C2M2
What is C2M2?
Cybersecurity Capability Maturity Model
A maturity model published by the US Department of Energy. It groups practices into domains and rates each domain against Maturity Indicator Levels. The AESCSF adapts C2M2 for the Australian energy sector.
What it is used for
C2M2 lets an organisation evaluate its cyber security practices against a structured set of domains and rate each against Maturity Indicator Levels. It was written for the energy sector but is used more broadly.
It is one of the frameworks a responsible entity can nominate under the CIRMP Rules.
Relationship to the AESCSF
The AESCSF is an Australian adaptation of C2M2 maintained by AEMO, adding Security Profiles and sector-specific content. An entity familiar with one will recognise the structure of the other.
Read more
- AESCSF Security Profile 2: What the Enhanced CIRMP Rules Now Require
The AESCSF has two scales and people mix them up. Maturity Indicator Levels measure where you are; Security Profiles say where you must be. The Enhanced CIRMP Rules move named energy asset classes to SP-2 by June 2028, and cumulative profiles make that further than it looks.
See also
- AESCSF Australian Energy Sector Cyber Security Framework A cyber security framework maintained by AEMO for the Australian energy sector, adapted from the US DOE C2M2.
- MIL Maturity Indicator Level The maturity scale used by C2M2 and by the AESCSF, running from MIL-0 to MIL-3.
- SP Security Profile The target state scale used by the AESCSF, running SP-1, SP-2 and SP-3 for low, moderate and high criticality entities.
O/IT Cyber advises Australian critical infrastructure operators on risk management programs, framework nomination and OT security. Talk to us.