Cybersecurity Capability Maturity Model (C2M2)

C2M2 Cybersecurity Capability Maturity Model

The Cybersecurity Capability Maturity Model (C2M2) is a free tool to help organizations evaluate their cybersecurity capabilities and optimize security investments. It was developed with input from more than 250 energy sector cybersecurity experts representing about 100 electricity, oil, and natural gas organizations.

The C2M2 is designed for use in both Information Technology (IT) and Operational Technology (OT) environments and aligns with the National Institute of Standards and Technology’s (NIST’s) Cybersecurity Framework (CSF). It has been widely adopted across industries and around the globe as a tool to measure cybersecurity capabilities and harden critical infrastructure against cybersecurity attack.

Model Document

Download the C2M2 Version 2.1 – Latest version, released June 2022.

Self-Evaluation Tool

Access the HTML-Based Self-Evaluation Tool by visiting https://c2m2.doe.gov.

Get the PDF-Based Self-Evaluation tool via email request to C2M2@doe.gov.  

The C2M2 and tool were designed to enable any organization to complete a self-evaluation in a single day. The tool generates summary and detailed reports with performance dashboards that present a comprehensive view of organizational maturity, facilitate benchmarking, and can help strengthen communications to executive leaders about program accomplishments and needs. All data remains only on user devices in both the HTML- and PDF-based tools.

DOE facilitates voluntary, no-cost self-assessments for C2M2 and National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) as well as threat profile development workshops for United States energy sector organizations upon request. The Department of Energy never collects or shares any self-assessment data as part of these facilitations.

Email C2M2@doe.gov for more information.

Additional Resources

📢 New Resources Added - Cybersecurity Threat Profile Development Guide
C2M2 Overview Presentation (July 2023)Introduces the C2M2, key concepts, and the benefits of using it.
C2M2 Help Text and Practices (Excel file) (June 2022)All C2M2 help text and practices in a spreadsheet.
Self-Evaluation Workshop Kickoff Presentation (July 2023)Introduces C2M2 and key concepts for self-evaluation workshop participants.
Self-Evaluation Guide (June 2022)Guides planning and facilitation of a self-evaluation workshop.
Self-Evaluation Cheat Sheet (June 2022)Placemat-style quick reference for self-evaluation participants.
Cybersecurity Threat Profile Development Guide (July 2026)Guidance on developing a prioritized list—profile—of high-priority cybersecurity threats to individual organizations for use in planning and decision making.
C2M2-CMMC Supplemental Guidance (January 2024)Guidance for C2M2 users subject to the Department of War Cybersecurity Maturity Model Certification (CMMC).
C2M2 to CSF Mappings (March 2023)Mappings of C2M2 V2.1 practices to CSF v1.1 subcategories. Mappings between CSF V2.0 and C2M2 V2.1 are coming soon.
C2M2 V1.1 to C2M2 V2.1 Mapping (July 2023)Mapping between C2M2 V1.1 and C2M2 V2.1.
C2M2 V2.0 to C2M2 V2.1 Mapping (July 2023)Mapping between C2M2 V2.0 and C2M2 V2.1.

Read the Version 2.1 announcement (June 2022) to see what’s new in this version and how the model was updated.

 

 

 

A rising three bar graph. the bars are labeled crawl, walk, and run and each bar has a figure in each stage of movement.

What Is a Maturity Model?

  • A Crawl/Walk/Run-style set of characteristics, practices, or processes that represent the progression of capabilities in a particular discipline
  • A tool to benchmark current capabilities and identify goals and priorities for improvement

Organizations can use the C2M2 to consistently measure their cybersecurity capabilities over time, identify target maturity levels based on risk, and prioritize the actions and investments that allow them to meet their targets.

Four icons in a row with the heading C2M2 goals. The icons are labeled enhance cyber posture, consistently measure cyber capabilities, share knowledge, prioritize actions, and investments

 

 

C2M2 User Community

Since its creation in 2012, organizations from across industries and around the globe have used the C2M2 self-evaluation tools to evaluate and improve their cybersecurity capabilities. This includes active daily use of the HTML-based tool and more than 3,500 total requests for the PDF-based tool. The following graphic illustrates the distribution of PDF-based tool requests from across U.S. industry sectors.

 

C2M2 Tool Requests by US Sector updated Dec 2025

 

 

Components of the C2M2

The model contains more than 350 cybersecurity practices, which are grouped by objective into 10 logical domains. Each practice is assigned a maturity indicator level (MIL) that indicates the progression of practices within a domain.

Domains

A domain contains a structured set of cybersecurity practices focused on a specific subject area. For example, the Risk Management domain is a group of practices that an organization can perform to establish and mature its cyber risk management capability. 
 

This is a list c2m2 domains. This list is as follows: Asset change and confirmation management (asset), Cybersecurity architecture (Architecture), cybersecurity program management (program), event and incident response continuity of operations (response), identity and access management (access), risk management (risk), situation awareness (situation), third-party risk management (third-parties), threat and vulnerability management (threat), workforce management (workforce)

Objectives

Practices within each domain are organized into objectives that can be achieved by implementing the practices in the domain. For example, the Risk Management domain comprises five objectives:

  1. Establish and Maintain Cyber Risk Management Strategy and Program
  2. Identify Cyber Risk
  3. Analyze Cyber Risk
  4. Respond to Cyber Risk
  5. Management Activities

Practices

Practices are the most fundamental component of the C2M2. Each practice is a brief statement describing a cybersecurity activity that may be performed by an organization. Practices within each domain are organized to progress along a maturity scale.

Maturity Indicator Levels (MILs)

To measure progression, the C2M2 uses a scale of maturity indicator levels, each representing maturity attributes described in the table below. Organizations that implement the cybersecurity practices within each MIL achieve that level.

This is a graphic outlining the three maturity indicator levels (MILs). Mil 1 is the initiated level, Mil 2 is the performed level, and Mil 3 is the Managed level.

 

Supplemental Materials

NIST Cybersecurity Framework

Energy Sector Cybersecurity Framework Implementation Guidance (PDF)

 

Questions and Feedback

Contact us C2M2@doe.gov with questions or feedback on C2M2.

The DOE facilitates voluntary, no-cost self-evaluations for the C2M2 and the National Institute of Standards and Technology (NIST) Cybersecurity Framework (CSF) as well as threat profile development workshops for United States energy sector organizations upon request. The Department of Energy never collects or shares any self-evaluation data as part of these facilitations. Email C2M2@doe.gov for more information.

 

News and Updates