Thank you for your question.
WHen choosing target maturity levels and capability levels, there are several aspects that play a role. These aspects include:
- Ambition
- Availability of resources
- Stakeholder expectations
- Organisational risk levels (or client risk levels in case of MSSP)
If you are comparing yourself against other companies in the same region and/or sector, then the information in the SOC Maturity Report can also be used.
The reason that the default levels are set to maturity level 3 and capability level 2 has to do with reliable, repeatable, and standardised service delivery. This allows an organisation (or clients in case of MSSP) to have a decent level of trust that security operations services are fairly complete and trustworthy. Maturity level 3 and capability level 2 are therefore considered the maturity baseline. SOCs below that level should strive to at least get to those levels. Whether higher levels are required depends on the factors previously mentioned.
Here is an article that may also be helpful:
Finally, as an example, this is what the CDC recommends as SOC maturity levels in the UAE. Higher mandatory levels are used for critical infrastructure:
https://csc.gov.ae/documents/38662/489552/SOC+Baseline+Capabilities+v2.0.pdf/ef9913e5-f280-36aa-7a01-8c12d8bae54e?t=1758541951178