C2M2 · Cybersecurity Capability Maturity Model · Evidence & Implementation Kit
Mature your cybersecurity with the C2M2, without turning the domains into controls yourself.
Every C2M2 domain handed to you as an adopt-ready control, across the ten domains and the maturity indicator levels, with the evidence a self-evaluation needs.
Maturity-ready in a weekend, not a quarter.
Here is the honest situation. The DoE Cybersecurity Capability Maturity Model is how organizations, especially in energy and critical infrastructure, measure and grow their cybersecurity: ten domains from asset and risk management to program management, each with practices grouped into objectives and rated by a maturity indicator level from MIL0 to MIL3. Running the self-evaluation and advancing each domain, with the evidence, is real work, and a domain where practices are performed but not documented or governed is exactly where the maturity level is not met.
This Kit removes that translation. It is every C2M2 domain written as an adopt-ready control you personalize in a weekend, with the evidence a self-evaluation needs.
What you get, the moment you buy
35
The domains as adopt-ready controls. Every C2M2 domain, from asset, threat and risk management through access, incident response, third-party risk, workforce, architecture and program management, written so you personalize and advance it, with the maturity indicator levels noted.
35
Evidence-a-self-evaluation-needs checklists. For each control, exactly the evidence a self-evaluation needs, plus where the maturity level is not met, so you advance the level.
1
C2M2 Maturity Matrix, pre-built. Every control in a working spreadsheet, ready to record maturity indicator level, status and evidence location across the domains.
1
Gap & Maturity Assessment. Score each control and the workbook returns your maturity as a single percentage per domain, and exactly what to advance next.
Grounded in the Cybersecurity Capability Maturity Model (C2M2), with the ten domains, the maturity indicator levels (MIL0 to MIL3) and the self-evaluation approach called out, applicable to IT and OT. Editable Word and Excel files.
Maturity is institutionalisation, not just doing
The C2M2 does not just ask whether you do a practice, it asks whether it is documented, resourced, governed by policy and reviewed for effectiveness. That is the difference between MIL1 and MIL3. This Kit builds the institutionalisation into every control, so your maturity reflects a program, not ad hoc activity.
What one control looks like
This is asset inventory and management, the foundation of the C2M2. All 35 are built to this depth.
ASSET-1 IT and OT asset inventory ASSET MANAGEMENT
Implement this control
[Organization] shall establish and maintain an inventory of IT and OT assets that are important to the delivery of the function, recording each asset with attributes such as owner, location, and criticality, and shall update the inventory when assets are added, changed, or retired so that coverage of the operating environment remains current.
Maturity note.
C2M2 domain Asset, Change, and Configuration Management (ASSET), Manage Asset Inventory objective. Inventory scope should reflect the function being evaluated.
Evidence a self-evaluation needs
- Asset inventory register listing IT and OT assets with owner and criticality attributes
- Change records showing inventory updates when assets are added or retired
- Procedure defining how asset inventory is created and maintained
- Screenshot or export from the asset management tooling used to hold the inventory
Common finding they raise: OT assets are often tracked separately or informally, leaving the enterprise inventory incomplete and asset criticality unrated.
Why this is not another template pack
- The evidence is the point. A practice you cannot evidence does not raise your maturity. This tells you the evidence a self-evaluation needs and where the level is not met, for every domain.
- The ten domains and MILs built in. The ten domains and the MIL0 to MIL3 institutionalisation model are written into the controls, so you measure and advance the way the C2M2 intends.
- Built on a mapped compliance corpus, not one person's opinion, from a graph of thousands of controls across standards.
- It compounds. The C2M2 underpins sector models like the AESCSF and aligns with the NIST CSF, so this work feeds your wider security program.
Who buys this
Organizations measuring and growing cybersecurity maturity, especially in energy and critical infrastructure, and the security and risk leads who own it, plus consultants running a self-evaluation. Whether it is a first evaluation or a maturity uplift, you save weeks and walk in with the domains and evidence structured.
By the end of the weekend you will have
✓ An adopt-ready control for all ten domains
✓ A completed C2M2 maturity matrix
✓ The evidence a self-evaluation needs
✓ Your target maturity indicator levels defined
✓ A per-domain maturity percentage and a fix list
✓ The gaps to your target level closed
Common questions
Is it really editable? Yes. Word and Excel files you own and adapt. No portal, no subscription.
What are the ten domains? Asset management, threat and vulnerability management, risk management, identity and access, situational awareness, incident response, third-party risk, workforce, architecture and program management. Each is built as controls.
What are maturity indicator levels? MIL0 to MIL3, measuring how institutionalised each domain's practices are. The Kit notes the level each control supports.
Does it apply to OT? Yes. The C2M2 is written for both IT and OT, and the controls reflect that.
What if it is not for me? A 30-day money-back guarantee.
Do not confuse doing a practice with a mature program.
Every C2M2 domain is fast to adopt with the Kit. It is instant, and it is guaranteed.
Add it to your cart and grow your maturity this weekend.
Instant digital download · 30-day money-back guarantee · The Art of Service Pty Ltd, GPO Box 2673, Brisbane QLD 4001 · support@theartofservice.com