# What is the benchmark for Maturity and Capability

**URL:** https://soc-cmm.discourse.group/t/what-is-the-benchmark-for-maturity-and-capability/33
**Category:** General
**Created:** [September 3, 2026, 12:56pm UTC](https://soc-cmm.discourse.group/t/what-is-the-benchmark-for-maturity-and-capability/33 "2026-09-03T12:56:46Z")
**Posts on this page:** 3
**Page:** 1

<div class="post-metadata">

### Author: ![harisanim](https://avatars.discourse-cdn.com/v4/letter/h/f08c70/32.png) [@harisanim](https://soc-cmm.discourse.group/u/harisanim)
#### Post date: [September 3, 2026, 12:56pm UTC](https://soc-cmm.discourse.group/t/what-is-the-benchmark-for-maturity-and-capability/33/1 "2026-09-03T12:56:46Z")

</div>

Dear Team,

I hope you’re doing.

When an organisation has not established its own SOC Target Operating Model, what does SOC-CMM consider the appropriate target maturity and capability level based on industry best practice, and what is the formal rationale for that target? Specifically, should we use Maturity Level 3 / Capability Level 2, or should the target be derived from the industry average?”

I need the clarification for this issue.

Regards,

Haris Rafiq

---

<div class="post-metadata">

### Author: ![robvanos](https://yyz2.discourse-cdn.com/flex050/user_avatar/soc-cmm.discourse.group/robvanos/32/58_2.png) [@robvanos](https://soc-cmm.discourse.group/u/robvanos)
#### Post date: [September 3, 2026, 7:44pm UTC](https://soc-cmm.discourse.group/t/what-is-the-benchmark-for-maturity-and-capability/33/2 "2026-09-03T19:44:49Z")

</div>

Thank you for your question.

WHen choosing target maturity levels and capability levels, there are several aspects that play a role. These aspects include:

- Ambition
- Availability of resources
- Stakeholder expectations
- Organisational risk levels (or client risk levels in case of MSSP)

If you are comparing yourself against other companies in the same region and/or sector, then the information in the SOC Maturity Report can also be used.

The reason that the default levels are set to maturity level 3 and capability level 2 has to do with reliable, repeatable, and standardised service delivery. This allows an organisation (or clients in case of MSSP) to have a decent level of trust that security operations services are fairly complete and trustworthy. Maturity level 3 and capability level 2 are therefore considered the maturity baseline. SOCs below that level should strive to at least get to those levels. Whether higher levels are required depends on the factors previously mentioned.

Here is an article that may also be helpful:

> [@Choosing SOC maturity levels](https://soc-cmm.discourse.group/t/choosing-soc-maturity-levels/19/5):
>
> @robvanos Thank you! I’m going to use your suggestions.

Finally, as an example, this is what the CDC recommends as SOC maturity levels in the UAE. Higher mandatory levels are used for critical infrastructure:  
[https://csc.gov.ae/documents/38662/489552/SOC+Baseline+Capabilities+v2.0.pdf/ef9913e5-f280-36aa-7a01-8c12d8bae54e?t=1758541951178](https://csc.gov.ae/documents/38662/489552/SOC+Baseline+Capabilities+v2.0.pdf/ef9913e5-f280-36aa-7a01-8c12d8bae54e?t=1758541951178)

---

<div class="post-metadata">

### Author: ![harisanim](https://avatars.discourse-cdn.com/v4/letter/h/f08c70/32.png) [@harisanim](https://soc-cmm.discourse.group/u/harisanim)
#### Post date: [September 4, 2026, 12:10pm UTC](https://soc-cmm.discourse.group/t/what-is-the-benchmark-for-maturity-and-capability/33/3 "2026-09-04T12:10:39Z")

</div>

Dear @robvanos,

Thank you so much for taking the time to clarify this for me. I truly appreciate your explanation and the guidance you have provided.

This has helped me understand the SOC-CMM benchmarking approach much more clearly. I was initially using the default maturity and capability levels from the assessment tool, but I started thinking about how I would justify the benchmark if someone asked, _“Why Level 3 and 2? Why not something else?”_

I now understand that the benchmark should have a proper and defensible basis rather than being selected arbitrarily. The reference you shared has made this much clearer for me.

Thank you once again for your time, patience, and valuable guidance. I genuinely appreciate your support and the knowledge you have shared with me. It means a lot. 🙏
