The SOC-CMM model: five domains and two scores
How the SOC-CMM model works: the five domains it assesses, the aspects within, and how it scores maturity and capability on a continuous 0 to 5 scale.

How the model is built
The SOC-CMM assesses a security operations center across five domains: business, people, process, technology and services. Each domain is broken down into aspects (the current model, version 2.4, uses 27 of them), and every aspect is scored individually. The result is a matrix rather than a single number, so strength in one area cannot quietly hide weakness in another. The model is published by soc-cmm.com as a free assessment tool.
The five domains
Splitting the SOC into five domains stops a diagnosis from being biased by a single dimension. Business, people and process are scored for maturity; technology and services are scored for both maturity and capability, because a tool or a service can be well governed yet still cover very little.
| Domain | What it covers | Scored for |
|---|---|---|
| Business | Drivers, customers, charter, governance and privacy | Maturity |
| People | Roles, people management, knowledge and training | Maturity |
| Process | SOC management, operations, reporting, use cases, detection, automation, logging | Maturity |
| Technology | SIEM, log, network and endpoint monitoring, security automation | Maturity and capability |
| Services | Monitoring, incident management, threat intelligence, threat hunting, forensics, vulnerability management | Maturity and capability |
Maturity and capability: two different questions
Maturity asks how well a practice is established and governed; capability asks how much it actually covers. The SOC-CMM keeps them separate for technology and services because conflating them is the classic mistake: a SOC can run a top-tier EDR (high capability) with no documented process around it (low maturity), or a well-governed service that barely covers the relevant threats. Measuring both is what makes the matrix honest, and what lets the same model grade an outsourced MSSP or MDR service from the buyer's side.
How scoring works: continuous 0 to 5
Each aspect is scored on a continuous scale from 0 to 5, derived from established maturity models such as CMMI and ISO/IEC 15504. Continuous scoring (2.4, 2.8) reflects real progress without forcing artificial jumps between staged levels. Per-aspect scores roll up into a per-domain average, and the domains into an overall picture.
| Level | Meaning |
|---|---|
| 0 - Nonexistent | The practice is absent or ad hoc; nothing can be relied on. |
| 1 - Initial | It happens, but informally and dependent on individuals. |
| 2 - Repeatable | Recurring practice exists, but is inconsistent across shifts or services. |
| 3 - Defined | Processes, roles and evidence are documented and followed. |
| 4 - Managed | Effectiveness is measured, reviewed and connected to decisions. |
| 5 - Optimizing | Improvement is continuous, data-led and governed. |
Why a matrix beats a single score
Because domains rarely move together. Technology is usually ahead of people or process; a global average of 2.5 can hide a technology at 4 sitting next to a people at 1, and the key-person dependency that comes with it. The per-domain, per-aspect matrix is what lets an organization invest where the gap creates the most business risk, not where points are easiest to gain.
Variants and the certification model
Alongside the main model, the SOC-CMM project publishes variants for specific contexts: SOC-CMM for CERT/CSIRT for incident-response teams, and SOCTOM for strategic target-operating-model decisions. They complement the main assessment without replacing it. The certification model is a related but stricter view, with five domains and twenty elements, used for the formal certification scheme.
Frequently asked questions
Independent by design
Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.
