Regulation — energy-specific
DOE C2M2 — Cybersecurity Capability Maturity Model
C2M2 is voluntary but load-bearing. Federal contracts, state PUC filings, insurance underwriting, and NERC CIP-013 supply-chain assessments all reference the model. AI/ML supplier scrutiny sits inside multiple C2M2 practice domains — especially Threat + Vulnerability Management (THREAT) and Supply Chain + External Dependencies (EXTERNAL-DEPENDENCIES).
What the model actually says
"The Cybersecurity Capability Maturity Model … is a tool to help organizations of any type or size to evaluate and improve their cybersecurity capabilities. The model measures cybersecurity practices at four maturity indicator levels (MIL) across ten domains …"
DOE C2M2 v2.1 — overview (paraphrased)
"Manage the cybersecurity aspects of relationships with external parties (for example, suppliers, customers, business partners, and internet service providers) … commensurate with the risk to the function …"
C2M2 EXTERNAL-DEPENDENCIES domain (paraphrased operative language)
What this means in plain English
- AI vendors are external dependencies. The model's supply-chain practices apply to the AI vendor's model + data pipeline + update cadence, not just to hardware suppliers.
- Maturity is measured on evidence. Higher MIL scores require documented, repeatable, independently-verifiable practices. Vendor self-attestation does not lift MIL.
C2M2 is voluntary in the sense that DOE does not fine operators for low scores. It is not voluntary in the sense that FERC, NERC, state PUCs, and cyber underwriters read the score.
What triggers the exposure in the sample
The sample operator relies on the grid-AI vendor's own dashboard as the primary AI-model monitoring. That stance caps EXTERNAL-DEPENDENCIES + THREAT + RISK maturity at low MIL levels. Independent verification, dated evidence, and named-principal attestation are the specific records that lift MIL scoring.
What the $499 Snapshot shows against this model
- Independent-verifier declaration — the EXTERNAL-DEPENDENCIES + THREAT evidence C2M2 assessors look for
- Distinct model family + retention pipeline — the RISK domain evidence
- Dated audit records + model version pin — the SITUATION + INFORMATION-SHARING record
- 3 fix-first items with owners + timelines — the PROGRAM + WORKFORCE evidence
See the signed independent-verifier declaration →
$499 Snapshot. 3 business days.
Independent-verifier evidence dated before your next C2M2 assessment or cyber renewal.
Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.