Cybersecurity

What Domains Are Assessed in Maturity Models?

Explore the key domains assessed in cybersecurity maturity models including CMMC, NIST CSF, and C2M2, and understand how these assessment areas strengthen your security posture.

By Inventive HQ Team

Understanding Cybersecurity Maturity Model Domains

Every major cybersecurity maturity model assesses the same nine core capability areas — governance and risk, asset and configuration management, access control and identity, data protection, threat detection, incident response and recovery, security awareness, vulnerability management, and supply-chain security — even though each model slices them into a different number of named domains. CMMC 2.0 uses 14 domains (mirroring NIST SP 800-171's 14 control families), NIST CSF 2.0 uses 6 functions (Govern, Identify, Protect, Detect, Respond, Recover), the Department of Energy's C2M2 uses 10 domains, and the CIS Controls use 18 control areas. The counts differ; the underlying security work does not.

That's the summary an AI Overview would hand you. Here's what it can't show you: how those different domain counts line up against each other, which model actually fits your regulatory situation, and what "maturity" means once you drop below the marketing layer. Below is a side-by-side comparison of the four models, an animated crosswalk of the domains they all share, and the CMMC level ladder with the exact control counts that trip up most first-time assessments.

Domain crosswalk: four maturity models converge on the same core capabilities CMMC (14 domains), NIST CSF 2.0 (6 functions), C2M2 (10 domains), and CIS Controls (18 controls) all map onto the same nine universal cybersecurity capability areas. Different Models, Same Core Domains Four frameworks, four domain counts — one shared set of capabilities CMMC 2.0 14 domains NIST CSF 2.0 6 functions C2M2 10 domains CIS Controls 18 controls

The 9 universal capability areas Governance & Risk Management Asset & Configuration Mgmt Access Control & Identity

<rect x="40" y="272" width="230" height="34" rx="8" fill="#ffffff" stroke="#e2e8f0"/>
<text x="155" y="294" text-anchor="middle">Data Protection &amp; Encryption</text>
<rect x="285" y="272" width="230" height="34" rx="8" fill="#ffffff" stroke="#e2e8f0"/>
<text x="400" y="294" text-anchor="middle">Threat Detection &amp; Monitoring</text>
<rect x="530" y="272" width="230" height="34" rx="8" fill="#ffffff" stroke="#e2e8f0"/>
<text x="645" y="294" text-anchor="middle">Incident Response &amp; Recovery</text>

<rect x="40" y="316" width="230" height="34" rx="8" fill="#ffffff" stroke="#e2e8f0"/>
<text x="155" y="338" text-anchor="middle">Security Awareness &amp; Training</text>
<rect x="285" y="316" width="230" height="34" rx="8" fill="#ffffff" stroke="#e2e8f0"/>
<text x="400" y="338" text-anchor="middle">Vulnerability Management</text>
<rect x="530" y="316" width="230" height="34" rx="8" fill="#ffffff" stroke="#e2e8f0"/>
<text x="645" y="338" text-anchor="middle">Supply-Chain &amp; Vendor Risk</text>
Pick a model for its audience and mandate — not its domain count. A program that genuinely covers these nine areas scores well against any of the four frameworks.
The domain labels change between frameworks; the capabilities they test are nearly identical.

The Four Models Side by Side

If you only remember one thing, remember this table. It answers the question most people are really asking when they search for maturity-model domains: which one applies to me, and how big is it?

ModelOwnerStructureSizePrimary audienceUse it when
CMMC 2.0US Dept. of Defense14 domains (= NIST SP 800-171 families), 3 levels15 / 110 / 800-172 subset controls by levelDoD contractors handling FCI or CUIYou bid on or hold DoD contracts — it is contractually mandatory as of the Nov 10, 2025 rollout
NIST CSF 2.0NIST (US Commerce)6 functions, 22 categoriesOutcome-based, no fixed control countAny organization, any industryYou want a flexible, board-friendly baseline you can map everything else onto
C2M2US Dept. of Energy10 domains, 4 MILs350+ practicesEnergy, utilities, critical infrastructureYou run OT/ICS or critical infrastructure and want to score capability, not just compliance
CIS Controls v8Center for Internet Security18 controls, 3 Implementation Groups153 safeguardsResource-constrained teams needing a to-do listYou want prescriptive, prioritized actions rather than abstract outcomes

Which should you use? Start with your mandate. If a contract or regulation names a framework, that decision is made for you (CMMC for defense work, often C2M2 for energy). If nothing is mandated, use NIST CSF 2.0 as your organizing framework and CIS Controls v8 as the prioritized implementation checklist underneath it — the two are designed to complement each other, and CIS publishes an official mapping into CSF.

Major Cybersecurity Maturity Models and Their Domains

CMMC (Cybersecurity Maturity Model Certification) 2.0

The Cybersecurity Maturity Model Certification represents one of the most comprehensive approaches to security assessment, particularly for defense contractors and organizations handling sensitive government data. CMMC 2.0 includes 14 domains that map directly to NIST SP 800-171 Rev 2 families.

These 14 domains cover critical security capabilities including access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.

The CMMC framework is organized into three maturity levels. Level 1 contractors handle Federal Contract Information (FCI) and must implement 15 basic security controls outlined in Federal Acquisition Regulation (FAR) 52.204-21. Level 2 organizations work with Controlled Unclassified Information (CUI) and must comply with 110 security requirements from NIST SP 800-171. Level 3 represents the highest maturity tier, containing a subset of security requirements specified in NIST SP 800-172 for organizations handling the most sensitive information.

The CMMC program underwent significant updates in 2024. The CMMC Program Rule (32 CFR Part 170) took effect December 16, 2024, and the acquisition rule (48 CFR / DFARS) that embeds CMMC requirements into contracts began its Phase 1 rollout on November 10, 2025 — marking the shift from a voluntary compliance model to a phased contractual requirement for DoD contractors and their subcontractors.

CMMC 2.0 level ladder with control counts CMMC Level 1 requires 15 practices for FCI, Level 2 requires 110 requirements for CUI, and Level 3 adds a subset of NIST SP 800-172 enhanced requirements. The CMMC 2.0 Level Ladder Higher levels = more controls + protecting more sensitive data Level 1 — Foundational 15 practices (FAR 52.204-21) Protects FCI · annual self-assessment Level 2 — Advanced 110 requirements (NIST SP 800-171) Protects CUI · C3PAO or self-assess Level 3 — Expert 110 + NIST SP 800-172 subset Highest-sensitivity CUI · gov assessed Sensitivity of data protected →
The 14 CMMC domains stay constant across levels — what climbs is the number of controls and the sensitivity of the data.
Advertisement

NIST Cybersecurity Framework 2.0

Released in 2024, the National Institute of Standards and Technology's Cybersecurity Framework 2.0 represents the latest evolution of this widely adopted security model. The framework includes six core functions that serve as foundational elements for most maturity assessments: Govern, Identify, Protect, Detect, Respond, and Recover.

The Govern function represents a new addition in version 2.0, emphasizing the importance of establishing cybersecurity governance structures, policies, and procedures that align with business objectives. This function addresses leadership commitment, risk management strategy, and supply chain risk management—areas that have become increasingly critical in today's interconnected business environment.

The Identify function focuses on developing organizational understanding to manage cybersecurity risk to systems, people, assets, data, and capabilities. This includes asset management, business environment analysis, governance structures, risk assessment, and risk management strategy.

The Protect function outlines safeguards to ensure delivery of critical services. This encompasses identity management and access control, awareness and training, data security, information protection processes and procedures, maintenance activities, and protective technology implementation.

Detection capabilities form the fourth function, enabling timely discovery of cybersecurity events through continuous monitoring, detection processes, and anomalous event analysis. The Respond function addresses appropriate activities to take action regarding detected cybersecurity incidents, including response planning, communications, analysis, mitigation, and improvements.

Finally, the Recover function identifies activities that restore capabilities or services impaired due to cybersecurity incidents, encompassing recovery planning, improvements based on lessons learned, and communications during recovery activities.

C2M2 (Cybersecurity Capability Maturity Model)

Developed by the Department of Energy, the Cybersecurity Capability Maturity Model provides a comprehensive examination of capability gaps, incident response readiness, and resilience-building measures. The model covers 10 domains with four maturity indicator levels, containing more than 350 specific cybersecurity practices.

The 10 C2M2 domains include Asset, Change, and Configuration Management; Threat and Vulnerability Management; Risk Management; Identity and Access Management; Situational Awareness; Information Sharing and Communications; Event and Incident Response, Continuity of Operations; Supply Chain and External Dependencies Management; Workforce Management; and Cybersecurity Program Management.

Each domain contains multiple objectives that organizations must address to achieve higher maturity levels. For instance, the Asset, Change, and Configuration Management domain focuses on establishing inventories of hardware, software, and information assets, as well as managing changes to these assets in a controlled manner.

The Threat and Vulnerability Management domain addresses identifying, analyzing, and responding to cybersecurity threats and vulnerabilities. This includes vulnerability scanning, penetration testing, threat intelligence gathering, and implementing controls to mitigate identified risks.

CIS Controls

The Center for Internet Security Controls represent another widely adopted framework, consisting of 18 control areas that provide prescriptive guidance for implementing specific security measures. These controls are organized by implementation group, allowing organizations to prioritize actions based on their resources and risk profile.

The 18 CIS Controls cover areas including inventory and control of enterprise assets, inventory and control of software assets, data protection, secure configuration of enterprise assets and software, account management, access control management, continuous vulnerability management, audit log management, email and web browser protections, malware defenses, data recovery, network infrastructure management, network monitoring and defense, security awareness and skills training, service provider management, application software security, incident response management, and penetration testing.

Common Assessment Areas Across Models

While different maturity models use varying terminology and organizational structures, several common themes emerge across frameworks. These universal assessment areas represent fundamental cybersecurity capabilities that all organizations must address regardless of industry or size.

Governance and Risk Management

All major maturity models emphasize the importance of cybersecurity governance structures. This includes establishing clear roles and responsibilities, developing comprehensive security policies and procedures, conducting regular risk assessments, and aligning security initiatives with business objectives. Effective governance ensures cybersecurity receives appropriate attention and resources at the leadership level.

Asset and Configuration Management

Understanding what you need to protect represents a fundamental security requirement. Assessment areas focused on asset management evaluate whether organizations maintain accurate inventories of hardware, software, and data assets. Configuration management assesses how well organizations control changes to these assets and maintain secure configurations.

Access Control and Identity Management

Controlling who can access what information and systems forms a cornerstone of cybersecurity. Maturity models assess identity management processes, authentication mechanisms, authorization controls, and access review procedures. This domain has grown increasingly complex with the rise of cloud services, remote work, and third-party access requirements.

Data Protection and Encryption

Organizations must demonstrate appropriate safeguards for sensitive information throughout its lifecycle. Assessment areas examine data classification schemes, encryption implementation, data loss prevention controls, and secure data disposal procedures. Privacy regulations like GDPR and CCPA have elevated the importance of this domain.

Threat Detection and Monitoring

The ability to detect security incidents quickly significantly reduces potential damage. Maturity assessments evaluate whether organizations implement continuous monitoring, analyze security logs effectively, deploy appropriate detection tools, and maintain situational awareness of their threat landscape.

Incident Response and Recovery

How organizations respond to security incidents determines whether a potential breach becomes a catastrophic event. Assessment domains examine incident response planning, team capabilities, communication protocols, forensic analysis capabilities, and business continuity procedures.

Security Training and Awareness

Technology alone cannot secure an organization—people represent both the greatest vulnerability and strongest defense. Maturity models assess security awareness training programs, role-based training for technical staff, phishing simulation exercises, and security culture initiatives.

Vendor and Supply Chain Security

Modern organizations depend on numerous third-party vendors and service providers, each representing potential security risks. Assessment areas evaluate vendor risk management processes, contract security requirements, ongoing vendor monitoring, and supply chain security controls.

Vulnerability Management

Identifying and remediating security vulnerabilities before attackers exploit them represents a critical capability. Maturity assessments examine vulnerability scanning programs, patch management processes, remediation timelines, and testing procedures.

Selecting the Right Model for Your Organization

Different maturity models serve different purposes and audiences. Organizations working with the Department of Defense must comply with CMMC requirements. Companies in the energy sector may find C2M2 most relevant. Many organizations adopt NIST CSF as a flexible framework applicable across industries.

When selecting a maturity model, consider your regulatory environment, industry best practices, customer requirements, and organizational resources. Some organizations implement multiple frameworks, mapping controls between models to demonstrate comprehensive compliance.

The Assessment Process

Conducting maturity assessments typically involves reviewing documentation, interviewing personnel, observing processes, and testing technical controls. Organizations should approach assessments honestly, as accurate baseline measurements enable meaningful improvement planning.

Maturity assessments generate gap analyses identifying areas where current capabilities fall short of target levels. These gaps inform roadmap development, prioritizing improvements based on risk, compliance requirements, and available resources.

Moving Forward with Maturity Assessment

Understanding the domains assessed in cybersecurity maturity models represents the first step toward improving your security posture. These frameworks provide structured approaches to evaluating capabilities across all essential security areas.

Organizations should view maturity assessment as an ongoing process rather than a one-time exercise. As threats evolve, technologies advance, and business environments change, continuous reassessment ensures security capabilities keep pace with emerging risks.

Whether you're pursuing CMMC certification, implementing NIST CSF, or adopting another framework, understanding assessment domains helps focus your efforts on building comprehensive security capabilities that protect your organization in today's complex threat landscape.

Frequently Asked Questions

How many domains does CMMC 2.0 have?

CMMC 2.0 assesses 14 domains that map one-to-one to the 14 control families in NIST SP 800-171 Rev 2: access control, awareness and training, audit and accountability, configuration management, identification and authentication, incident response, maintenance, media protection, personnel security, physical protection, risk assessment, security assessment, system and communications protection, and system and information integrity.

What are the six functions of the NIST Cybersecurity Framework 2.0?

NIST CSF 2.0, released in February 2024, has six core functions: Govern, Identify, Protect, Detect, Respond, and Recover. Govern is the new function added in version 2.0, and it wraps around the other five to cover strategy, roles, policy, and supply-chain risk.

How many domains are in C2M2?

The Department of Energy's Cybersecurity Capability Maturity Model (C2M2) has 10 domains and uses four Maturity Indicator Levels (MIL0-MIL3), containing more than 350 individual cybersecurity practices. It is most commonly used in the energy and critical-infrastructure sectors.

Are the domains the same across CMMC, NIST CSF, C2M2, and CIS Controls?

No, the labels and counts differ, but the underlying capabilities converge. Nearly every model assesses the same core areas: governance and risk management, asset and configuration management, access control and identity, data protection, threat detection and monitoring, incident response and recovery, security awareness, vulnerability management, and supply-chain security. The frameworks slice these into 6, 10, 14, or 18 buckets, but a strong program covers the same ground regardless of which model you pick.

Which maturity model should my organization use?

Defense contractors handling FCI or CUI must use CMMC. Energy and critical-infrastructure operators typically use C2M2. Most other organizations start with NIST CSF 2.0 as a flexible, industry-agnostic baseline, then layer CIS Controls for prescriptive, prioritized implementation guidance. Many mature programs run more than one and cross-map the controls.

What is the difference between a maturity model domain and a control?

A domain is a broad capability area (for example, "Incident Response"), while a control is a specific, testable requirement inside that domain (for example, "establish an incident-handling capability that includes preparation, detection, analysis, containment, recovery, and user response"). Domains organize controls into logical groups so assessors can score capability by area.

What are the CMMC levels and how many controls does each require?

CMMC 2.0 has three levels. Level 1 requires 15 basic safeguarding practices from FAR 52.204-21 for Federal Contract Information. Level 2 requires all 110 requirements from NIST SP 800-171 for Controlled Unclassified Information. Level 3 adds a selected subset of NIST SP 800-172 enhanced requirements for the highest-sensitivity work.

When did CMMC become mandatory?

The CMMC Program Rule (32 CFR Part 170) took effect December 16, 2024, and the acquisition rule (48 CFR / DFARS) that puts CMMC requirements into contracts began Phase 1 rollout on November 10, 2025. From that point CMMC shifted from voluntary to a phased contractual requirement for DoD contractors and subcontractors.

cybersecurity maturityCMMCNISTsecurity assessment