C2M2 — Cybersecurity Capability Maturity Model v2.1
A maturity model developed by the US Department of Energy to help critical infrastructure organisations evaluate and improve their cyber security capabilities. Assesses practices across 10 domains at four maturity indicator levels.
See where NodeZero appliesWhat is C2M2?
The Cybersecurity Capability Maturity Model (C2M2) was developed by the US Department of Energy to help organisations in the energy sector evaluate and improve their cyber security capabilities. Version 2.1 organises practices across 10 domains -- from risk management and identity access to threat management and cybersecurity architecture -- each assessed at four Maturity Indicator Levels (MIL 0-3). While it originated in the energy sector, C2M2 is now used across critical infrastructure and is approved as one of five cyber frameworks under Australia's SOCI CIRMP rules.
C2M2 is primarily a maturity and governance model. Most of its 356 practices address processes, policies, and organisational capabilities rather than specific technical controls. This means that achieving maturity requires demonstrating that practices are not just performed but are planned, managed, and measured. For domains like Identity and Access Management and Threat and Vulnerability Management, however, technical evidence is essential to prove that practices are actually effective.
Where NodeZero applies
NodeZero provides strong technical evidence across the five domains most dependent on exploitable reality: Asset management (discovery and crown-jewel identification), Identity and access (credential, MFA, and privilege-escalation testing including cloud IAM), Threat and vulnerability management (direct exploitation, scanner ingest, attacker-technique correlation), Situational awareness (deception, EDR effectiveness, attacker-behaviour telemetry), and Cybersecurity architecture (segmentation and trust-boundary validation). For workforce, incident response, supply chain, and programme-management domains we contribute narrower technical evidence and clearly delineate what remains organisational work.
This mapping reflects our best-effort analysis of where NodeZero's autonomous pentesting produces relevant technical evidence against each requirement. It is intended to help you focus security effort on the controls NodeZero can test — not to serve as a compliance certification. You remain responsible for your own compliance assessment, for validating applicability to your environment, and for evidencing the requirements NodeZero does not directly test.
Please note the following require separate evidence: Risk management, Event and incident response, continuity of operations, Workforce management and Cybersecurity programme management.
Showing coverage grouped by compliance category.
Asset, change, and configuration management
Partial coverage. NodeZero discovers assets and identifies configuration weaknesses.
Internal pentestingCore
Enumerates every reachable host and service from the attacker perspective — often surfacing assets the inventory doesn't track.
High-Value TargetingElite only
Infers which assets carry the most business risk and prioritises attack paths to them — supporting input to the documented asset-prioritisation criteria this practice asks you to define and apply.
Identity and access management
Strong coverage. NodeZero directly tests IAM controls and credential security.
AD Password AuditCore
First AI to solve GOAD in 14 minutes (Horizon3-reported); audits password strength and reuse on privileged, service, and break-glass accounts — it is not uncommon for NodeZero to crack more than 50% of the passwords it tests on a first audit.
Phishing Impact TestingCore
Takes a phished credential and demonstrates its blast radius — what an attacker reaches when a single factor is enough — surfacing higher-risk access where a stronger or multifactor credential is not actually required.
Internal pentestingCore
Proves end-to-end paths from initial access to domain compromise — evidence of whether least-privilege is actually enforced.
BloodHound (integrated)Core
Built-in attack-graph visualisation — surfaces the higher-risk, over-privileged relationships ACCESS-2g (MIL2) requires extra scrutiny on.
Cloud pentestingCore
Extends privileged-credential validation into cloud IAM and tests whether those credentials are tightly scoped across on-prem and cloud.
Threat and vulnerability management
Strongest alignment. This domain is exactly what autonomous pentesting produces evidence for.
Internal pentestingCore
Returns proof of which vulnerabilities are actually exploitable in your environment — vulnerability information interpreted for the function, not theoretical CVSS lists.
Rapid ResponsePro & Elite
Rapid Response tests are delivered often within hours of disclosure, and in some cases ahead of the public patch — attacker-first assessment inside the detection window.
Vulnerability Risk IntelligenceElite only
Ingests existing scanner exports and classifies each CVE-asset pair as Confirmed Exploitable, Contextually Exploitable, or Threat Actor Pressure — attacker-first prioritisation of the scanner backlog.
Threat Actor IntelligenceElite only
Maps your real attack paths to MITRE ATT&CK and named threat-actor behaviour — produces environment-specific threat intelligence alongside external sources.
Vulnerability Management HubCore
Findings flow to Jira and ServiceNow through existing integrations, tracked through an Open → Mitigated → Regressed lifecycle, with Quick Verify to confirm a mitigation actually held.
High-Value TargetingElite only
Concentrates discovery and exploitation effort on the assets that carry the most business risk — vulnerability information that explicitly addresses the higher-priority subset.
Quick VerifyCore
Re-tests the exact attack chain after a remediation is applied and reports whether the action actually closed the vulnerability — direct effectiveness review built into the workflow.
Situational awareness
Direct coverage via deception, EDR effectiveness measurement, and attacker-behaviour generation.
NodeZero TripwiresPro & Elite
Honeytoken decoys on high-risk assets alert the moment an attacker interacts — routed via Splunk, Sentinel, or webhook into the same monitoring programme SITUATION-2 expects.
Internal pentestingCore
Every NodeZero action is timestamped with proofs and commands — correlate with your SIEM to validate whether your defined indicators actually fire.
Endpoint Security EffectivenessCore
Per-host and per-vendor EDR block/allow data mapped to MITRE ATT&CK — concrete effectiveness metrics for the monitoring layer.
Supply chain and external dependencies management
Minimal coverage. NodeZero tests the technical boundary where a supplier compromise would land.
Segmentation testingCore
Proves whether a supplier-side compromise would be contained at the interconnect or cascade into your critical assets — direct evidence that the controls protecting against third-party risk actually hold.
Phishing Impact TestingCore
Where a supplier credential or interconnect can be tested, proves how far that access reaches into your environment — one input to your supplier risk assessment, not the assessment itself.
High-Value TargetingElite only
Discovery + High-Value Targeting flag third-party connections that carry privileged reach into critical assets — direct evidence of which suppliers warrant the escalated-prioritisation tier.
Cybersecurity architecture
Direct coverage — tests whether architectural security controls actually hold.
Segmentation testingCore
Enumerates IPs, ports, services, and applications across the network to prove whether the security-zone boundaries hold the way the architecture says they should.
Internal pentestingCore
Proves end-to-end attack paths that cross architectural boundaries — evidence that the boundary-enforcement controls are not holding in practice. Whether a cybersecurity architecture is documented and maintained remains governance work.
Cloud pentestingCore
Hybrid architectures are where pentesters find the most gaps; cloud pentesting tests privilege-escalation paths between on-prem and AWS/Azure/K8s boundaries.
BloodHound (integrated)Core
Attack-graph visualisation surfaces every over-privileged user and service account — the gap between policy and practice that ARCHITECTURE-3c (MIL2) requires you to close.
Endpoint Security EffectivenessCore
Reports per-host EDR and host-firewall block/allow outcomes across 40+ vendors — direct evidence of which assets actually have the required security applications enforced.
Web application pentestingPriced separately
Runs the penetration-testing element of this practice against in-house-developed and in-house-tailored applications — OWASP Top 10 weaknesses, access-control failures and business-logic flaws, in pre-production and production, on a periodic or change-triggered cadence. Static, dynamic-code and fuzz testing remain separate activities.
External pentestingCore
Exercises internet-facing applications and services from the attacker's perspective, on a continuous cadence and after changes — the perimeter half of the security testing this domain expects, alongside the application-layer testing above.
See every control mapped to NodeZero
The full control-by-control coverage map — every C2M2requirement matched to the NodeZero capability that produces evidence for it, with maturity-level grouping and source citations. We'll email you the link and a downloadable copy.
Who does this apply to?
C2M2 was originally developed for the US energy sector and remains most widely adopted by electricity utilities, oil and gas companies, and pipeline operators in the United States. However, its sector-agnostic design means it can be applied by any organisation seeking a maturity-based approach to cyber security improvement.
In Australia, C2M2 is one of five frameworks approved under the SOCI CIRMP rules for meeting the cyber and information security hazard obligation. Critical infrastructure entities -- particularly those in the energy sector who may already be familiar with C2M2 through US operations or partnerships -- can adopt it as their CIRMP cyber framework. It is also referenced by organisations in the water, transport, and telecommunications sectors.
C2M2 is best suited for organisations that want to benchmark their current maturity and build a structured improvement roadmap. If your organisation is focused on measuring where you are today and demonstrating progress over time -- rather than achieving a pass/fail certification -- C2M2 provides that maturity-based lens.
Four levels, scored per domain
C2M2 scores each of its 10 domains at one of four Maturity Indicator Levels (MIL). Organisations select a target MIL per domain based on risk and obligations — for designated asset classes under the Enhanced CIRMP Rules 2026, the SOCI cyber hazard obligation rises to C2M2 MIL 2, phasing in over 24 months to June 2028, and most critical infrastructure entities aim higher in the domains directly exposed to attack.
One or more of the MIL 1 practices are not performed. The domain has not yet reached the foundational baseline and cannot be counted toward SOCI obligations.
DOE definition →All MIL 1 practices are performed, establishing a foundational set of cyber security activities. Practices may be ad-hoc but are present. This is the baseline SOCI CIRMP recognises.
DOE definition →Practices are documented, planned, and resourced. Stakeholders are identified, adequate resources are provided, and practices are applied consistently across the relevant parts of the organisation.
DOE definition →Practices are analysed for effectiveness, adapted based on evidence, and integrated across the organisation. Continuous improvement is supported by metrics, governance, and formal review.
DOE definition →One or more of the MIL 1 practices are not performed. The domain has not yet reached the foundational baseline and cannot be counted toward SOCI obligations.
DOE definition →All MIL 1 practices are performed, establishing a foundational set of cyber security activities. Practices may be ad-hoc but are present. This is the baseline SOCI CIRMP recognises.
DOE definition →Practices are documented, planned, and resourced. Stakeholders are identified, adequate resources are provided, and practices are applied consistently across the relevant parts of the organisation.
DOE definition →Practices are analysed for effectiveness, adapted based on evidence, and integrated across the organisation. Continuous improvement is supported by metrics, governance, and formal review.
DOE definition →Close the gaps before your next assessment
See how NodeZero generates audit-ready evidence for your compliance obligations. We'll walk you through where NodeZero applies for your specific framework.