SOC-CMM assessment checklist
A practical SOC-CMM assessment checklist with domain evidence, scoping questions and self-assessment risks based on the 2026 report.
What this checklist is for
The 2026 SOC-CMM report shows that a full assessment takes effort and that the main blockers are lack of time —the most cited barrier, 54% of responses—, missing documentation or evidence, insufficient expertise and management commitment. This checklist does not replace SOC-CMM or the methodology: it prepares evidence, reduces fieldwork friction and stops a self-assessment based only on perception from turning into scoring. Used well, it shortens consultant time and improves the quality of the SOC-CMM assessment.
Checklist by SOC-CMM domain
Preparation should cover the five model domains and their aspects. Evidence does not need to be perfect before starting; missing evidence is also a finding. The important distinction is whether evidence is absent, outdated or actually demonstrates operational capability. The SOC maturity model details what each domain measures.
| Domain | Initial evidence | Control question |
|---|---|---|
| Business | Charter, stakeholders, objectives, executive reporting, policies. | Which business decisions does the SOC support? |
| People | RACI, shifts, roles, skills matrix, training, retention. | Does capability depend on specific individuals? |
| Process | Playbooks, use cases, escalation, metrics, post-mortems. | Is the process repeatable and measured? |
| Technology | Sources, rules, coverage, SIEM/EDR/SOAR, technical debt. | Is the tool integrated into real operations? |
| Services | Catalogue, SLAs, incident management, CTI, threat hunting, vulnerabilities. | Does the service have demonstrable scope and quality? |
Who provides each piece of evidence — and who validates it
A checklist without owners stays half-done. Before collecting, assign who provides each block and who validates it, because evidence lives spread across SOC, IT, security, business and compliance. The split follows the same logic as assessment interviews: each block has an interlocutor and a set of verifiable evidence.
| Block | Who provides it | Evidence to gather |
|---|---|---|
| SOC | Head of SOC, analysts, shift leads. | Use cases, rules, playbooks, escalations and operational metrics. |
| IT / Security | Architecture, infrastructure, IAM, networks. | Log sources, integrations, technical coverage and change control. |
| Business / Compliance | CISO, CIO, service owners, compliance. | Charter, risks, SLAs, board reporting and regulatory obligations. |
Questions before assigning a score
The 2026 report again warns about overestimation in self-assessment. Before assigning levels, separate three layers: what people believe happens, what evidence exists and what has been observed in operation. If those layers do not match, the gap should be documented.
- Which model version will be used.
- Which SOC, services and geographies are in scope.
- Which evidence period is valid.
- Who validates SOC, IT, business and compliance answers.
- Which executive decision the report must support.
Evidence map: sufficient, weak, missing or outdated
Before scoring, classify each evidence item. A policy approved three years ago and never used does not carry the same weight as a live incident record. This classification reduces subjective debate during interviews and accelerates the move from diagnosis to roadmap.
| Status | Criterion | Assessment treatment |
|---|---|---|
| Sufficient | Current, traceable and used in operation. | Can support scoring if it matches the assessed aspect. |
| Weak | Exists, but does not cover the full scope or is not applied consistently. | Document as a partial gap. |
| Missing | No document, record or operational observation exists. | Do not replace with opinion; prioritize as a gap. |
| Outdated | Exists, but no longer reflects current people, stack or services. | Should not support scoring without update. |
How evidence translates into a 0-5 score
SOC-CMM does not assign an integer between 1 and 5: each aspect gets a continuous score between 0 and 5, and the per-domain average aggregates aspects. Preparing evidence with this in mind avoids binary have-it-or-not debates: what decides the score is whether evidence is current, used in operation and covers the full scope. The 2026 SOC-CMM report publishes per-domain international averages that serve as reference, not target. How each band is read is explained in SOC maturity levels.
| Domain | 2026 international average | Evidence that supports a higher score |
|---|---|---|
| Business | 2.5 | Approved charter, stakeholders and executive reporting in use. |
| People | 2.3 | Skills matrix, training and coverage without dependency on specific individuals. |
| Process | 2.3 | Applied playbooks, metrics and traceable post-incident reviews. |
| Technology | 2.7 | Integrated sources, maintained rules and governed technical debt. |
| Services | 2.2 | Catalogue with SLAs, incident management, CTI and demonstrable threat hunting. |
Common preparation mistakes
The 2026 SOC-CMM report quantifies the bias to avoid: self-assessments score on average 0.6 points per aspect above third-party assessments. Good preparation narrows that gap; poor preparation widens it. These are the errors that most distort scoring.
- Confusing intent with capability: a policy exists, but nobody applies it in operation.
- Accepting outdated evidence that no longer reflects current people, stack or services.
- Filling gaps with opinion instead of declaring them as a gap.
- Mixing different scopes or evidence periods within a single aspect.
- Scoring high on Technology and assuming global maturity when People or Process lag behind.
Preparation timeline
Preparation is split into short blocks so operations are not paused. A Quick Assessment usually closes in 2-3 weeks and a full assessment in 4-6; internal load concentrates earlier, in gathering evidence. This timeline guides the work before interviews.
| Phase | Activity | Output |
|---|---|---|
| Scope | Set SOC, services, geographies and the decision the report must support. | Scope agreed in writing. |
| Collection | Gather evidence per domain with the assigned owners. | Initial dossier with gaps flagged. |
| Classification | Label each item as sufficient, weak, missing or outdated. | Prioritized list of evidence gaps. |
| Interview prep | Confirm interlocutors and agenda per block. | Interview schedule ready for the assessment. |
Expected output and next step
The checklist is complete when interviews and document review can start with enough context. The assessment output should be a per-domain maturity matrix, prioritized gaps, dependency risks, missing evidence and a SOC-CMM roadmap that can be defended to a board, auditor or customer. That same evidence base later supports the regulatory conversation: NIS2 and DORA reuse the documented SOC maturity instead of demanding parallel work. When improvement becomes continuous, continuous maturity sustains it.
Frequently asked questions
Independent by design
Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

