SOC maturity levels explained
How to interpret SOC maturity levels and why a single score is not enough for investment decisions.

Initial level
Operations depend on specific individuals, informal knowledge and case-by-case reaction. It may work, but it is hard to defend to a board or auditor.
Repeatable level
Recurring practices, some playbooks and basic metrics exist. The main risk is inconsistency across shifts, technologies or services.
Defined and managed level
Processes, services, roles and evidence are defined. The SOC can explain coverage, limits, escalations, KPIs and improvement decisions.
| Axis | Defined level | Managed level |
|---|---|---|
| Processes | Playbooks approved and used. | Effectiveness measured and reviewed by service. |
| Services | SOC catalogue and boundaries are clear. | SLAs, KPIs and business reviews are periodic. |
| People | Roles and responsibilities are documented. | Coverage, skills and dependency are monitored. |
| Technology | Critical sources and rules are identified. | Coverage, quality and technical debt are governed. |
Optimized level
Continuous improvement is governed. Changes are prioritized by risk, evidence, cost and operational effect, not by pressure or intuition. At this level, the annual reassessment is no longer an isolated event: it is part of the SOC governance rhythm, feeds the board and connects to the budget cycle.
| Horizon | Typical decision | Board evidence |
|---|---|---|
| 30 days | Process, reporting or coverage quick wins. | Prioritized list and owner assigned. |
| 90 days | Gap correction with moderate dependency. | Metric evolution and risk reduction. |
| 180 days | Structural service or platform changes. | Investment, dependency and expected effect. |
| 365 days | Continuous improvement program and reassessment. | New SOC-CMM matrix and updated roadmap. |
How SOC-CMM scores: continuous 0-5, not steps
SOC-CMM does not assign a single integer between 1 and 5 per domain. Each aspect receives a continuous score between 0 and 5. That reflects real progress without forcing artificial jumps. A SOC that climbs from 2.4 to 2.8 in Process in a quarter has measurable, defensible progress. The per-domain average aggregates aspects; the global average aggregates domains. The 2026 SOC-CMM report publishes international averages around 2.5 Business, 2.3 People, 2.3 Process, 2.7 Technology, 2.2 Services, serving as reference but not automatic target.
| Domain | 2026 international average | Recommended reading |
|---|---|---|
| Business | 2.5 | Charter, stakeholders and governance: the most underestimated block. |
| People | 2.3 | Roles, training and individual dependency are critical levers. |
| Process | 2.3 | Where measurable operations are won or lost. |
| Technology | 2.7 | Usually the highest domain; does not guarantee global maturity. |
| Services | 2.2 | Incident management, CTI and threat hunting are the hardest aspects. |
How long it takes to climb a full level
Moving from level 2 to level 3 usually takes 9-12 months without added marketing. Required investment depends on the domain: raising Technology is often faster if budget is available, while raising People or Process requires cultural and governance change whose timeline is less elastic. Going from 3 to 4 (introducing systematic measurement and review) typically takes another 12-18 months. Going from 4 to 5 (data-governed continuous improvement) requires mature analytical infrastructure and a constant executive sponsor.
Common mistakes when reading levels
First, confusing high scoring with effectiveness. SOC-CMM measures capability and maturity, not detection performance. A level 4 SOC may have poor MTTD if its stack does not cover relevant techniques. Second, treating the global score as a target: the average hides per-domain imbalance. Third, comparing against international averages without adjusting for sector and size. Fourth, assuming the level rises on its own: without reassessment and active governance, maturity can stagnate or even drop after staff or stack changes.
Frequently asked questions
Independent by design
Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

