Taking new engagements — Q4 hello@datadefenz.com
ServicesAll servicesGRC & Compliance7Security Culture1Risk Management3Technical Security5Leadership Advisory1Fast-Turnaround1
ProductsResourcesPracticeAboutBook a 30-minute callContact
Services / Technical Security / SOC Maturity Assessment (SOC-CMM)

SOC Maturity Assessment (SOC-CMM)

Score your security operations centre against the model the industry actually uses.

In plain terms

The SOC-CMM is an open maturity and capability model for security operations, built from academic research by Rob van Os and used worldwide to benchmark SOCs. It assesses five domains — Business, People, Process, Technology and Services — and scores each on maturity and capability separately, which matters: a SOC can own excellent tooling and still score badly because nothing about how it runs is defined or measured. We run the assessment, validate the answers through interviews and evidence rather than self-report, and hand back a scored baseline with a roadmap you can re-run next year to show movement.

What you get

  • Scored assessment across all five SOC-CMM domains, maturity and capability rated separately
  • Evidence-validated answers — interviews and artefacts, not a self-assessment questionnaire
  • Domain and element level heat map showing exactly where the weakness sits
  • Target maturity profile appropriate to your threat exposure, not a blanket “aim for level 5”
  • Prioritised improvement roadmap, and a baseline you can re-run annually

Who it is for

Organisations running an internal or hybrid SOC, those about to build one, and those who have inherited a SOC and cannot tell whether it is any good.

The model

Five domains, scored separately.

Five domains. Maturity and capability are scored separately, which is the point of the model — a SOC can own excellent tooling and still score badly because nothing about how it runs is defined, measured or improved.

0Non-existentNot performed at all.
1InitialHappens, but ad hoc and dependent on individuals.
2RepeatableRepeated with some consistency, largely undocumented.
3DefinedDocumented, standardised and actually followed.
4ManagedMeasured and controlled against defined metrics.
5OptimisingContinuously improved on the basis of those measurements.

Domain and element names follow the published SOC-CMM, an open model developed by Rob van Os from academic research. Maturity and capability are scored separately. DATADEFENZ is not affiliated with the model's author.