Disclaimer: the SOC-CMM is provided without warranty of any kind. The author of the tool cannot assure its accuracy and is not liable for any cost as a result of decisions based on the output of this tool. The usage of this tool does not in any way entitle the user to support or consultancy. If you wish to obtain support for the SOC-CMM, please visit the license section for more information.
The CC BY-SA 4.0 licence applies to the SOC-CMM. Please download and read the license agreement before using this product.
The SOC-CMM toolkit has 2 versions: basic and advanced. The difference between these versions is that the advanced version has options for weighing and exclusion of elements, thus enabling the assessor to influence the scoring. If you are unsure which version to use, go with the 'basic' version.
Use the download links below to download the SOC-CMM. Use the form at the bottom of this page to subscribe to the newsletter and get notified about updates to the SOC-CMM.
Please read the V2.2 changenote if you wish to have more information on the changes since the previous version.
Security note: there is no active content (i.e. macros) in these files.
|- Download the SOC-CMM basic assessment tool, version 2.2 (xlsx)|
|- Download the SOC-CMM advanced assessment tool, version 2.2 (xlsx)|
|- Download the SOC-CMM for CERT 1.0 (xlsx)|
|- Download the SOC-CMM (v2.2) to NIST CSF (v1.1) mapping file (xlsx)|
|- Download the template for sharing assessment results with the SOC-CMM project|
|- Download the instructions for migrating results between versions|
If you wish to be informed about updates to the SOC-CMM, use the form below to sign up to the newsletter. Your email address will not be shared or used for any other purpose than information about the SOC-CMM. The SOC-CMM mailinglist is powered by MailChimp.