RegScale Announces Support for the DOE C2M2 Catalog

October 4, 2022 | By J. Travis Howerton

The Cybersecurity Capability Maturity Model is a free tool to help organizations evaluate their cybersecurity capabilities and optimize security investments. It uses a set of industry-vetted cybersecurity practices focused on both information technology (IT) and operations technology (OT) assets and environments. While the U.S. energy industry led development of the C2M2 and championed its adoption, any organization—regardless of size, type, or industry—can use the model to evaluate, prioritize, and improve their cybersecurity capabilities.

At RegScale, we give energy sector customers easy and free tools to get started with building a fully compliant C2M2 program with support for tracking policies, related assessments, evidence collection, issues management/performance improvement, and other related workflows. As of October 4, 2022, RegScale has announced that we officially support the DOE C2M2 Version 2.1 as a catalog within our platform with automated tools/wizards for building compliant inspection programs. In addition, we have published multiple machine readable formats of C2M2 including the raw JSON and NIST OSCAL that are available upon request. These artifacts are freely available for others to reuse in their compliance automation programs using machine readable formats.

Schedule a free demo today to learn how RegScale can help you continuously meet your C2M2 requirements. If you are ready to start automating your compliance processes for creating and managing C2M2 requirements in the energy sector, this demo will also show how you can leverage RegScale to deliver continuous compliance. In addition to offering free tools, we have experienced compliance professionals who can assist you in creating robust C2M2 compliance artifacts that will help you pass audits and reduce your risk with ease. With RegScale, our customers get software with a service to provide a concierge like experience for reducing risk related to their energy sector IT and OT systems.

Ready to get started?

Choose the path that is right for you! 

Skip the line

My organization doesn’t have GRC tools yet and I am ready to start automating my compliance with continuous monitoring pipelines now. 


My organization already has legacy compliance software, but I want to automate many of the manual processes that feed it.