Regulation — energy-specific

DOE C2M2 — Cybersecurity Capability Maturity Model

C2M2 is voluntary but load-bearing. Federal contracts, state PUC filings, insurance underwriting, and NERC CIP-013 supply-chain assessments all reference the model. AI/ML supplier scrutiny sits inside multiple C2M2 practice domains — especially Threat + Vulnerability Management (THREAT) and Supply Chain + External Dependencies (EXTERNAL-DEPENDENCIES).

What the model actually says

"The Cybersecurity Capability Maturity Model … is a tool to help organizations of any type or size to evaluate and improve their cybersecurity capabilities. The model measures cybersecurity practices at four maturity indicator levels (MIL) across ten domains …" DOE C2M2 v2.1 — overview (paraphrased)
"Manage the cybersecurity aspects of relationships with external parties (for example, suppliers, customers, business partners, and internet service providers) … commensurate with the risk to the function …" C2M2 EXTERNAL-DEPENDENCIES domain (paraphrased operative language)

What this means in plain English

  1. AI vendors are external dependencies. The model's supply-chain practices apply to the AI vendor's model + data pipeline + update cadence, not just to hardware suppliers.
  2. Maturity is measured on evidence. Higher MIL scores require documented, repeatable, independently-verifiable practices. Vendor self-attestation does not lift MIL.

C2M2 is voluntary in the sense that DOE does not fine operators for low scores. It is not voluntary in the sense that FERC, NERC, state PUCs, and cyber underwriters read the score.

What triggers the exposure in the sample

The sample operator relies on the grid-AI vendor's own dashboard as the primary AI-model monitoring. That stance caps EXTERNAL-DEPENDENCIES + THREAT + RISK maturity at low MIL levels. Independent verification, dated evidence, and named-principal attestation are the specific records that lift MIL scoring.

What the $499 Snapshot shows against this model

See the signed independent-verifier declaration →

How does this help me?

C2M2 scoring feeds directly into cyber insurance renewal, federal contract eligibility, and NERC CIP-013 audit-response stance.

Read: DOE C2M2 -- what an independent-verifier record does for MIL scoring →

$499 Snapshot. 3 business days.

Independent-verifier evidence dated before your next C2M2 assessment or cyber renewal.

Buy $499
Snapshot credit applies to Baseline ($2,500) or Enterprise Attestation ($35-55K) upgrade within 30 days.