primedefence

SOC-CMM and DORA: resilience evidence and TLPT

How SOC-CMM provides SOC maturity evidence for DORA: ICT risk management, incident reporting and readiness for the Article 26 TLPT, aligned with TIBER-EU.

Two parallel glass columns with distinct inner lattices joined at the base, the European regulatory frameworks NIS2 and DORA

The SOC angle inside DORA

DORA (Regulation (EU) 2022/2554) applies directly to EU financial entities since 17 January 2025 and, within the financial sector, prevails over NIS2 as lex specialis. The SOC-CMM angle is specific: evidence that the SOC detects, responds, reports and withstands testing with measurable capabilities. The DORA Article 26 deep-dive sets out who must run threat-led penetration tests and on what cycle.

DORA pillars and their SOC-CMM reading

DORA structures digital operational resilience into five blocks. For a SOC the useful exercise is not reciting them but translating each into operational evidence by SOC-CMM domain.

DORA pillarWhat it requiresPrimary SOC-CMM domain
ICT risk managementGovernance and control framework for ICT risk under the management body.Business
Incident management and reportingSeverity classification and progressive reports to the financial supervisor.Services + Process
Operational resilience testingA testing programme and, for designated entities, TLPT every 3 years (Art. 26).Services + Process
ICT third-party riskRegister of information and mandatory contractual clauses with critical providers.Business + Services
Information sharingThreat intelligence sharing between entities.Services (CTI)

Article 26: TLPT every three years

Article 26 requires threat-led penetration testing (TLPT) at least every three years for financial entities designated by their competent authority. It is not a vulnerability scan: it runs against live production systems supporting critical or important functions, covertly to the defenders, and follows TIBER-EU, the ECB framework for intelligence-led red teaming. The exercise closes with a purple-teaming phase where attackers and defenders replay the test together, which is where most of the learning happens.

Article 27: who can run the test

Article 27 sets the bar for testers. External testers must meet independence, certification and insurance requirements. An internal team can run the TLPT only under additional conditions, including authority approval and the mandatory use of an external threat intelligence provider. Significant credit institutions must use external testers.

SOC maturity and TLPT readiness

A TLPT measures real end-to-end detection and response capability, not the presence of vulnerabilities. SOC-CMM scores exactly the aspects a TLPT stresses: detection engineering and use-case management, incident response and threat intelligence. The 2026 SOC-CMM report shows self-assessments overestimate maturity by about 0.6 points and ATT&CK coverage averages near 60%. An independent assessment before the testing cycle gives a realistic picture of whether the SOC will produce signal or silence during the exercise.

What the TLPT stressesSOC-CMM domainTypical evidence
Detection and use casesProcess + TechnologyDetection engineering, log coverage, detection validation.
Incident responseServicesPlaybooks, escalations, time-stamped post-mortems.
Threat intelligenceServicesActionable CTI, threat modelling, ATT&CK mapping.

DORA versus NIS2: do not duplicate the work

DORA and NIS2 pursue the same supervised-resilience outcome through different instruments. Because DORA is lex specialis, financial entities are governed by it instead of NIS2 where they overlap. A single controls framework with a regulatory mapping layer avoids running two compliance programmes, and an independent SOC maturity assessment gives both regimes the same evidence base.

Frequently asked questions

Independent by design

Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

Independent SOC-CMM assessment