primedefence

Independent SOC-CMM consultant

Verifiable professional context for SOC-CMM assessment, SOC maturity and executive evidence conversations with Primedefence.

Public profile

Daute Delgado is CEO and co-founder of Primedefence, with more than a decade in security operations for airlines, managed SOCs and international organizations. Annalisa Battistelli, CTO, comes from threat analysis at Malwarebytes and international CSIRT operations. Both maintain public LinkedIn profiles. Primedefence has been a SOC-CMM Silver Support Partner since November 2023 and is listed as such in the official SOC Maturity Report 2026. Both facts can be checked at soc-cmm.com and on the author profile. This page exists so a CISO, a procurement lead or an auditor can verify who signs the assessment before the first call.

What independence means in practice

Independence is not an adjective: it is a list of conditions you can verify. The assessor does not operate the SOC being assessed, does not compete for the operating contract and earns the same whether the score goes up or down. The report says the same thing at a 1.8 as at a 3.2; that is the difference between a diagnosis and a sales proposal dressed up as one.

  • Fixed fee paid by the client, with no incentives tied to the result.
  • No role in operating the assessed SOC and no stake in the MDR contract.
  • Every score traces back to a concrete, verifiable piece of evidence.
  • Conflicts of interest disclosed in writing before scope opens.

Why assessor quality changes the score

The most cited figure in the SOC Maturity Report 2026, SOC-CMM®: self-assessments score on average 0.6 maturity points higher than assessments performed by third parties. On a 0-5 scale, that difference separates a defensible matrix from one that collapses under an auditor's questions. An external assessor with operational experience calibrates every answer against evidence, separates documented capability from declared intent and applies the same standard across all five domains. The methodology publishes step by step how that calibration works.

Conversation areas

The fit is SOC maturity, evidence, dependencies, roadmap and preparation for board, audit or regulator conversations. The usual starting point is a SOC-CMM assessment with a scope agreed in writing.

  • SOC-CMM assessment and reasonable scope.
  • Evidence that supports scoring.
  • 30/90/180/365-day roadmap.
  • Independent diagnosis versus MDR operations.

Engagement models

Useful consulting starts by choosing the right format, not the biggest one. These are the four usual models, from lowest to highest commitment. All of them end in a signed report your board can read without technical translation.

ModelFor whomOutcome
Express diagnosticBuyers who need a fast first reading.Initial maturity reading and next steps.
Full SOC-CMM assessmentSingle entity under board or regulator pressure.Per-domain, per-aspect matrix with evidence.
Multi-entity assessmentGroups, holdings and providers with several SOCs.Comparable matrices across entities.
Continuous maturitySOCs with a baseline that must sustain improvement.Quarterly cadence of evidence and committee.

How to verify a SOC-CMM consultant

Before hiring a SOC-CMM consultant, verify them with the same rigor they will apply to your SOC. Five checks are enough and none takes more than an hour.

  • Experience: ask for the assessor's operational track record in SOC or CSIRT work and which assessments they have signed, not a generic mention of experience.
  • Partnership: check the public partner listing at soc-cmm.com.
  • Methodology: request the scoring method in writing before signing.
  • Signature: confirm who runs the interviews and who signs the report; they are not always the same person.
  • Conflicts: ask whether the firm operates SOCs or competes for the operating contract, and get the answer in writing.

Independence standard

Primedefence can state its Silver Support Partner status, but does not use this page to promise client certifications or unverifiable outcomes. If procurement requires a specific formal condition, it is clarified before scope starts.

Frequently asked questions

Independent by design

Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

Independent SOC-CMM assessment