C2M2
Cybersecurity Capability Maturity Model for energy sector
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (16)
Asset, Change and Configuration Management
| Code | Title |
|---|---|
| ASSET-1 | IT and OT Asset Inventory |
| ASSET-2 | Configuration and Change Management |
C2M2: Access Management
Controlling access to critical infrastructure systems (C2M2)
| Code | Title |
|---|---|
| C2M2-06 | Physical and logical access controls |
| C2M2-07 | Personnel risk assessment |
| C2M2-08 | Electronic access perimeter management |
| C2M2-09 | Interactive remote access security |
| C2M2-10 | Revocation of access procedures |
C2M2: Asset Identification & Governance
Identifying and governing critical assets (C2M2)
| Code | Title |
|---|---|
| C2M2-01 | Critical asset identification and inventory |
| C2M2-02 | System security categorization |
| C2M2-03 | Security governance structure |
| C2M2-04 | Roles and responsibilities for critical systems |
| C2M2-05 | Security policy for operational technology |
C2M2: Incident Response & Recovery
Responding to incidents in critical infrastructure (C2M2)
| Code | Title |
|---|---|
| C2M2-16 | Incident response plan for operational disruptions |
| C2M2-17 | Recovery plan for critical systems |
| C2M2-18 | Reporting obligations to authorities |
| C2M2-19 | Coordination with sector-specific agencies |
| C2M2-20 | Exercises and drills for OT incidents |
C2M2: Supply Chain & Configuration
Managing supply chain and system configurations (C2M2)
| Code | Title |
|---|---|
| C2M2-21 | Supply chain risk management for critical components |
| C2M2-22 | Configuration management for OT systems |
| C2M2-23 | Change management procedures |
| C2M2-24 | Vulnerability assessment for critical systems |
C2M2: Systems Security
Securing operational technology systems (C2M2)
| Code | Title |
|---|---|
| C2M2-11 | Security patch management for OT |
| C2M2-12 | Malware prevention for operational systems |
| C2M2-13 | Network security monitoring |
| C2M2-14 | System security hardening |
| C2M2-15 | Ports and services management |
Cybersecurity Architecture
| Code | Title |
|---|---|
| ARCH-1 | Cybersecurity Architecture Strategy |
| ARCH-2 | Network Segmentation and Protection |
| ARCH-3 | Data Protection and Cryptography |
Event and Incident Response
| Code | Title |
|---|---|
| IR-1 | Event Detection and Triage |
| IR-2 | Incident Response and Recovery |
| IR-3 | Continuity of Operations |
Identity and Access Management
| Code | Title |
|---|---|
| IAM-1 | Identity Lifecycle Management |
| IAM-2 | Privileged and Remote Access Control |
Information Sharing and Communications
| Code | Title |
|---|---|
| ISC-1 | Information Sharing |
Program Management
| Code | Title |
|---|---|
| PGM-1 | Cybersecurity Program Management |
Risk Management
| Code | Title |
|---|---|
| RM-1 | Risk Management Strategy |
| RM-2 | Cyber Risk Identification and Analysis |
| RM-3 | Risk Response |
Situational Awareness
| Code | Title |
|---|---|
| SA-1 | Logging and Monitoring |
| SA-2 | Common Operating Picture |
Supply Chain and External Dependencies
| Code | Title |
|---|---|
| SCRM-1 | Supply Chain Cybersecurity Risk Management |
| SCRM-2 | Supplier Monitoring and Incident Notification |
Threat and Vulnerability Management
| Code | Title |
|---|---|
| TVM-1 | Threat Profile |
| TVM-2 | Vulnerability Management |
Workforce Management
| Code | Title |
|---|---|
| WORKFORCE-1 | Cyber Workforce Management |
| WORKFORCE-2 | Training and Awareness |
Your Compliance Coverage
If you comply with C2M2, you already cover:
NIS2 Directive
38%
18 controls mapped
Compare →DO-326A / ED-202A
36%
17 controls mapped
Compare →IEC 62443
36%
17 controls mapped
Compare →+ 647 more: BIMCO Cyber Security (36%), IEEE 1686 (36%)
See all 650 mapped frameworks ↓Maps to 650 other frameworks
Frequently Asked Questions
What is C2M2?
C2M2 is a compliance framework from United States with 16 domains and 47 controls. Cybersecurity Capability Maturity Model for energy sector It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does C2M2 have?
C2M2 has 47 controls organised across 16 domains. The largest domains are C2M2: Access Management (5 controls), C2M2: Asset Identification & Governance (5 controls), C2M2: Incident Response & Recovery (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does C2M2 map to?
C2M2 maps to 650 other compliance frameworks. The top mapping partners are NIS2 Directive (38% coverage), DO-326A / ED-202A (36% coverage), IEC 62443 (36% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with C2M2 compliance?
Start your C2M2 compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about C2M2 requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 47 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 700 frameworks.
Get Started Free →Free forever — no credit card required