primedefence

What is SOC-CMM and when to use it

SOC-CMM explained for CISOs: what it measures, what it does not measure and when to use it as a SOC maturity baseline.

Direct definition

SOC-CMM is a maturity model for evaluating how a Security Operations Center operates. It reviews technology, processes, people, services and business alignment to produce a defensible maturity matrix.

When to use SOC-CMM

It fits when the CISO needs a baseline, investment case, audit preparation, roadmap or evidence of continuous improvement for board, regulator or external audit conversations.

  • Before increasing SOC budget.
  • Before audit or regulatory reviews.
  • After MDR, SIEM, EDR or SOAR changes.
  • When SOC growth needs a shared maturity model.

What SOC-CMM is not

It is not a legal certification, does not replace NIS2, DORA or ISO 27001 and should not become an evidence-free questionnaire. Its value comes from validated scoring. SOC-CMM also does not prescribe specific tools, does not impose a vendor and does not compete with the SOC's continuous improvement cycle: it structures it.

Origin and authorship of the model

SOC-CMM was created by Rob van Os from a 2016 academic study and has been maintained as an open, free, revisable model. Version 2.4 organizes the assessment into five domains and twenty-seven aspects, with continuous scoring from 0 to 5. Compared to vendor-driven models, its independent governance reduces commercial bias: no vendor decides what is measured or how it is scored. That is why it is referenced by MITRE (11 Strategies of a World-class Cybersecurity Operations Center), NCSC (Factsheet on Security Operations Centers) and ENISA (How to set up CSIRT and SOC) as an operational reference.

The five domains and why they matter together

Business covers drivers, stakeholders, charter, governance and privacy; without it, the SOC is justified by budget only. People captures roles, people management, knowledge and training; without it, processes depend on key individuals. Process organizes SOC management, operations, reporting, use cases, detection, automation and logs. Technology reviews log, network, endpoint and SecOps automation monitoring. Services lands incident management, CTI, forensics, threat hunting and vulnerability management. The matrix exposes imbalance: strong Technology does not compensate weak Process, or vice versa.

  • Business: drivers, stakeholders, charter, governance and privacy.
  • People: roles, management, knowledge and training.
  • Process: SOC management, operations, reporting, use cases, detection, automation and logs.
  • Technology: log, network, endpoint and SecOps automation monitoring.
  • Services: incident management, CTI, forensics, threat hunting and vulnerability management.

SOC-CMM versus self-assessment and questionnaires

The 2026 SOC-CMM report again shows self-assessments tend to overestimate real scoring by an average of 0.6 points per element. A questionnaire without evidence does not support board decisions or stand up to auditor review. The difference between self-assessment and independent assessment is precisely how the answer is contrasted: multi-layer interviews (analyst, engineer, manager, sponsor), documentary review, operational observation, cross-domain calibration. That difference justifies the cost of third-party assessment when the answer has regulatory or investment consequences.

When NOT to use SOC-CMM

Avoid applying SOC-CMM when there is no SOC yet, when the goal is only to tick a regulatory check without intent to improve, when no sponsor can act on findings, or when the requested scope does not cover minimum evidence per domain. In those cases, a lighter initial diagnosis (gap analysis, readiness assessment or specific regulatory audit) fits better and leaves room to return to SOC-CMM once there is enough operational context and executive commitment.

Frequently asked questions

Independent by design

Primedefence assesses against the SOC-CMM and nothing else. The model is free, open and cited by MITRE, the NCSC and ENISA. The assessment is delivered by an external third party with no stake in the result and no SOC operation of its own, so the finding answers to your interest alone.

Independent SOC-CMM assessment