 2-3 weeks and a full assessment in 4-6; internal load concentrates earlier, in gathering evidence. This timeline guides the work before interviews.

PhaseActivityOutput
ScopeSet SOC, services, geographies and the decision the report must support.Scope agreed in writing.
CollectionGather evidence per domain with the assigned owners.Initial dossier with gaps flagged.
ClassificationLabel each item as sufficient, weak, missing or outdated.Prioritized list of evidence gaps.
Interview prepConfirm interlocutors and agenda per block.Interview schedule ready for the assessment.

Expected output and next step

The checklist is complete when interviews and document review can start with enough context. The assessment output should be a per-domain maturity matrix, prioritized gaps, dependency risks, missing evidence and a SOC-CMM roadmap that can be defended to a board, auditor or customer. That same evidence base later supports the regulatory conversation: NIS2 and DORA reuse the documented SOC maturity instead of demanding parallel work. When improvement becomes continuous, continuous maturity sustains it.

Frequently asked questions

Independent by design

Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

Independent SOC-CMM assessment