U.S. Dept. of Energy Seeks Comment on Updated Cybersecurity Capability Maturity Model

Dec 1, 2021

Reading Time : 1 min

DOE first developed C2M2 in 2012 in partnership with the U.S. Department of Homeland Security and in collaboration with industry, private-sector and public-sector experts.1 Version 1.1 came in 2014, with separate versions targeted for the electricity and oil and natural gas subsectors. Version 2.0 is “designed for use across the energy sector, and can be used by other critical infrastructure sectors as well.” It includes “input from the Energy Sector C2M2 Working Group, which comprises 145 energy sector cybersecurity practitioners representing 77 energy sector and cybersecurity organizations.” According to DOE, it “better addresses new technologies like cloud, mobile, and artificial intelligence,” as well as “evolving threats such as ransomware and supply chain risks.” Since July, DOE has been piloting Version 2.0 with energy companies and utilities and now seeks to “obtain the broadest possible input” to “inform the C2M2 Working Group as it develops future model updates.” In particular, DOE seeks input on:

  • “The usefulness of C2M2 practices in evaluating and improving cybersecurity program capabilities.”
  • “The applicability of practice language to the IT and OT environments in use by energy sector organizations.”
  • “The readability of and ability to understand practice language.”
  • “The completeness of cybersecurity domains, objectives, and practices [in] the C2M2.”
  • “The effectiveness of guidance documentation (e.g., model introduction sections, domain introductions, and appendices) in conveying model concepts, architecture, and how to use the model.”
  • “Any other potential improvements to the C2M2 documentation or practices contained therein.”

Interested entities can submit comments to C2M2@hq.doe.gov using the Comment Submission Form available here.


1 See https://www.energy.gov/ceser/cybersecurity-capability-maturity-model-c2m2.

Share This Insight

Previous Entries

Speaking Energy

June 25, 2026

On June 18, 2026, the Federal Energy Regulatory Commission (FERC or the Commission) issued an order to the California Independent System Operator Corporation (CAISO) directing CAISO and CAISO transmission owners to show cause as to why CAISO’s tariff should not be found to be unjust and unreasonable (California Indep. Sys. Operator Corp., 195 FERC ¶ 61,214 (2026) (the Order)) because it fails to sufficiently:

...

Read More

Speaking Energy

June 24, 2026

On June 18, 2026, the Federal Energy Regulatory Commission (FERC or the Commission) issued an order to New York Independent System Operator, Inc. (NYISO) directing NYISO and NYISO transmission owners to show cause as to why NYISO’s tariff should not be found to be unjust and unreasonable (New York Independent System Operator, Inc., 195 FERC ¶ 61,216 (2026) (Order)) because it fails to sufficiently:

...

Read More

Speaking Energy

June 23, 2026

On June 18, 2026, the Federal Energy Regulatory Commission (FERC or the Commission) issued an order to Midcontinent Independent System Operator, Inc. (MISO) directing MISO and MISO transmission owners to show cause as to why MISO’s tariff should not be found to be unjust and unreasonable (Midcontinent Independent System Operator, Inc., 195 FERC ¶ 61,212 (2026) (Order)) because it fails to sufficiently:

...

Read More

Speaking Energy

June 23, 2026

On June 18, 2026, the Federal Energy Regulatory Commission (FERC or the Commission) issued an order to PJM Interconnection, L.L.C. directing PJM and PJM transmission owners to show cause as to why PJM’s tariff should not be found to be unjust and unreasonable (PJM Interconnection, L.L.C., 195 FERC ¶ 61,211 (2026) (the Order)) because it fails to sufficiently:

...

Read More

© 2026 Akin Gump Strauss Hauer & Feld LLP. All rights reserved. Attorney advertising. This document is distributed for informational use only; it does not constitute legal advice and should not be used as such. Prior results do not guarantee a similar outcome. Akin is the practicing name of Akin Gump LLP, a New York limited liability partnership authorized and regulated by the Solicitors Regulation Authority under number 267321. A list of the partners is available for inspection at Eighth Floor, Ten Bishops Square, London E1 6EG. For more information about Akin Gump LLP, Akin Gump Strauss Hauer & Feld LLP and other associated entities under which the Akin Gump network operates worldwide, please see our Legal Notices page.