SOC-CMM and DORA: resilience evidence and TLPT
How SOC-CMM provides SOC maturity evidence for DORA: ICT risk management, incident reporting and readiness for the Article 26 TLPT, aligned with TIBER-EU.

The SOC angle inside DORA
DORA (Regulation (EU) 2022/2554) applies directly to EU financial entities since 17 January 2025 and, within the financial sector, prevails over NIS2 as lex specialis. The SOC-CMM angle is specific: evidence that the SOC detects, responds, reports and withstands testing with measurable capabilities. The DORA Article 26 deep-dive sets out who must run threat-led penetration tests and on what cycle.
DORA pillars and their SOC-CMM reading
DORA structures digital operational resilience into five blocks. For a SOC the useful exercise is not reciting them but translating each into operational evidence by SOC-CMM domain.
| DORA pillar | What it requires | Primary SOC-CMM domain |
|---|---|---|
| ICT risk management | Governance and control framework for ICT risk under the management body. | Business |
| Incident management and reporting | Severity classification and progressive reports to the financial supervisor. | Services + Process |
| Operational resilience testing | A testing programme and, for designated entities, TLPT every 3 years (Art. 26). | Services + Process |
| ICT third-party risk | Register of information and mandatory contractual clauses with critical providers. | Business + Services |
| Information sharing | Threat intelligence sharing between entities. | Services (CTI) |
Article 26: TLPT every three years
Article 26 requires threat-led penetration testing (TLPT) at least every three years for financial entities designated by their competent authority. It is not a vulnerability scan: it runs against live production systems supporting critical or important functions, covertly to the defenders, and follows TIBER-EU, the ECB framework for intelligence-led red teaming. The exercise closes with a purple-teaming phase where attackers and defenders replay the test together, which is where most of the learning happens.
Article 27: who can run the test
Article 27 sets the bar for testers. External testers must meet independence, certification and insurance requirements. An internal team can run the TLPT only under additional conditions, including authority approval and the mandatory use of an external threat intelligence provider. Significant credit institutions must use external testers.
SOC maturity and TLPT readiness
A TLPT measures real end-to-end detection and response capability, not the presence of vulnerabilities. SOC-CMM scores exactly the aspects a TLPT stresses: detection engineering and use-case management, incident response and threat intelligence. The 2026 SOC-CMM report shows self-assessments overestimate maturity by about 0.6 points and ATT&CK coverage averages near 60%. An independent assessment before the testing cycle gives a realistic picture of whether the SOC will produce signal or silence during the exercise.
| What the TLPT stresses | SOC-CMM domain | Typical evidence |
|---|---|---|
| Detection and use cases | Process + Technology | Detection engineering, log coverage, detection validation. |
| Incident response | Services | Playbooks, escalations, time-stamped post-mortems. |
| Threat intelligence | Services | Actionable CTI, threat modelling, ATT&CK mapping. |
DORA versus NIS2: do not duplicate the work
DORA and NIS2 pursue the same supervised-resilience outcome through different instruments. Because DORA is lex specialis, financial entities are governed by it instead of NIS2 where they overlap. A single controls framework with a regulatory mapping layer avoids running two compliance programmes, and an independent SOC maturity assessment gives both regimes the same evidence base.
Frequently asked questions
Independent by design
Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

