C2M2
Also known as: C2M2, DOE C2M2, Cybersecurity Capability Maturity Model, ES-C2M2
Cybersecurity Capability Maturity Model — US Department of Energy (DOE CESER)
Official site Official change log
A free self-assessment model from the US Department of Energy covering ten domains of cybersecurity practice at three maturity indicator levels, written for both IT and operational technology. Voluntary, and widely used across energy and other critical infrastructure sectors as the maturity language regulators and boards recognise. Version 2.1 is current.
Timeline
No changes recorded yet — we are watching, and nothing has been published.
Monitoring
Watched by 1 official source. Watching since 20 September 2026.