CISA released the Logging Reference Architecture on August 20, 2026 — on the exact 90-day timeline M-26-14 set. It is more specific than most agencies expected, and it documents a compliance gap that will catch agencies doing precisely what the maturity model asks of them.
The Logging Reference Architecture is live at CISA. Every downstream deadline in M-26-14 now has a fixed date attached to it, and the 90-day Agency Logging Plan window is open.
OMB Memorandum M-26-14 (May 22, 2026) rescinds M-21-31 effective immediately. The EL1–EL3 event-logging tiers and the 30-month retention mandate are gone. In their place, agencies must organize logging around two objectives: Continuous Event Monitoring (CEM) — real-time SOC monitoring, anomaly flagging, and timely response — and THIRF — threat hunting, investigation, response, and forensics after a known or suspected compromise, backed by sufficient hot and cold storage with centralized retrieval.
The minimums are lower, but the scope is wider. Logs must be searchable for 6 months and retrievable for 12 — down from 30 months of mandated retention — while coverage obligations now explicitly reach every IT, OT, and IoT asset in agency systems, including devices with no native logging capability. The LRA extends that reach further: it covers systems "operated on behalf of the agency, including contractor-run, managed service provider (MSP), or third-party environments," and requires agencies to apply the same logging, retention, and visibility decisions there.
| Dimension | M-21-31 (2021–2026) | M-26-14 + LRA (now) |
|---|---|---|
| Framework | Prescriptive EL1–EL3 event-logging tiers | Risk-based CEM + THIRF objectives |
| Retention floor | 30 months (12 active + 18 cold) | 6 months searchable / 12 months retrievable, plus separate immutable handling for designated evidence |
| What gets graded | Log categories collected | % of assets covered — inventory, collection, alerting, retention, log management (Levels 0–4) |
| Scope | Agency information systems | IT, OT, IoT — plus contractor, MSP, and third-party operated systems |
| Guidance | Static memo | CISA Logging Reference Architecture, re-evaluated at least annually |
| Log production | CISA access on request | CISA and FBI, "within the timeframes requested" |
The LRA is implementation guidance, not a mandate layer. It is explicit about what it does not do: it does not "prescribe specific vendor schemas, products, platforms, operating models, or commercial architectures," and it does not create compliance requirements beyond M-26-14. National security systems, DoD, and IC systems remain excluded — this is a civilian-agency reset.
Every M-26-14 deadline was written as an offset from LRA publication. That anchor is now fixed at August 20, 2026.
Agency Logging Plan submitted to OMB and CISA through CyberScope — a strategy document, not an implementation record.
Level 1 across every maturity element: inventory visibility, collection coverage, collection operations, retention, log management.
Level 2: 80% collection coverage, periodically tuned detections, 12-month retrievable retention.
Level 3 (Advanced): 90% coverage, routinely tuned detections, encrypted and integrity-hashed log management.
CISA hosts the plan template on CyberScope and asks it to cover seven areas: scope and governance; CEM and THIRF implementation approach; minimum baseline implementation; additional mission and risk-based logging; retention, access, and protection; validation and maturity measurement; and a gaps and improvement roadmap.
Under a year from publication to Level 3 — across every element, for every reportable system, with maturity scored by the lowest watermark. Agencies that spend the plan window deciding what to buy will spend the maturity window catching up.
This is the part of the LRA worth reading twice. M-26-14 contains two different retention numbers in two different appendices, and they do not agree. The LRA says so directly.
"While Appendix B of M-26-14 establishes the required baseline retention — that logs must be actively searchable for at least six months and retrievable for one year — the M-26-14 Appendix C Maturity Model defines staged progression levels used for assessing agency maturity. Under that model, Advanced (Level 3) requires only three months of searchable retention, with the six-month searchable window appearing at Optimal (Level 4)."
CISA · Logging Reference Architecture · §5.3Agencies are required to reach Level 3 within 320 days. Level 3 asks for three months of searchable retention. The mandatory baseline in Appendix B asks for six.
An agency can hit the maturity level it is graded and reported on, file a clean maturity number, and still be out of compliance with M-26-14. CISA states the resolution plainly: reaching Level 3 "satisfies maturity reporting requirements; however, agencies must still ensure their architectures meet the six-month searchable baseline in Appendix B to comply with M-26-14."
Any architecture sized to the maturity model alone is sized wrong. The governing number is six months searchable and twelve months retrievable — not the three-month Level 3 figure, which is the one that will get designed against because it is the one attached to a deadline.
The LRA also asks agencies to separate three things most log architectures blur together: data that is actively searchable for monitoring, triage, and routine investigation; data that is retrievable from lower-cost tiers for reconstruction and oversight; and designated immutable or evidentiary datasets requiring stronger access control and auditability. That distinction is supposed to be explicit in the operating model and written in plain language in the plan — and tied to outcomes rather than, in the LRA's words, "vendor defaults."
Every SecureWatch subscription ships above the governing baseline: 90 days hot with sub-second query, searchable through 18 months of warm storage, retrievable through 30 months of WORM-locked cold archive — included at every tier, with extended archive to 7 years for records schedules and litigation hold.
The incumbent-SIEM story about M-26-14 was that lower retention minimums mean lower bills. Look at what actually gets measured. The maturity model grades agencies on the percentage of inventoried assets whose logs are searchable and retrievable — 50% at Level 1, 80% at Level 2, 90% at Level 3, 95% at Optimal — with IoT and OT explicitly in scope.
Under per-GB pricing, every asset brought into coverage raises the invoice. Coverage benchmarks and ingestion-based licensing are structurally opposed: the meter punishes exactly the behavior the memo requires. And CEM is continuous by definition — real-time monitoring means the ingest never stops.
That tension is no longer just a procurement complaint. The LRA's readiness measures make cost the first thing an agency is told to assess and report:
"Consideration and analysis of costs (including labor, staff burden, operations, maintenance, procurement, licensing, and service costs) pertaining to log sources and collection, in relation to its impact on the agency's cybersecurity risk… Are there alternative infrastructure or design choices that achieve mission and operational goals while decreasing cost or complexity for operability?"
CISA · Logging Reference Architecture · §3.5 — Measuring Logging Capability ReadinessNine more measures follow — coverage, timeliness, fidelity, integrity, searchability and retrievability, data quality, operational usability, forensic readiness, and validation maturity — and CISA asks that all ten be reported at operational and executive levels on a continuous improvement loop.
Per-agent pricing inverts the math. With SecureWatch, enrolling the next asset costs a flat per-agent rate — never a per-GB penalty — so driving coverage from 50% to 95% is a predictable, linear line item. AI-generated decoders onboard the long tail (mainframes, SCADA, bespoke systems — the assets that keep agencies below 95%) in minutes instead of onboarding quarters. When the CISO has to answer §3.5 in writing, that is the answer.
The LRA does not mandate a pattern. It describes several neutrally and notes where each breaks down — and the commentary is pointed.
"Moving every log into centralized storage with one analytical platform does not automatically improve monitoring or investigation. Centralization can improve consistency and visibility, but only if the data remains timely, trustworthy, and usable. A centralized storage design that strips away context, introduces major delay, or creates a fragile chokepoint is weaker than a more federated design with strong common governance and shared operational handling."
CISA · Logging Reference Architecture · §5.3CISA's list of strategies agencies should avoid includes "centralizing all telemetry into a single fragile pipeline" and "overreliance on direct point-to-point integrations." On the SIEM-first pattern specifically: it "often becomes costly and less flexible as telemetry volume and retention expectations grow," it "may also weaken fidelity if ingestion-time processing becomes the agency's only durable event representation," and practitioner guidance "generally warns against treating a SIEM as the central data store for all logs where broader retention and flexibility are needed."
For most maturing agencies, the LRA recommends source-appropriate collection with common downstream handling — collect each source the way that source is best collected, then converge on shared normalization, enrichment, validation, policy enforcement, and tiered retention once data is inside the logging infrastructure. Storage follows the outcome: low-latency tiers for what analysts actually search, lower-cost retrievable tiers for what they occasionally need, separate immutable handling for what has to hold up as evidence.
Among the named patterns, Repository First — logs land in an authoritative object store or lakehouse, with analytic platforms querying from it rather than ingesting every source directly — is called a strong fit for agencies needing long-term retention, multi-team access, and the ability to evolve analytic tooling without recollecting data. The Segregated-Access Overlay pattern layers RBAC/ABAC, partitioning, and encryption domains on top for sensitive datasets without duplicating pipelines.
Agencies already participating in CISA's Comprehensive Log Aggregation Warehouse (CLAW) may optionally route designated telemetry there as part of a storage or replication strategy. It is not a required component, and it complements rather than replaces an operational search tier — SecureWatch can replicate designated telemetry to CLAW while remaining the CEM and THIRF layer.
| What the LRA asks for | SecureWatch |
|---|---|
| Six months searchable / twelve retrievable — the governing baseline, not the Level 3 figure | 90 days hot, searchable through 18 months, retrievable through 30 — included, WORM-locked. Clears Appendix B and Optimal on both axes. |
| Explicit searchable / retrievable / immutable separation | Tiered hot, warm, and cold storage with S3 Object Lock on designated evidentiary datasets |
| Source-appropriate collection, common downstream handling | Agent, syslog, API, and Collector on-ramps into shared normalization and enrichment — including IoT and OT devices with no native logging |
| Repository-first storage, analytics querying from it | Object storage as the durable record with in-place query via Athena — rather than a SIEM that must ingest everything to see it |
| Inventory visibility toward 95% | Hardware/software inventory from every enrolled agent, refreshed on check-in; syslog-sourced visibility for unagentable IoT/OT |
| Coverage toward 95% without a cost cliff | Flat per-agent pricing; AI auto-decoders onboard non-standard sources in minutes |
| Identity-centric analytics carried forward from M-21-31 | User and entity behavior analysis for credential misuse, lateral movement, and privilege abuse — the capability the LRA names explicitly in §6.2.1 |
| AI output tied to underlying event records | AI detection and natural-language hunting included at every tier, with full query provenance and result-set hashing preserving the link between derived output and source records |
| CISA / FBI production within requested timeframes | Centralized search plus in-place SQL over cold archives — production in hours, not restore-weeks |
AI and ML are treated as optional enabling methods, never substitutes for required telemetry. Detections must stay "tied to underlying event records, validated detections, and analyst-reviewable rationale." Actions with material containment, disclosure, legal, privacy, or mission impact "require human review." AI must not "alter source evidence, replace chain-of-custody controls, or become the authoritative record." Agencies using AI are asked to document their use cases, data inputs, validation approach, human review points, fallback procedures, and chain-of-custody separation in the logging plan.
Those are boundary conditions SecureWatch was built to satisfy rather than caveats to work around — query provenance and evidentiary separation are how the AI layer has always shipped.
We're offering a free M-26-14 Readiness Assessment: a review of your draft plan against CISA's own reviewer criteria — the Appendix C priority architecture and design decision checklist, scored across the seven content areas CISA asks the plan to cover — returned as a gap list with owners and remediation paths, in the form CISA asks for.
No cost, no obligation, and useful whether or not SecureWatch is ever part of your architecture.
Request a Readiness Assessment →Plans are due to OMB and CISA via CyberScope on November 18, 2026.