C2M2

Also known as: C2M2, DOE C2M2, Cybersecurity Capability Maturity Model, ES-C2M2

Cybersecurity Capability Maturity Model — US Department of Energy (DOE CESER)

A free self-assessment model from the US Department of Energy covering ten domains of cybersecurity practice at three maturity indicator levels, written for both IT and operational technology. Voluntary, and widely used across energy and other critical infrastructure sectors as the maturity language regulators and boards recognise. Version 2.1 is current.

Subscribe to C2M2 (RSS)

Timeline

No changes recorded yet — we are watching, and nothing has been published.

Monitoring

Watched by 1 official source. Watching since 20 September 2026.