C2M2
What is C2M2?
Cybersecurity Capability Maturity Model for energy sector. It comprises 22 controls organised across 10 domains, and applies in the United States.
How C2M2 maps to other frameworks
All 22 controls, each one mapped to the equivalent requirement in other standards, with the evidence that carries across and the mappings that were judged and rejected shown alongside. No account needed to look.
See the control mappings →The 10 domains C2M2 groups its controls into
Where C2M2 overlaps with the standards you already hold
What C2M2 means in your sector
What C2M2 means for your job
Questions people ask about C2M2
What is C2M2?
How many controls does C2M2 have?
Where does C2M2 apply?
What frameworks does C2M2 map to?
How do I get started with C2M2 compliance?
Query C2M2 programmatically
C2M2, its 22 controls and every mapping into other standards are available over a REST endpoint and an MCP server, so an agent can read them directly. The free tier is 10 calls a day and needs no signup.
C2M2 API reference and MCP config →What C2M2 requires, control by control
Each page carries the requirement text for one C2M2 control and what an assessor expects to see as evidence.
- ACCESS-1 Establish and Maintain Identities
- ACCESS-2 Control Logical and Physical Access
- ARCH-1 Establish a Cybersecurity Architecture Strategy
- ARCH-2 Implement Network Protections
- ARCH-3 Implement Data Security
- ASSET-1 Manage IT and OT Asset Inventory
- ASSET-2 Manage Asset Configuration and Changes
- PROGRAM-1 Establish and Maintain the Cybersecurity Program
- RESPONSE-1 Detect and Analyze Cybersecurity Events
- RESPONSE-2 Respond to and Recover from Cybersecurity Incidents
How ready are you for C2M2?
Answer 25 questions and get a professional readiness report with gap analysis, maturity scores, and prioritised action items. Results in 5 minutes.