MITRE ATT&CK coverage in the SOC
How to use MITRE ATT&CK in a SOC-CMM assessment: coverage, detection validation, threat modelling and operational evidence from the 2026 report.

ATT&CK coverage is growing, but coverage is not enough
The 2026 SOC-CMM report shows a clear increase in MITRE ATT&CK coverage: the average rises from 45% to 60%. That improvement matters, but the report also cautions that coverage must be compared with targets and context. A high percentage does not prove the SOC detects real threats, and not every framework technique is relevant or technically observable for every organization.
What an assessment should review
ATT&CK is useful for threat modelling, detection engineering and defensive gap analysis. In SOC-CMM, maturity appears when the map is connected to data sources, use cases, validation, operations and continuous improvement.
| Element | Expected evidence | Common error |
|---|---|---|
| Coverage | Relevant technique matrix, target and status. | Counting techniques without defining relevance. |
| Telemetry | Data sources that make behavior observable. | Marking coverage without enough data. |
| Detections | Rules, logic, owner and review cycle. | Creating rules nobody maintains. |
| Validation | Pre-production tests, purple teaming or event generation. | Assuming a rule works because it exists. |
Detection validation is the bridge
The report treats detection validation as an activity that creates operational trust in detection capability. It can include pre-production tests, exercises, simulation, purple teaming, event injection or ingestion monitoring. The mature question is not how many rules exist, but which ones have been tested and under what conditions.
Improvement roadmap
A defensible roadmap prioritizes techniques by risk, exposure, available sources and operational value. It also separates telemetry gaps, logic gaps, validation gaps and process gaps. This prevents ATT&CK from becoming a decorative table.
- Define relevant techniques by threat and critical service.
- Map data sources and ingestion quality.
- Prioritize detections by risk and feasibility.
- Validate rules with controlled tests.
- Review coverage as part of the SOC improvement cycle.
Minimum telemetry required to claim coverage
A technique is not covered just because a rule has its tag. There must be a source observing the behavior, maintained logic, an owner, a test and a review criterion. Without that chain, ATT&CK describes intent, not operational capability.
| Layer | Control question | Typical gap |
|---|---|---|
| Source | Do we have enough data to observe the technique? | Logs not enabled or insufficient retention. |
| Logic | Does detection identify behavior, not only brittle indicators? | Rules copied without environment adaptation. |
| Validation | Was it tested with real, simulated or purple-team events? | Coverage claimed without testing. |
| Operation | Does the analyst know triage, severity and response? | Detection without runbook or handover. |
Frequently asked questions
Independent by design
Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

