⚡ U.S. Department of Energy | CESER

C2M2 Program Portal

Cybersecurity Capability Maturity Model — Energy Sector Self-Evaluation Program

Version 2.1 10 Domains MIL 0–3 Scale IT & OT Coverage
🏛️
0
Cybersecurity Domains
📋
0+
Cybersecurity Practices
📊
0
Maturity Indicator Levels
🏭
0+
Critical Infrastructure Sectors
📅
2022
Current Version (v2.1)
Quick Jump — C2M2 Domains
ASSET 🗂️ Asset & Config Mgmt THREAT 🛡️ Threat & Vuln Mgmt RISK ⚖️ Risk Management ACCESS 🔑 Identity & Access Mgmt SITUATE 👁️ Situational Awareness RESPONSE 🚨 Incident Response 3RD-PTY 🤝 Third-Party Risk WORK 👷 Workforce Mgmt ARCH 🏗️ Cyber Architecture PROGRAM 📋 Program Mgmt
Portal Sections
Case Studies
🏫

C2M2 Training Case Studies

Sector-specific fictional organizations built for hands-on C2M2 training exercises. Each case study provides a complete organizational profile, IT and OT asset inventories, network architecture diagrams, security control gaps, third-party risk exposure, and C2M2 domain assessments — giving students realistic data to practice scoring, gap analysis, and remediation planning. Case studies are being developed for each of the eight critical infrastructure sectors covered in the C2M2 framework.

⚡ Electric Utilities 💧 Water Systems 🛢️ Oil & Natural Gas 🏭 Industrial / OT 🏥 Healthcare 🏦 Financial Services 🏛️ Government 🔭 Research
View Case Studies →
C2M2 Reports
📊

C2M2 Assessment Reports

Structured reports are the documentary backbone of a C2M2 implementation. They translate raw assessment data into actionable evidence — capturing asset inventories, access control posture, vulnerability findings, maintenance status, and identified gaps. Each report maps directly to one or more C2M2 domains and MIL levels, providing the audit trail required to validate maturity claims, prioritize remediation, and communicate risk to leadership. Together they form a complete picture of your organization's cybersecurity posture against the C2M2 framework.

📦 Asset Inventory 🔐 Access Control 🛡️ Vulnerability Scan 🔧 Maintenance 🗺️ Gap Analysis & POA&M
View All Reports →