US DOE: Cybersecurity, Energy Security, and Emergency Response
Pacific Northwest National Laboratory
Welcome to Version 2.1! Note: The Version 2.0 HTML-Based Tool is still offered as an option on the Tools menu to support full access to existing self-evaluations generated using Version 2.0.

C2M2 Version 2.1

The Cybersecurity Capability Maturity Model (C2M2) enables organizations to evaluate their cybersecurity capabilities and optimize security investments. It uses a set of industry-vetted cybersecurity practices focused on both information technology (IT) and operations technology (OT) assets and environments. The C2M2 Version 2.1 Model Document provides key concepts and C2M2 practices.

While the U.S. energy industry led development of the C2M2 and championed its adoption, any organization—regardless of size, type, or industry—can use the model to evaluate, prioritize, and improve their cybersecurity capabilities.

A free, user-friendly C2M2 Self-Evaluation Tool is available on both an HTML and a PDF platform. The two versions of the tool both offer interactive features and help text, allow users to securely record results, and automatically generate a detailed, graphical report. In both versions, all user data remains only on user devices, and results from either platform can be saved and loaded into the other. A new feature allows users to compare results from self-evaluations conducted using the same version of the model. All the C2M2 self-evaluation tools are accessible from the “Tools” dropdown menu on the navigation bar at the top of the webpage. The Resources webpage provides access to C2M2 guidance and training products.

The C2M2 was developed collaboratively by the U.S. Department of Energy (DOE), private- and public-sector experts, and representatives of asset owners and operators within the energy sector. It has been widely used to support self-evaluations in the energy sector and other sectors since its initial release in 2012. Version 1.1 was released in 2014, Version 2.0 was introduced in June 2021, and Version 2.1 was launched in June 2022.

Additional information on the C2M2 program is presented at https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2.