primedefence

SOC maturity levels explained

How to interpret SOC maturity levels and why a single score is not enough for investment decisions.

Five frosted-glass steps ascending with progressively more saturated blue, from pale to intense

Initial level

Operations depend on specific individuals, informal knowledge and case-by-case reaction. It may work, but it is hard to defend to a board or auditor.

Repeatable level

Recurring practices, some playbooks and basic metrics exist. The main risk is inconsistency across shifts, technologies or services.

Defined and managed level

Processes, services, roles and evidence are defined. The SOC can explain coverage, limits, escalations, KPIs and improvement decisions.

AxisDefined levelManaged level
ProcessesPlaybooks approved and used.Effectiveness measured and reviewed by service.
ServicesSOC catalogue and boundaries are clear.SLAs, KPIs and business reviews are periodic.
PeopleRoles and responsibilities are documented.Coverage, skills and dependency are monitored.
TechnologyCritical sources and rules are identified.Coverage, quality and technical debt are governed.

Optimized level

Continuous improvement is governed. Changes are prioritized by risk, evidence, cost and operational effect, not by pressure or intuition. At this level, the annual reassessment is no longer an isolated event: it is part of the SOC governance rhythm, feeds the board and connects to the budget cycle.

HorizonTypical decisionBoard evidence
30 daysProcess, reporting or coverage quick wins.Prioritized list and owner assigned.
90 daysGap correction with moderate dependency.Metric evolution and risk reduction.
180 daysStructural service or platform changes.Investment, dependency and expected effect.
365 daysContinuous improvement program and reassessment.New SOC-CMM matrix and updated roadmap.

How SOC-CMM scores: continuous 0-5, not steps

SOC-CMM does not assign a single integer between 1 and 5 per domain. Each aspect receives a continuous score between 0 and 5. That reflects real progress without forcing artificial jumps. A SOC that climbs from 2.4 to 2.8 in Process in a quarter has measurable, defensible progress. The per-domain average aggregates aspects; the global average aggregates domains. The 2026 SOC-CMM report publishes international averages around 2.5 Business, 2.3 People, 2.3 Process, 2.7 Technology, 2.2 Services, serving as reference but not automatic target.

Domain2026 international averageRecommended reading
Business2.5Charter, stakeholders and governance: the most underestimated block.
People2.3Roles, training and individual dependency are critical levers.
Process2.3Where measurable operations are won or lost.
Technology2.7Usually the highest domain; does not guarantee global maturity.
Services2.2Incident management, CTI and threat hunting are the hardest aspects.

How long it takes to climb a full level

Moving from level 2 to level 3 usually takes 9-12 months without added marketing. Required investment depends on the domain: raising Technology is often faster if budget is available, while raising People or Process requires cultural and governance change whose timeline is less elastic. Going from 3 to 4 (introducing systematic measurement and review) typically takes another 12-18 months. Going from 4 to 5 (data-governed continuous improvement) requires mature analytical infrastructure and a constant executive sponsor.

Common mistakes when reading levels

First, confusing high scoring with effectiveness. SOC-CMM measures capability and maturity, not detection performance. A level 4 SOC may have poor MTTD if its stack does not cover relevant techniques. Second, treating the global score as a target: the average hides per-domain imbalance. Third, comparing against international averages without adjusting for sector and size. Fourth, assuming the level rises on its own: without reassessment and active governance, maturity can stagnate or even drop after staff or stack changes.

Frequently asked questions

Independent by design

Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

Independent SOC-CMM assessment