SOC-CMM methodology: interviews and scoring
How a real SOC-CMM assessment is executed: scope, interviews, evidence, calibration and improvement plan.

1. Scope and context
The assessment starts by defining SOC scope, services, team, dependencies, regulatory pressure and decisions the report must support. Without clear scope, scoring loses executive value.
2. Interviews and evidence
SOC, IT, security, business and service owners are interviewed. Answers are checked against evidence: playbooks, tickets, metrics, rules, reports, escalations and service reviews.
| Block | Participants | Evidence reviewed |
|---|---|---|
| SOC | Head of SOC, analysts, shift leads. | Cases, rules, playbooks, escalations and metrics. |
| IT / Security | Architecture, infrastructure, IAM, networks. | Sources, integrations, changes and technical coverage. |
| Business | CISO, CIO, compliance, service owners. | Risks, reporting, minutes, SLAs and priorities. |
3. Calibrated scoring
The score does not come from one opinion. It is calibrated by domain and aspect, separating real capability, available evidence and dependency risk.
4. Defensible roadmap
Gaps become actions prioritized by risk, cost, dependency and regulatory value. The output separates quick wins from structural initiatives and connects each action to a sponsor, a closure criterion and the board decision it enables.
| Horizon | Action type | Executive output |
|---|---|---|
| 30 days | Quick evidence, reporting or playbook corrections. | Quick wins with owner and closure criteria. |
| 90 days | Operational improvements with limited dependency. | Prioritized work plan and tracking metrics. |
| 180 days | Structural service, process or platform changes. | Investment case and external dependencies. |
| 365 days | Reassessment and continuous improvement governance. | New SOC-CMM matrix and updated roadmap. |
5. Cross calibration
A serious methodology requires scoring to pass through more than one set of eyes. SOC-CMM solves this with cross calibration: the consultant who interviews is not the only one who scores. Each aspect is discussed in an internal calibration session, contrasting the interviewee's answer, the reviewed evidence and the reading compared with prior assessments in the same sector. The 2026 SOC-CMM report shows average self-assessment overestimation of 0.6 points per aspect; without calibration, that gap quietly enters the final report.
6. Deliverables and ownership
The assessment produces a per-domain matrix (Excel or official tool), an executive report, an operational roadmap and an evidence dossier. Intellectual property of the deliverables stays with the client. The consultant keeps only anonymized data for internal benchmarking with explicit permission. This separation, together with operational independence, is what distinguishes a SOC-CMM assessment from a vendor report with a commercial conflict.
- Per-domain SOC-CMM matrix with scoring and per-aspect notes.
- Executive report in actionable language for the board.
- 30/90/180/365 roadmap with sponsor and closure criterion.
- Evidence dossier referencing runbooks, metrics, escalations and minutes.
- Questionnaire version and methodology stated in writing.
7. Typical timelines and client load
A Quick Assessment usually closes in 2-3 weeks with 4-6 key interviews and focused documentary review. A full assessment requires 4-6 weeks, between 12 and 20 interviews and broader per-domain evidence review. Client-side load concentrates on preparing evidence ahead of time: a clear checklist reduces consultant time and improves scoring quality. The 2026 SOC-CMM report confirms insufficient time is the most cited barrier to running assessments (54% of responses), and preparation mitigates it.
Frequently asked questions
Independent by design
Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

