primedefence

SOC-CMM and NIS2: SOC maturity evidence

How SOC-CMM supports SOC capability, gaps and continuous improvement conversations around NIS2 requirements.

Abstract NIS2 architecture rendered in frosted-glass shapes with glowing royal-blue accents on a near-white background

The SOC angle inside NIS2

NIS2 is broad. The SOC-CMM angle is specific: evidencing that the SOC can detect, respond, report and improve with measurable capabilities.

Evidence that usually matters

Playbooks, incident traceability, monitoring coverage, reporting, escalation paths, service reviews and continuous improvement mechanisms.

EvidenceNIS2 readingSOC-CMM use
Playbooks and escalationOrganized response capability.Processes and Services.
Incident traceabilityRecord of decisions and accountability.Technology, Processes and Business.
Executive reportingGovernance and oversight.Business and Services.
Service reviewsDemonstrable continuous improvement.Services and Business.

Operational maturity versus formal compliance

SOC-CMM does not certify legal compliance, but it helps sustain operational conversations with auditors, regulators and boards. For financial entities, DORA adds specific operational-resilience and TLPT obligations that share the same SOC maturity evidence base.

Sectors covered by NIS2

NIS2 distinguishes essential and important entities across 18 sectors. The directive expanded the perimeter substantially compared with NIS1, adding public administration, healthcare, space, food, manufacturing of critical products and digital service providers. The actionable read for a SOC is not the list itself but mapping which supported services fall into each category, because obligations, fines and deadlines differ.

CategoryExample sectorsNIS2 treatment
Essential entitiesEnergy, transport, banking, financial markets, health, water, digital infrastructure, public administration, space.Proactive supervision and higher fines.
Important entitiesPostal services, waste management, chemicals, food, critical manufacturing, digital providers, research.Reactive supervision after incident or complaint.
ExceptionsSmall local public administration, defence and national security per Member State transposition.Verify each Member State's transposition.

Fines and personal liability of management bodies

NIS2 raises fines and, crucially, shifts part of the responsibility to the management body. Essential entities can face administrative fines of up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher. Important entities, up to 7 million euros or 1.4%. In addition, the management body must approve risk management measures, oversee implementation and receive training to understand cyber risk; Member States may temporarily suspend certifications, authorizations or executive responsibilities in cases of repeated non-compliance.

Incident notification deadlines

The directive sets a three-step notification chain with verifiable milestones. The SOC must demonstrate the chain runs with evidence: timestamp, content, escalation, approval. SOC-CMM places that evidence inside Incident management (Services) and Reporting (Process).

MilestoneDeadlineMinimum content
Early warning24 hours from awareness of a significant incidentSuspected malicious cause, cross-border impact, affected scope.
Incident notification72 hours from awarenessInitial severity assessment, impact, indicators of compromise.
Intermediate reportUpon request by CSIRT or authorityResponse status and impact update.
Final report1 month from notificationRoot cause, measures adopted, definitive cross-border impact.

Mapping NIS2 obligations to SOC-CMM domains

Article 21 lists minimum risk-management measures. A serious SOC-CMM assessment ties each obligation to concrete evidence in one or more domains. This table is a starting guide for conversations with auditor or legal counsel.

NIS2 obligation (Art. 21)Primary SOC-CMM domainTypical evidence
Risk analysis and information system security policiesBusinessRisk register, charter, drivers, stakeholders documented.
Incident handlingServicesPlaybooks, records, post-mortems, notification chain.
Business continuity and crisis managementBusiness + ServicesTested BCP/DR plans, RTO/RPO agreed with business.
Supply chain securityBusiness + ServicesCritical vendor inventory, log coverage, contractual clauses.
Security in acquisition and developmentProcess + TechnologySDLC processes, vulnerability management, hardening.
Encryption, cryptography and MFA policiesTechnologyMFA coverage, key management, encrypted transport.
Basic hygiene and cybersecurity trainingPeopleTraining programme, coverage metrics, phishing tests.
Vulnerability managementServicesRemediation SLA by criticality, follow-up evidence.
Effectiveness review of measuresProcess + BusinessSOC-CMM reassessment, continuous improvement metrics.

2026 context worth including in scope

The WEF Global Cybersecurity Outlook 2026 (804 leaders, 92 countries) describes a landscape where 65% of large enterprises name third-party and supply chain risks as the biggest resilience obstacle, up from 54% the prior year. Uneven NIS2 transposition across Member States and geopolitical pressure (91% of the largest companies adjusting cyber posture) make the SOC central to the conversation. A SOC-CMM assessment separates what is already demonstrable from what needs investment, and translates it into actionable language for the board.

NIS2 in Spain: National Security Framework and Royal Decree 311/2022

In Spain, the Esquema Nacional de Seguridad (ENS, Royal Decree 311/2022) has become a practical lever for evidencing many of the obligations NIS2 transposes to the corporate perimeter. CCN-CERT publishes a specific compliance profile for entities in scope of NIS2 that reuses ENS language. For the SOC this changes the assessment conversation: in addition to the SOC-CMM domain scoring, it is worth mapping the ENS technical measures the SOC already supports (monitoring, incident handling, logging) against those that require reinforcement before presenting the matrix to the board or regulator.

Frequently asked questions

Independent by design

Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

Independent SOC-CMM assessment