Almost every SOC can tell you how many alerts it handled last month. Few can tell you how mature it is. Maturity is not the number of tools or the size of the team: it is how predictable, measured and self-improving the operation is. Assessing it with a public method avoids two common traps: buying technology to fix a process problem, and chasing a "level 5" the business does not need.
What maturity means for a SOC
An immature SOC may detect an attack well, but it depends on who happens to be on shift that day. A mature SOC detects and responds consistently, documents what it does, measures the outcome and uses that measurement to tune rules, processes and priorities. The difference is not what the SOC can do on a good day, but what it delivers every day.
That is why it helps to separate two concepts that usually travel together. Capability means having the function: there is threat hunting, there is a ransomware playbook, there is EDR integration. Maturity is how well that function is managed: whether it is repeatable, has an owner, is measured and reviewed.
The five dimensions of a SOC
Assessment models look at the SOC from five complementary angles:
- Governance (business). Defined mission and scope, executive sponsorship, budget, links to risk management and accountability. Without it, the SOC monitors what is easy, not what matters.
- People. Roles, 24×7 staffing, training, career paths, retention and knowledge management. High turnover wipes out any maturity that was never written down.
- Processes. Triage, escalation, incident management, the detection rule lifecycle, shift handover and continuous improvement.
- Technology. SIEM, EDR/XDR, SOAR, integrated log sources, retention and the quality of the telemetry that reaches the analyst.
- Services. What the SOC actually delivers: monitoring, response, threat hunting, threat intelligence, vulnerability management, reporting.
Three public references to use
SOC-CMM
SOC-CMM (SOC Capability & Maturity Model) was launched in 2016, based on a master's thesis, and describes itself as the first open standard for measuring SOC maturity. In version 2.4, the model has 5 domains and 27 aspects: Business, People and Process are assessed for maturity only; Technology and Services for both maturity and capability. Maturity runs from 0 to 5 (non-existent, initial, managed, defined, quantitatively managed and optimizing), and capability has four levels (incomplete, performed, managed and defined). The self-assessment tool is available on the project's official website, and the model itself states that the right level is not necessarily the highest: risk, ambition, budget and resources set the target.
NIST CSF 2.0 and its Tiers
The NIST Cybersecurity Framework 2.0 provides the vocabulary to place the SOC within the security program: it concentrates the Detect and Respond functions and relies on Govern for scope and priorities. The CSF Tiers (Partial, Risk Informed, Repeatable and Adaptive) help describe how rigorously the organization governs and manages cybersecurity risk. But, as we explain in our article on the six functions of NIST CSF 2.0, a Tier is not a maturity score: the most useful tool for an action plan is the Profile, which compares the current state with the target state.
MITRE ATT&CK for detection coverage
MITRE ATT&CK is the public knowledge base of tactics and techniques observed in real-world attacks. Mapping every detection rule and every log source against ATT&CK shows which behaviors the SOC can see and where the blind spots are. Open tools such as ATT&CK Navigator and DeTT&CT help visualize that coverage. The caveat is not to confuse "a rule exists" with "the rule works": coverage only counts when it is tested, for example in purple team exercises.
The models complement each other. SOC-CMM measures the operation from the inside, the CSF connects the SOC to the organization's risk program and ATT&CK measures what it can actually detect. Using only one usually leaves a blind spot.
Metrics that signal maturity
A mature SOC measures outcomes, not volume. The indicators that best reveal the stage of the operation, already discussed in what to expect from a 24×7 SOC, are:
- MTTD (mean time to detect). From the start of malicious activity to detection. Shows whether telemetry and rules are working.
- MTTR (mean time to respond). From detection to containment or resolution. Shows whether processes and escalation paths are clear.
- Coverage. Share of critical assets sending events and of relevant ATT&CK techniques with tested detection.
- False positive rate. Measures rule quality and the risk of alert fatigue.
- Trend. More important than this month's number is the direction over several months.
A single metric can mislead. A low MTTR may mean cases closed without investigation; few false positives may mean rules that were switched off. Maturity shows when the indicators are read together, each with a written definition of how it is calculated.
How to run a self-assessment
- Define the scope. In-house, outsourced or hybrid SOC? Which services are being assessed?
- Choose the model. SOC-CMM covers all five dimensions; complement it with ATT&CK mapping for technical coverage.
- Involve the people who run it. Analysts, shift leads and detection engineers answer better than management alone, and disagreement between their answers is already a finding.
- Require evidence. A process that is not written down, or that nobody follows, does not count as implemented.
- Set the target. For each dimension, what level does business risk require?
- Turn the gap into a plan. Prioritize by risk impact and effort, and repeat the assessment periodically to measure progress.
What to prioritize at each level
- Initial (ad hoc operation). An inventory of critical assets, integration of essential log sources (identity, endpoints, perimeter and cloud), genuine 24×7 monitoring, written triage and escalation criteria, and an incident response plan with defined roles.
- Managed and defined. Playbooks for the most likely scenarios, a detection rule lifecycle (create, test, tune, retire), first metrics with formal definitions, ATT&CK mapping and automation of repetitive enrichment tasks.
- Quantitative and optimizing. Hypothesis-driven threat hunting, threat intelligence applied to rules, continuous coverage testing through purple teaming, targets per indicator and reports that speak about risk to the board.
The target is not level 5. SOC-CMM itself recommends choosing the level that fits your risk, ambition and resources. A consistent operation at level 3 is worth more than level 5 processes that exist only on paper.
In practice
For many companies, moving up a level internally requires building shift teams, tooling and time. Outsourcing the operation, or part of it, is a way to inherit processes that are already structured. In that case, the maturity assessment becomes a criterion for choosing the provider. The Network Secure SOC is ISO/IEC 27001:2022 certified, audited by Bureau Veritas, with a scope covering monitoring, detection, analysis and incident response, and its reports include indicators such as MTTD, MTTR and incident trends. Learn more about our SOC and MDR service.
Frequently asked questions
What is SOC maturity?
It is the degree to which a SOC's capabilities are performed consistently, documented, measured and continuously improved.
Which model should I use to assess a SOC?
SOC-CMM is the most widely used open model for a full assessment of the operation. NIST CSF 2.0 helps place the SOC within the risk program, and MITRE ATT&CK measures detection coverage.
How often should SOC maturity be reassessed?
A full assessment once a year is usually enough to track progress, with an extra review after major changes such as a new SIEM, outsourcing or a significant incident. Operational metrics should be tracked monthly.
Can an outsourced SOC be assessed too?
Yes. The customer can apply the same model by asking the provider for evidence: documented processes, coverage mapping against ATT&CK, metric definitions and certifications whose scope includes the contracted service.
Sources consulted: SOC-CMM, official model description (version 2.4: domains, aspects, maturity and capability levels); NIST Cybersecurity Framework 2.0 (CSWP 29), Govern, Detect and Respond functions, Tiers and Profiles; MITRE ATT&CK; DeTT&CT (open project for mapping data sources and detection coverage against ATT&CK). This article is educational and does not replace a maturity assessment of your own environment.