Comparison · updated 2026-08-20
TIR-CMM vs C2M2 — a whole-programme maturity model against a response-only instrument
C2M2 is the US Department of Energy's Cybersecurity Capability Maturity Model: 356 practices across 10 domains, scored MIL0 to MIL3 independently per domain. TIR-CMM measures one thing — whether an organisation can actually stop an intrusion in time. Run C2M2 to grade the whole security programme; run TIR-CMM to grade response.
What is C2M2?
C2M2 is a self-evaluation maturity model published by the US Department of Energy, currently at Version 2.1, released June 2022. The model holds 356 cybersecurity practices grouped into 10 domains: ASSET, THREAT, RISK, ACCESS, SITUATION, RESPONSE, THIRD-PARTIES, WORKFORCE, ARCHITECTURE and PROGRAM. Each practice is assigned a maturity indicator level, and each domain is scored separately.
C2M2 began in the electricity subsector. The Electricity Subsector Cybersecurity Capability Maturity Model appeared in May 2012 with input from more than 250 energy sector experts, was generalised into C2M2 the same year, revised to v1.1 in February 2014, rebuilt as v2.0 in July 2021 with input from more than 145 energy sector experts, and refined to v2.1 in June 2022. DOE reports adoption across industries and globally, and over 3,500 requests for the PDF tool from US sectors outside energy.
How the Maturity Indicator Levels work
C2M2 uses four maturity indicator levels: MIL0 (practices are not performed), MIL1 Initiated, MIL2 Performed and MIL3 Managed. The critical structural fact, and the one most often got wrong in summaries of the model, is that the MILs apply independently to each domain. C2M2 does not produce a single organisational maturity number. An organisation can sit at MIL3 in ACCESS and MIL1 in RESPONSE, and the model regards that as a legitimate and informative result rather than an averaging problem.
MIL achievement is a hard gate. The C2M2 Self-Evaluation Guide states that to achieve a MIL in a domain, every practice in that MIL and in all preceding MILs must be answered Fully Implemented or Largely Implemented. One practice at Partially Implemented or Not Implemented stops the domain at the level below.
How a C2M2 evaluation runs
C2M2 is delivered as a facilitated self-evaluation. DOE offers a free HTML-based tool at c2m2.doe.gov and a free PDF-based tool by email request, and states that data stays local to the user's device. Practices are answered on a four-point scale — Fully Implemented, Largely Implemented, Partially Implemented, Not Implemented. The guide asks organisations to schedule at least eight hours for the workshop, or 60-to-90-minute virtual sessions inside one week; the stated design goal is a self-evaluation for a single function completed in one day without extensive preparation. The output is a report of donut charts showing implementation by MIL and by domain, plus the list of partially and unimplemented practices.
C2M2 issues no certificate. DOE publishes the model and the tools; the organisation scores itself.
What does TIR-CMM measure?
TIR-CMM measures one capability: whether an organisation can detect, decide, contain, evict and recover faster than the adversary moves, and prove it. The model holds 8 domains and 58 sub-capabilities with weights summing to 100, scored 0 to 5 across six bands from L0 Improvised to L5 Adaptive.
Alongside the domain score, TIR-CMM scores the Containment Lattice — 8 attack-path stages crossed with 8 asset classes, 64 cells maximum, of which a typical in-scope working set is 24 to 38. Each cell carries a Response Readiness Status of 0 to 3, where 3 means executed against a real incident or live-fire exercise inside the recency window, at the intended blast radius, within its stage time objective. Status 3 expires after 12 months, or immediately on an EDR swap, a SOAR migration, an on-call model change or the departure of the named owner.
TIR-CMM's central claim is a metric: MTTDecide, the interval between having a validated alert and being authorised to act on it, measured separately from MTTR. Containment Margin subtracts MTTD + MTTDecide + MTTC from a priority actor's breakout time. Tempo Ratio expresses the same relationship as a fraction, and a ratio at or above 2.0 caps the band at L1 regardless of how good the paperwork is.
How do they compare?
| Axis | C2M2 v2.1 | TIR-CMM v0.2 |
|---|---|---|
| Publisher | US Department of Energy, Office of Cybersecurity, Energy Security, and Emergency Response | Reza Adineh, UTIOM |
| Scope | The whole security programme — 10 domains | Incident response capability only |
| Structure | 356 practices in 10 domains | 58 sub-capabilities in 8 domains, plus a 64-cell lattice |
| Scale | MIL0-MIL3, four levels, applied per domain | 0.00-5.00, six bands L0-L5, one overall figure plus per-domain |
| Aggregation | No single organisational score by design | Weighted overall score, weights summing to 100 |
| Response coverage | One domain, RESPONSE, with four objectives | The entire model |
| Evidence handling | Four-point implementation self-rating; evidence quality is not scored | Four evidence grades VC0-VC3 capping sub-capability scores at 1, 2, 4 and 5 |
| Mechanical downgrades | One rule: all practices at and below a MIL must be FI or LI | Seven constraints R1-R7, which only ever lower a score |
| Adversary tempo | Not measured | Containment Margin and Tempo Ratio against actor breakout time |
| Certification | None; self-evaluation only | None; self-evaluation with three declared depths |
| Cost | Free | Free |
| Typical effort | At least eight hours; one day for a single function | 20 minutes Pulse, 1-2 hours Baseline, 2-4 weeks Assurance |
| Output | Donut charts by MIL and domain, unimplemented practice list | Band, domain radar, lattice heat map, binding constraints, prioritised roadmap |
| Data handling | Tool data stays local to the device | Runs entirely in the browser; nothing transmitted |
Do they overlap?
The overlap between the two models is one domain wide and several layers deep. C2M2's RESPONSE domain — full name Event and Incident Response, Continuity of Operations — carries the purpose "establish and maintain plans, procedures, and technologies to detect, analyze, mitigate, respond to, and recover from cybersecurity events and incidents and to sustain operations during cybersecurity incidents, commensurate with the risk to critical infrastructure and organizational objectives." RESPONSE holds four objectives: detect and analyse events and incidents, respond to events and incidents, sustain operations during incidents, and the domain's management activities.
Everything TIR-CMM measures sits inside that one C2M2 domain, and TIR-CMM's 58 sub-capabilities plus 64-cell lattice expand it by roughly an order of magnitude. The relationship is not competitive. C2M2's RESPONSE domain and TIR-CMM's whole model answer the same question at two different resolutions.
Outside RESPONSE the overlap thins fast. C2M2's SITUATION and THREAT domains correspond to detection and threat intelligence, which TIR-CMM deliberately excludes and consumes as an input constraint — R4 caps the RE, CE and FI domains at detection maturity plus one. C2M2's ARCHITECTURE domain touches the lattice's S0 Prevent & Harden stage, which the model weights most heavily at λ = 1.6 precisely because an attack path closed by architecture never needs a response. The remaining six C2M2 domains have no TIR-CMM counterpart at all.
Where C2M2 is stronger
C2M2 is far broader, and breadth is the point. C2M2's 356 practices cover asset management, risk management, identity, workforce, third parties, architecture and programme management — none of which TIR-CMM touches. A CISO who needs one instrument that reads across the entire security programme should run C2M2 and should not pretend a response model substitutes for it.
C2M2 also carries institutional weight TIR-CMM does not have and does not claim: a US federal product with fourteen years of history, four public releases across 2012, 2014, 2021 and 2022, a documented public comment process, published alignment to the NIST Cybersecurity Framework and supplemental guidance mapping the model to CMMC. TIR-CMM is version 0.2, published on 17 August 2026, with no adoption history, no accreditation body and no institutional sponsor. A board that recognises the DOE seal will not recognise this one.
The per-domain MIL design is genuinely better than a single number for programme-level reporting. C2M2 refuses to average away a MIL1 domain behind six MIL3 domains, which is exactly the failure mode of composite maturity scores. TIR-CMM reports a single weighted figure because it is measuring a single capability, but for programme-wide use C2M2's refusal to aggregate is the more honest design.
Use C2M2 instead if you need one assessment covering the whole security programme, you operate in the energy sector or another critical infrastructure sector where C2M2 is already the recognised instrument, you need a result a regulator or a federal counterparty will accept on sight, or you have never measured anything and need a baseline across all ten domains before deciding where to go deep.
Where TIR-CMM is stronger
TIR-CMM is deeper on response by design, and depth here means specific things C2M2 does not attempt. C2M2 scores whether practices are implemented. TIR-CMM scores whether the implemented ones would survive contact with a clock. Nothing in RESPONSE's four objectives measures the interval between a validated alert and an authorised containment decision, and that interval — MTTDecide — is where TIR-CMM argues most of the loss sits.
Evidence handling differs sharply. C2M2's four-point scale records how much of a practice is implemented, as judged in a facilitated discussion. TIR-CMM's R3 constraint caps a sub-capability by the class of artefact behind it: VC0 assertion caps at 1, VC1 design or policy at 2, VC2 implemented and tested at 4, VC3 repeatably validated at 5. A blank evidence level is treated as VC0. The cap is a ceiling, not a conversion — VC3 evidence behind a capability scored 2 leaves the score at 2.
TIR-CMM applies seven mechanical constraints, of which two have no counterpart in any other maturity model. R2, the authority ceiling, holds automation and containment scores to the authority score plus one, on the ground that automation nobody is permitted to fire is a demonstration and not a capability. R5, the tempo ceiling, caps the band at L1 when the containment chain takes twice the adversary's breakout time. R7 caps the band by the depth of the assessment itself: Pulse at L3, Baseline at L4, with L5 reachable only through an Assurance assessment carrying independent evidence review and a declared conflict-of-interest position.
C2M2 has one mechanical rule — the MIL gate — and it is a good one. TIR-CMM has seven, all of which only ever lower a score, and none of which can be argued with. Read scoring and constraints for the full application order.
Perishability is the last difference. C2M2 records a point-in-time implementation judgement. TIR-CMM expires a proven lattice cell after 12 months, and immediately on tooling change, on-call model change, reorganisation, architecture change or a change of managed provider — because response capability rests on people and authority, and organisations change those faster than they change detection logic.
Can you run both?
Running both is the intended pattern, and the sequencing is straightforward. C2M2 first, as the programme-wide read: eight hours, ten domains, a MIL per domain. If RESPONSE comes back at MIL1 or MIL2 while the rest of the programme sits at MIL2 or MIL3, that is the signal to go deep — and going deep is what TIR-CMM is for.
A C2M2 result tells you which RESPONSE practices are not implemented. A TIR-CMM result tells you whether the implemented ones would work at 03:00 on a Sunday, which lattice cells on a path to a crown jewel have no response option at all, and whether the containment chain finishes inside the breakout window. C2M2 identifies the gap; TIR-CMM explains why it persists. Start with the 20-minute Pulse before committing to a Baseline.
One caution. TIR-CMM's bands and C2M2's MILs are not convertible: TIR-CMM runs 0.00 to 5.00 across six bands, C2M2 runs MIL0 to MIL3 per domain against a fixed practice set. Anyone presenting "L3 equals MIL3" in a board pack is inventing an equivalence neither publisher supports.
Which should you run?
If you need to measure the whole security programme, run C2M2. Ten domains, 356 practices, eight hours, free, federally published, and MILs that refuse to hide a weak domain behind strong ones. TIR-CMM covers roughly one tenth of that surface and is not a substitute.
If C2M2's RESPONSE domain is where your programme is weakest, run TIR-CMM Baseline next. One to two hours, all 58 sub-capabilities with evidence grades, the lattice scoped to your crown jewels, the authority map and measured response tempo. TIR-CMM will tell you which of the seven constraints is binding, and in most organisations the answer is R1 — every domain held to the rehearsal score plus one.
If you have never measured anything and have two hours, run TIR-CMM Pulse first, then C2M2. Twenty questions capped at L3 will tell you whether response is the problem before you spend a day scoring ten domains.
If you are in the energy sector, run C2M2 regardless. C2M2 is the instrument the sector recognises, and no result from a version 0.2 model published in August 2026 will change that. Use TIR-CMM as the depth instrument underneath it, not as a replacement for it.