Where does your SOC actually stand?
A condensed, SOC-CMM-inspired maturity model across five domains โ Business, People, Process, Technology, Services. Pick a persona for an instant benchmark, or build your own by answering 20 short questions. Runs entirely in your browser; nothing is sent to a server.
Pick a persona for an instant rating
Business
Mission, strategy, governance, risk integrationIs the SOC's mission, scope and mandate formally defined and understood by stakeholders?
A written charter exists and stakeholders outside the SOC could describe its scope.
Does the SOC have a strategy or roadmap aligned to business risk and objectives?
A multi-year roadmap ties SOC investment to named business risks, not just tooling refresh.
Is there executive sponsorship and a defined reporting line into the business?
A named executive sponsor and a regular reporting cadence to leadership exist.
Is SOC output (findings, risk indicators) integrated into enterprise risk management?
SOC metrics feed the enterprise risk register, not just a SOC-internal dashboard.
Opens directly in Excel, Sheets or Numbers.