Overview
The C2M2 was initiated by the U.S. Department of Energy in collaboration with energy and cybersecurity industry stakeholders to address cybersecurity risks in critical infrastructure, including the energy sector. The model offers a maturity-based approach, with practices organized into domains, objectives, and maturity indicator levels (MILs). Initially targeted at the energy sector, it has been adopted across industries worldwide. Version 2.1, released in June 2022, features improvements in technology alignment, threat relevance, and usability. Supplemental tools, such as self-evaluation platforms and mapping guides, enhance user accessibility and simplify adoption. The model is designed to measure and improve cybersecurity over time, aiding organizations in prioritizing security investments and achieving targeted maturity levels.