The Cybersecurity Capability Maturity Model (C2M2) is a free tool to help organizations evaluate their cybersecurity capabilities and optimize security investments. It was developed with input from more than 250 energy sector cybersecurity experts representing about 100 electricity, oil, and natural gas organizations.
The C2M2 is designed for use in both Information Technology (IT) and Operational Technology (OT) environments and aligns with the National Institute of Standards and Technology’s (NIST’s) Cybersecurity Framework (CSF). It has been widely adopted across industries and around the globe as a tool to measure cybersecurity capabilities and harden critical infrastructure against cybersecurity attack.
Model Document
Download the C2M2 Version 2.1 – Latest version, released June 2022.
Self-Evaluation Tool
Access the HTML-Based Self-Evaluation Tool by visiting https://c2m2.doe.gov.
Get the PDF-Based Self-Evaluation tool via email request to C2M2@doe.gov.
The C2M2 and tool were designed to enable any organization to complete a self-evaluation in a single day. The tool generates summary and detailed reports with performance dashboards that present a comprehensive view of organizational maturity, facilitate benchmarking, and can help strengthen communications to executive leaders about program accomplishments and needs. All data remains only on user devices in both the HTML- and PDF-based tools.
DOE facilitates voluntary, no-cost self-assessments for C2M2 and National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) as well as threat profile development workshops for United States energy sector organizations upon request. The Department of Energy never collects or shares any self-assessment data as part of these facilitations.
Email C2M2@doe.gov for more information.
Additional Resources
| 📢 New Resources Added - Cybersecurity Threat Profile Development Guide | |
| C2M2 Overview Presentation (July 2023) | Introduces the C2M2, key concepts, and the benefits of using it. |
| C2M2 Help Text and Practices (Excel file) (June 2022) | All C2M2 help text and practices in a spreadsheet. |
| Self-Evaluation Workshop Kickoff Presentation (July 2023) | Introduces C2M2 and key concepts for self-evaluation workshop participants. |
| Self-Evaluation Guide (June 2022) | Guides planning and facilitation of a self-evaluation workshop. |
| Self-Evaluation Cheat Sheet (June 2022) | Placemat-style quick reference for self-evaluation participants. |
| Cybersecurity Threat Profile Development Guide (July 2026) | Guidance on developing a prioritized list—profile—of high-priority cybersecurity threats to individual organizations for use in planning and decision making. |
| C2M2-CMMC Supplemental Guidance (January 2024) | Guidance for C2M2 users subject to the Department of War Cybersecurity Maturity Model Certification (CMMC). |
| C2M2 to CSF Mappings (March 2023) | Mappings of C2M2 V2.1 practices to CSF v1.1 subcategories. Mappings between CSF V2.0 and C2M2 V2.1 are coming soon. |
| C2M2 V1.1 to C2M2 V2.1 Mapping (July 2023) | Mapping between C2M2 V1.1 and C2M2 V2.1. |
| C2M2 V2.0 to C2M2 V2.1 Mapping (July 2023) | Mapping between C2M2 V2.0 and C2M2 V2.1. |
Read the Version 2.1 announcement (June 2022) to see what’s new in this version and how the model was updated.
What Is a Maturity Model?
- A Crawl/Walk/Run-style set of characteristics, practices, or processes that represent the progression of capabilities in a particular discipline
- A tool to benchmark current capabilities and identify goals and priorities for improvement
Organizations can use the C2M2 to consistently measure their cybersecurity capabilities over time, identify target maturity levels based on risk, and prioritize the actions and investments that allow them to meet their targets.
C2M2 User Community
Since its creation in 2012, organizations from across industries and around the globe have used the C2M2 self-evaluation tools to evaluate and improve their cybersecurity capabilities. This includes active daily use of the HTML-based tool and more than 3,500 total requests for the PDF-based tool. The following graphic illustrates the distribution of PDF-based tool requests from across U.S. industry sectors.
Components of the C2M2
The model contains more than 350 cybersecurity practices, which are grouped by objective into 10 logical domains. Each practice is assigned a maturity indicator level (MIL) that indicates the progression of practices within a domain.
Domains
A domain contains a structured set of cybersecurity practices focused on a specific subject area. For example, the Risk Management domain is a group of practices that an organization can perform to establish and mature its cyber risk management capability.
Objectives
Practices within each domain are organized into objectives that can be achieved by implementing the practices in the domain. For example, the Risk Management domain comprises five objectives:
- Establish and Maintain Cyber Risk Management Strategy and Program
- Identify Cyber Risk
- Analyze Cyber Risk
- Respond to Cyber Risk
- Management Activities
Practices
Practices are the most fundamental component of the C2M2. Each practice is a brief statement describing a cybersecurity activity that may be performed by an organization. Practices within each domain are organized to progress along a maturity scale.
Maturity Indicator Levels (MILs)
To measure progression, the C2M2 uses a scale of maturity indicator levels, each representing maturity attributes described in the table below. Organizations that implement the cybersecurity practices within each MIL achieve that level.
Supplemental Materials
Energy Sector Cybersecurity Framework Implementation Guidance (PDF)
Questions and Feedback
Contact us C2M2@doe.gov with questions or feedback on C2M2.
The DOE facilitates voluntary, no-cost self-evaluations for the C2M2 and the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) as well as threat profile development workshops for United States energy sector organizations upon request. The Department of Energy never collects or shares any self-evaluation data as part of these facilitations. Email C2M2@doe.gov for more information.
News and Updates
-
The Threat Profile Guide provides a practical methodology to transform fragmented threat updates into actionable insights. -
The U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) today released Version 2.1 (V2.1) of the Cybersecurity Capability Maturity Model (C2M2). -
The Department of Energy is seeking public comment on Version 2.0 of the Cybersecurity Capability Maturity Model (C2M2) through February 10, 2022. -
U.S. energy companies have been using the Cybersecurity Capability Maturity Model (C2M2) to evaluate their cybersecurity capabilities and optimize their security investments for nearly a decade.