SOC-CMM Latest version

SOC-CMM Latest Version

Disclaimer: the SOC-CMM is provided without warranty of any kind. The author of the tool cannot assure its accuracy and is not liable for any cost as a result of decisions based on the output of this tool. The usage of this tool does not in any way entitle the user to support or consultancy. The GPLv3 licence applies to the SOC-CMM. Please download and read the license agreement before using this product.


The SOC-CMM toolkit has 2 versions: basic and advanced. The difference between these versions is that the advanced version has options for weighing and exclusion of elements, thus enabling the assessor to influence the scoring. If you are unsure which version to use, go with the \'basic\' version.

Use the download links below to download the SOC-CMM. Use the form at the bottom of this page to subscribe to the newsletter and get notified about updates to the SOC-CMM.
Security note: there is no active content (i.e. macros) in these files.


- Download the SOC-CMM basic assessment tool, version 2.1 (xlsx)
- Download the SOC-CMM advanced assessment tool, version 2.1 (xlsx)
- Download the SOC-CMM (v2.1) to NIST CSF (v1.1) mapping file (xlsx)
- Download the instructions for migrating results between versions

If you wish to be informed about updates to the SOC-CMM, use the form below to sign up to the newletter. Your email address will not be shared or used for any other purpose than information about the SOC-CMM. The SOC-CMM mailinglist is powered by MailChimp.

* indicates required