SOC-CMM certification: levels, process and scheme
SOC-CMM certification: the three levels, the audit process from preparation to certificate, the rules of the scheme and where LRQA and Primedefence fit in.

The certification model
SOC-CMM certification uses a dedicated certification model: five domains and twenty elements, with significant overlap with the assessment model so a SOC can move between them. It differs in two ways. Technology is assessed from a platform perspective, the whole monitoring stack rather than individual tools, and services include threat intelligence as a mandatory component, so a certified SOC can show it understands what it is defending against. The scheme is more prescriptive than the assessment questionnaire.
The three certification levels
Certification is awarded at one of three levels, each building on the one below. They map to the maturity scale of the model, so the level a SOC can reach is a direct reflection of how its operations actually run, not a paperwork exercise.
| Level | Requirement | What it signals |
|---|---|---|
| 1 - Defined | Maturity level 3 across all domains. | A standardized, reliable and repeatable way of working. |
| 2 - Validated | Maturity level 4 across all domains, plus all Defined controls. | Services that are measured and quality-controlled, with validated detection rules. |
| 3 - Risk-driven | All Defined and Validated controls, plus risk-alignment and threat-intelligence controls. | Operations aligned to risk, with threat intelligence integrated into service delivery. |
The certification process
Certification runs as a staged audit. It begins with preparation, moves through a documentation audit and an implementation audit, and ends with independent validation before a certificate is issued and the SOC is listed.
| Stage | What happens |
|---|---|
| 0 - Preparation | The SOC readies itself: self-assessment, gap analysis against the target level and review of the scheme. It can do this alone or with an official support partner. |
| 1 - Documentation audit | An auditor reviews the required documentation against the scheme. If it is complete and of sufficient quality, the process advances. |
| 2 - Implementation audit | The auditor checks that services, processes and procedures actually exist and work, including an on-site visit to verify the SOC's physical environment. |
| Validation and certificate | Findings are validated through the scheme, the certificate is issued and the SOC appears on the certified list. |
The certification scheme
The scheme is the rulebook behind the audit. It defines a total of 127 controls, most derived from the capability and maturity questions of the assessment tool but written more prescriptively. Organizations can scope out specific components following a defined set of rules, but the mandatory part grows with each level: the higher the certification, the less can be excluded. The scheme also lists the documentation an auditor will expect.
Who certifies, and where Primedefence fits
Primedefence is an independent assessor and a SOC-CMM Silver Support Partner. We do not issue the certificate: the formal certification is delivered through the scheme with LRQA as the certifying body. What we do is get you ready. An independent readiness assessment tells you, honestly, which level is realistic, where the documentation and evidence gaps are, and what to fix before an auditor arrives, so you enter the formal process from a position of strength rather than turning predictable gaps into non-conformities.
- A readiness assessment against your target certification level.
- A gap list across the five domains and twenty elements.
- An evidence and documentation dossier organized for the audit.
- A prioritized roadmap to close gaps before the formal audit with LRQA.
Frequently asked questions
Independent by design
Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

