Cybersecurity Capability Maturity Model (C2M2)

View as Markdown

What is the Cybersecurity Capability Maturity Model?

The Cybersecurity Capability Maturity Model (C2M2) is a voluntary framework from the United States Department of Energy, first published in 2012 and most recently updated in 2022. It helps organizations evaluate their cybersecurity capabilities and optimize security investments. C2M2 defines practices across 10 cybersecurity domains and measures progression within each domain with maturity level indicators.

Who is the intended audience?

The Department of Energy developed C2M2 with asset owners and operators in the electricity, oil, and natural gas industries, but the model is intended for organizations in every sector. Today it is used in energy, manufacturing, healthcare, financial services, and other sectors.

Where can I find more information?

These resources are on the U.S. Department of Energy website:

How can runZero help me with these controls?

The table below maps runZero to the 10 domains of C2M2 v2.1. Strong alignment means runZero can play a significant role in helping an organization implement safeguards; Partial alignment means runZero can play a complementary role.

Domains Strong alignment Partial alignment
Asset, Change, and Confirmation Management (ASSET) ✔
Threat and Vulnerability Management (THREAT) ✔
Risk Management (RISK) ✔
Identity and Access Management (ACCESS)
Situational Awareness (SITUATION)
Event and Incident Response, Continuity of Operations (RESPONSE)
Third-Party Risk Management (THIRD-PARTIES)
Workforce Management (WORKFORCE)
Cybersecurity Architecture (ARCHITECTURE) ✔
Cybersecurity Program Management (PROGRAM)
Updated