DrochaidHorizon3.ai
NodeZero/Australia & NZ compliance/C2M2
Australia & NZ compliance

C2M2 — Cybersecurity Capability Maturity Model v2.1

A maturity model developed by the US Department of Energy to help critical infrastructure organisations evaluate and improve their cyber security capabilities. Assesses practices across 10 domains at four maturity indicator levels.

See where NodeZero applies

What is C2M2?

The Cybersecurity Capability Maturity Model (C2M2) was developed by the US Department of Energy to help organisations in the energy sector evaluate and improve their cyber security capabilities. Version 2.1 organises practices across 10 domains -- from risk management and identity access to threat management and cybersecurity architecture -- each assessed at four Maturity Indicator Levels (MIL 0-3). While it originated in the energy sector, C2M2 is now used across critical infrastructure and is approved as one of five cyber frameworks under Australia's SOCI CIRMP rules.

C2M2 is primarily a maturity and governance model. Most of its 356 practices address processes, policies, and organisational capabilities rather than specific technical controls. This means that achieving maturity requires demonstrating that practices are not just performed but are planned, managed, and measured. For domains like Identity and Access Management and Threat and Vulnerability Management, however, technical evidence is essential to prove that practices are actually effective.

US DOE — C2M2

Where NodeZero applies

NodeZero provides strong technical evidence across the five domains most dependent on exploitable reality: Asset management (discovery and crown-jewel identification), Identity and access (credential, MFA, and privilege-escalation testing including cloud IAM), Threat and vulnerability management (direct exploitation, scanner ingest, attacker-technique correlation), Situational awareness (deception, EDR effectiveness, attacker-behaviour telemetry), and Cybersecurity architecture (segmentation and trust-boundary validation). For workforce, incident response, supply chain, and programme-management domains we contribute narrower technical evidence and clearly delineate what remains organisational work.

C2M2 v2.1 (June 2022)

This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.

Please note the following require separate evidence: Risk management, Event and incident response, continuity of operations, Workforce management and Cybersecurity programme management.

Showing coverage grouped by compliance category.

Asset, change, and configuration management

Partial coverage. NodeZero discovers assets and identifies configuration weaknesses.

Internal pentestingCore

Enumerates every reachable host and service from the attacker perspective — often surfacing assets the inventory doesn't track.

High-Value TargetingElite only

Infers which assets carry the most business risk and prioritises attack paths to them — supporting input to the documented asset-prioritisation criteria this practice asks you to define and apply.

4 controls mapped

Identity and access management

Strong coverage. NodeZero directly tests IAM controls and credential security.

AD Password AuditCore

First AI to solve GOAD in 14 minutes (Horizon3-reported); audits password strength and reuse on privileged, service, and break-glass accounts — it is not uncommon for NodeZero to crack more than 50% of the passwords it tests on a first audit.

Phishing Impact TestingCore

Takes a phished credential and demonstrates its blast radius — what an attacker reaches when a single factor is enough — surfacing higher-risk access where a stronger or multifactor credential is not actually required.

Internal pentestingCore

Proves end-to-end paths from initial access to domain compromise — evidence of whether least-privilege is actually enforced.

BloodHound (integrated)Core

Built-in attack-graph visualisation — surfaces the higher-risk, over-privileged relationships ACCESS-2g (MIL2) requires extra scrutiny on.

Cloud pentestingCore

Extends privileged-credential validation into cloud IAM and tests whether those credentials are tightly scoped across on-prem and cloud.

7 controls mapped

Threat and vulnerability management

Strongest alignment. This domain is exactly what autonomous pentesting produces evidence for.

Internal pentestingCore

Returns proof of which vulnerabilities are actually exploitable in your environment — vulnerability information interpreted for the function, not theoretical CVSS lists.

Rapid ResponsePro & Elite

Rapid Response tests are delivered often within hours of disclosure, and in some cases ahead of the public patch — attacker-first assessment inside the detection window.

Vulnerability Risk IntelligenceElite only

Ingests existing scanner exports and classifies each CVE-asset pair as Confirmed Exploitable, Contextually Exploitable, or Threat Actor Pressure — attacker-first prioritisation of the scanner backlog.

Threat Actor IntelligenceElite only

Maps your real attack paths to MITRE ATT&CK and named threat-actor behaviour — produces environment-specific threat intelligence alongside external sources.

Vulnerability Management HubCore

Findings flow to Jira and ServiceNow through existing integrations, tracked through an Open → Mitigated → Regressed lifecycle, with Quick Verify to confirm a mitigation actually held.

High-Value TargetingElite only

Concentrates discovery and exploitation effort on the assets that carry the most business risk — vulnerability information that explicitly addresses the higher-priority subset.

Quick VerifyCore

Re-tests the exact attack chain after a remediation is applied and reports whether the action actually closed the vulnerability — direct effectiveness review built into the workflow.

12 controls mapped

Situational awareness

Direct coverage via deception, EDR effectiveness measurement, and attacker-behaviour generation.

NodeZero TripwiresPro & Elite

Honeytoken decoys on high-risk assets alert the moment an attacker interacts — routed via Splunk, Sentinel, or webhook into the same monitoring programme SITUATION-2 expects.

Internal pentestingCore

Every NodeZero action is timestamped with proofs and commands — correlate with your SIEM to validate whether your defined indicators actually fire.

Endpoint Security EffectivenessCore

Per-host and per-vendor EDR block/allow data mapped to MITRE ATT&CK — concrete effectiveness metrics for the monitoring layer.

3 controls mapped

Supply chain and external dependencies management

Minimal coverage. NodeZero tests the technical boundary where a supplier compromise would land.

Segmentation testingCore

Proves whether a supplier-side compromise would be contained at the interconnect or cascade into your critical assets — direct evidence that the controls protecting against third-party risk actually hold.

Phishing Impact TestingCore

Where a supplier credential or interconnect can be tested, proves how far that access reaches into your environment — one input to your supplier risk assessment, not the assessment itself.

High-Value TargetingElite only

Discovery + High-Value Targeting flag third-party connections that carry privileged reach into critical assets — direct evidence of which suppliers warrant the escalated-prioritisation tier.

3 controls mapped

Cybersecurity architecture

Direct coverage — tests whether architectural security controls actually hold.

Segmentation testingCore

Enumerates IPs, ports, services, and applications across the network to prove whether the security-zone boundaries hold the way the architecture says they should.

Internal pentestingCore

Proves end-to-end attack paths that cross architectural boundaries — evidence that the boundary-enforcement controls are not holding in practice. Whether a cybersecurity architecture is documented and maintained remains governance work.

Cloud pentestingCore

Hybrid architectures are where pentesters find the most gaps; cloud pentesting tests privilege-escalation paths between on-prem and AWS/Azure/K8s boundaries.

BloodHound (integrated)Core

Attack-graph visualisation surfaces every over-privileged user and service account — the gap between policy and practice that ARCHITECTURE-3c (MIL2) requires you to close.

Endpoint Security EffectivenessCore

Reports per-host EDR and host-firewall block/allow outcomes across 40+ vendors — direct evidence of which assets actually have the required security applications enforced.

Web application pentestingPriced separately

Runs the penetration-testing element of this practice against in-house-developed and in-house-tailored applications — OWASP Top 10 weaknesses, access-control failures and business-logic flaws, in pre-production and production, on a periodic or change-triggered cadence. Static, dynamic-code and fuzz testing remain separate activities.

External pentestingCore

Exercises internet-facing applications and services from the attacker's perspective, on a continuous cadence and after changes — the perimeter half of the security testing this domain expects, alongside the application-layer testing above.

11 controls mapped
C2M2 kit

See every control mapped to NodeZero

The full control-by-control coverage map — every C2M2requirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.

Who does this apply to?

C2M2 was originally developed for the US energy sector and remains most widely adopted by electricity utilities, oil and gas companies, and pipeline operators in the United States. However, its sector-agnostic design means it can be applied by any organisation seeking a maturity-based approach to cyber security improvement.

In Australia, C2M2 is one of five frameworks approved under the SOCI CIRMP rules for meeting the cyber and information security hazard obligation. Critical infrastructure entities -- particularly those in the energy sector who may already be familiar with C2M2 through US operations or partnerships -- can adopt it as their CIRMP cyber framework. It is also referenced by organisations in the water, transport, and telecommunications sectors.

C2M2 is best suited for organisations that want to benchmark their current maturity and build a structured improvement roadmap. If your organisation is focused on measuring where you are today and demonstrating progress over time -- rather than achieving a pass/fail certification -- C2M2 provides that maturity-based lens.

Maturity indicator levels

Four levels, scored per domain

C2M2 scores each of its 10 domains at one of four Maturity Indicator Levels (MIL). Organisations select a target MIL per domain based on risk and obligations — for designated asset classes under the Enhanced CIRMP Rules 2026, the SOCI cyber hazard obligation rises to C2M2 MIL 2, phasing in over 24 months to June 2028, and most critical infrastructure entities aim higher in the domains directly exposed to attack.

MIL 0
Practices not performed

One or more of the MIL 1 practices are not performed. The domain has not yet reached the foundational baseline and cannot be counted toward SOCI obligations.

DOE definition
MIL 1SOCI minimum
Initial practices

All MIL 1 practices are performed, establishing a foundational set of cyber security activities. Practices may be ad-hoc but are present. This is the baseline SOCI CIRMP recognises.

DOE definition
MIL 2
Planned and managed

Practices are documented, planned, and resourced. Stakeholders are identified, adequate resources are provided, and practices are applied consistently across the relevant parts of the organisation.

DOE definition
MIL 3
Measured and improving

Practices are analysed for effectiveness, adapted based on evidence, and integrated across the organisation. Continuous improvement is supported by metrics, governance, and formal review.

DOE definition
Trusted by 7,013 organisations worldwide
Powers the NSA's CAPT program310,332 pentests4.7 Gartner

Close the gaps before your next assessment

See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.