Cybersecurity Capability Maturity Model to NIST Cybersecurity Framework Mapping


The NIST National Cybersecurity Center of Excellence (NCCoE) and the U.S. Department of Energy (DOE) Office of Cybersecurity, Energy Security, and Emergency Response (CESER) have been working to map recent updates of the Cybersecurity Capability Maturity Model (C2M2) to the NIST Cybersecurity Framework (CSF).

The draft mapping of C2M2 Version 2.0 is complete. The draft mapping of Version 2.1 – the latest version of the C2M2 – is under way and will be posted for public comment when complete.


The NCCoE and CESER are seeking public comments on the draft C2M2 V2.0 to CSF mappings.

NIST requests that all comments be submitted by 11:59 pm Eastern Time on January 20, 2023.

Please submit your comments to Comments are requested on both mapping spreadsheets.

We encourage you to submit comments using this comment template.