SOC-CMM and NIS2: SOC maturity evidence
How SOC-CMM supports SOC capability, gaps and continuous improvement conversations around NIS2 requirements.

The SOC angle inside NIS2
NIS2 is broad. The SOC-CMM angle is specific: evidencing that the SOC can detect, respond, report and improve with measurable capabilities.
Evidence that usually matters
Playbooks, incident traceability, monitoring coverage, reporting, escalation paths, service reviews and continuous improvement mechanisms.
| Evidence | NIS2 reading | SOC-CMM use |
|---|---|---|
| Playbooks and escalation | Organized response capability. | Processes and Services. |
| Incident traceability | Record of decisions and accountability. | Technology, Processes and Business. |
| Executive reporting | Governance and oversight. | Business and Services. |
| Service reviews | Demonstrable continuous improvement. | Services and Business. |
Operational maturity versus formal compliance
SOC-CMM does not certify legal compliance, but it helps sustain operational conversations with auditors, regulators and boards. For financial entities, DORA adds specific operational-resilience and TLPT obligations that share the same SOC maturity evidence base.
Sectors covered by NIS2
NIS2 distinguishes essential and important entities across 18 sectors. The directive expanded the perimeter substantially compared with NIS1, adding public administration, healthcare, space, food, manufacturing of critical products and digital service providers. The actionable read for a SOC is not the list itself but mapping which supported services fall into each category, because obligations, fines and deadlines differ.
| Category | Example sectors | NIS2 treatment |
|---|---|---|
| Essential entities | Energy, transport, banking, financial markets, health, water, digital infrastructure, public administration, space. | Proactive supervision and higher fines. |
| Important entities | Postal services, waste management, chemicals, food, critical manufacturing, digital providers, research. | Reactive supervision after incident or complaint. |
| Exceptions | Small local public administration, defence and national security per Member State transposition. | Verify each Member State's transposition. |
Fines and personal liability of management bodies
NIS2 raises fines and, crucially, shifts part of the responsibility to the management body. Essential entities can face administrative fines of up to 10 million euros or 2% of total worldwide annual turnover, whichever is higher. Important entities, up to 7 million euros or 1.4%. In addition, the management body must approve risk management measures, oversee implementation and receive training to understand cyber risk; Member States may temporarily suspend certifications, authorizations or executive responsibilities in cases of repeated non-compliance.
Incident notification deadlines
The directive sets a three-step notification chain with verifiable milestones. The SOC must demonstrate the chain runs with evidence: timestamp, content, escalation, approval. SOC-CMM places that evidence inside Incident management (Services) and Reporting (Process).
| Milestone | Deadline | Minimum content |
|---|---|---|
| Early warning | 24 hours from awareness of a significant incident | Suspected malicious cause, cross-border impact, affected scope. |
| Incident notification | 72 hours from awareness | Initial severity assessment, impact, indicators of compromise. |
| Intermediate report | Upon request by CSIRT or authority | Response status and impact update. |
| Final report | 1 month from notification | Root cause, measures adopted, definitive cross-border impact. |
Mapping NIS2 obligations to SOC-CMM domains
Article 21 lists minimum risk-management measures. A serious SOC-CMM assessment ties each obligation to concrete evidence in one or more domains. This table is a starting guide for conversations with auditor or legal counsel.
| NIS2 obligation (Art. 21) | Primary SOC-CMM domain | Typical evidence |
|---|---|---|
| Risk analysis and information system security policies | Business | Risk register, charter, drivers, stakeholders documented. |
| Incident handling | Services | Playbooks, records, post-mortems, notification chain. |
| Business continuity and crisis management | Business + Services | Tested BCP/DR plans, RTO/RPO agreed with business. |
| Supply chain security | Business + Services | Critical vendor inventory, log coverage, contractual clauses. |
| Security in acquisition and development | Process + Technology | SDLC processes, vulnerability management, hardening. |
| Encryption, cryptography and MFA policies | Technology | MFA coverage, key management, encrypted transport. |
| Basic hygiene and cybersecurity training | People | Training programme, coverage metrics, phishing tests. |
| Vulnerability management | Services | Remediation SLA by criticality, follow-up evidence. |
| Effectiveness review of measures | Process + Business | SOC-CMM reassessment, continuous improvement metrics. |
2026 context worth including in scope
The WEF Global Cybersecurity Outlook 2026 (804 leaders, 92 countries) describes a landscape where 65% of large enterprises name third-party and supply chain risks as the biggest resilience obstacle, up from 54% the prior year. Uneven NIS2 transposition across Member States and geopolitical pressure (91% of the largest companies adjusting cyber posture) make the SOC central to the conversation. A SOC-CMM assessment separates what is already demonstrable from what needs investment, and translates it into actionable language for the board.
NIS2 in Spain: National Security Framework and Royal Decree 311/2022
In Spain, the Esquema Nacional de Seguridad (ENS, Royal Decree 311/2022) has become a practical lever for evidencing many of the obligations NIS2 transposes to the corporate perimeter. CCN-CERT publishes a specific compliance profile for entities in scope of NIS2 that reuses ENS language. For the SOC this changes the assessment conversation: in addition to the SOC-CMM domain scoring, it is worth mapping the ENS technical measures the SOC already supports (monitoring, incident handling, logging) against those that require reinforcement before presenting the matrix to the board or regulator.
Frequently asked questions
Independent by design
Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

