Score SOC maturity across business alignment, people, process, technology and services on a five-level capability scale.
Process and technology carry the heaviest weights because they are what make capability survive staff turnover — an undocumented SOC loses its capability with its best analyst. The weakest-domain output exists because maturity is limited by its worst pillar rather than its average. Maturity assessments are how SOC investment gets prioritised and how regulators and customers judge the function, and a balanced level 3 delivers more than a lopsided level 4 with no documented process.
SOC Maturity
Maturity = 0.25 × process + 0.25 × technology + 0.2 × people + 0.15 × business alignment + 0.15 × services, each scored 1–5.
Gap to target
Gap to target = target level − current score, floored at zero.
Maturity = 0.25 × process + 0.25 × technology + 0.2 × people + 0.15 × business alignment + 0.15 × services, each scored 1–5. Process and technology carry the heaviest weights because they are what make capability survive staff turnover — an undocumented SOC loses its capability with its best analyst. The weakest-domain output exists because maturity is limited by its worst pillar rather than its average.
Maturity assessments are how SOC investment gets prioritised and how regulators and customers judge the function, and a balanced level 3 delivers more than a lopsided level 4 with no documented process.
This calculator takes 6 inputs: Business alignment — charter, sponsorship, reporting, People — staffing, skills, training, retention, Process — playbooks, escalation, quality assurance, Technology — SIEM, EDR, SOAR, coverage and tuning, Services — monitoring, IR, hunting, intel, forensics, Target maturity level. The pre-filled defaults are a realistic starting point — replace them with figures from your own environment for a result you can act on.
For most organisations, no. Level 4 — measured and managed — is the sensible destination; level 5 requires continuous optimisation effort that only pays back where security operations are core to the product. Aim for balance across domains before height in any one.
Annually as a formal exercise, with a lightweight quarterly check on the domain you are actively investing in. More frequent full assessments generate noise rather than insight, since maturity moves slowly by design.