Back to Frameworks
United States
v2.1
10 domains
22 controls

Cybersecurity Capability Maturity Model for energy sector

Verified

Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.

Framework Domains (10)

C2M2 Domain: Asset, Change and Configuration Management (ASSET)

2 controls
Controls in the C2M2 Domain: Asset, Change and Configuration Management (ASSET) domain of C2M22 controls
CodeTitle
ASSET-1Manage IT and OT Asset Inventory
ASSET-2Manage Asset Configuration and Changes

C2M2 Domain: Cybersecurity Architecture (ARCHITECTURE)

3 controls
Controls in the C2M2 Domain: Cybersecurity Architecture (ARCHITECTURE) domain of C2M23 controls
CodeTitle
ARCH-1Establish a Cybersecurity Architecture Strategy
ARCH-2Implement Network Protections
ARCH-3Implement Data Security

C2M2 Domain: Cybersecurity Program Management (PROGRAM)

1 controls
Controls in the C2M2 Domain: Cybersecurity Program Management (PROGRAM) domain of C2M21 controls
CodeTitle
PROGRAM-1Establish and Maintain the Cybersecurity Program

C2M2 Domain: Event and Incident Response, Continuity of Operations (RESPONSE)

3 controls
Controls in the C2M2 Domain: Event and Incident Response, Continuity of Operations (RESPONSE) domain of C2M23 controls
CodeTitle
RESPONSE-1Detect and Analyze Cybersecurity Events
RESPONSE-2Respond to and Recover from Cybersecurity Incidents
RESPONSE-3Plan for Continuity of Operations

C2M2 Domain: Identity and Access Management (ACCESS)

2 controls
Controls in the C2M2 Domain: Identity and Access Management (ACCESS) domain of C2M22 controls
CodeTitle
ACCESS-1Establish and Maintain Identities
ACCESS-2Control Logical and Physical Access

C2M2 Domain: Risk Management (RISK)

3 controls
Controls in the C2M2 Domain: Risk Management (RISK) domain of C2M23 controls
CodeTitle
RISK-1Establish a Cyber Risk Management Strategy and Program
RISK-2Identify and Analyze Cyber Risk
RISK-3Manage and Respond to Cyber Risk

C2M2 Domain: Situational Awareness (SITUATION)

2 controls
Controls in the C2M2 Domain: Situational Awareness (SITUATION) domain of C2M22 controls
CodeTitle
SITUATION-1Perform Logging and Monitoring
SITUATION-2Establish and Maintain a Common Operating Picture

C2M2 Domain: Third-Party Risk Management (THIRD-PARTIES)

2 controls
Controls in the C2M2 Domain: Third-Party Risk Management (THIRD-PARTIES) domain of C2M22 controls
CodeTitle
THIRD-1Identify and Manage Third-Party Risk
THIRD-2Manage Supplier Relationships and Incident Notification

C2M2 Domain: Threat and Vulnerability Management (THREAT)

2 controls
Controls in the C2M2 Domain: Threat and Vulnerability Management (THREAT) domain of C2M22 controls
CodeTitle
THREAT-1Identify and Respond to Cyber Threats
THREAT-2Reduce Cybersecurity Vulnerabilities

C2M2 Domain: Workforce Management (WORKFORCE)

2 controls
Controls in the C2M2 Domain: Workforce Management (WORKFORCE) domain of C2M22 controls
CodeTitle
WORKFORCE-1Establish Cybersecurity Responsibilities and Workforce
WORKFORCE-2Develop Cybersecurity Workforce and Awareness

Maps to 1 other framework

22 total controls
NIST Cybersecurity Framework 2.0
22 source controls mapped|13 target controls covered
100%

Frequently Asked Questions

What is C2M2?

C2M2 is a compliance framework from United States with 10 domains and 22 controls. Cybersecurity Capability Maturity Model for energy sector It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.

How many controls does C2M2 have?

C2M2 has 22 controls organised across 10 domains. The largest domains are C2M2 Domain: Cybersecurity Architecture (ARCHITECTURE) (3 controls), C2M2 Domain: Event and Incident Response, Continuity of Operations (RESPONSE) (3 controls), C2M2 Domain: Risk Management (RISK) (3 controls). Each control defines specific requirements that organisations must implement to achieve compliance.

What frameworks does C2M2 map to?

C2M2 maps to 1 other compliance frameworks. The top mapping partners are NIST Cybersecurity Framework 2.0 (100% coverage). Use our comparison tool to explore control-level mappings between frameworks.

How do I get started with C2M2 compliance?

Start your C2M2 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about C2M2 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 22 controls and track your progress.

Start Your Compliance Journey

Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.

Get Started Free →

Free forever — no credit card required