Policy Brief · OMB M-26-14

M-21-31 Is Gone. The New Logging Clock Is Already Running.

In May 2026, OMB rescinded the memo that defined federal log retention for five years — and replaced it with something agencies should take just as seriously: a risk-based framework with coverage benchmarks, a maturity model, and hard deadlines that start the moment CISA publishes its Logging Reference Architecture.

M-21-31 RESCINDED CEM + THIRF OBJECTIVES MATURITY LEVELS 0–4 LRA EXPECTED ~AUG 2026

01What actually changed

OMB Memorandum M-26-14 (May 22, 2026) rescinds M-21-31 effective immediately. The EL1–EL3 event-logging tiers and the 30-month retention mandate are gone. In their place, agencies must organize logging around two objectives: Continuous Event Monitoring (CEM) — real-time SOC monitoring, anomaly flagging, and timely response — and THIRF — threat hunting, investigation, response, and forensics after a known or suspected compromise, backed by sufficient hot and cold storage with centralized retrieval.

The minimums are lower, but the scope is wider. Logs must be searchable for 6 months and retrievable for 12 — down from 30 months of mandated retention — while coverage obligations now explicitly reach every IT, OT, and IoT asset in agency systems, including devices with no native logging capability. And the memo is explicit that its minimums do not relieve agencies of records-schedule obligations, which often run far longer.

DimensionM-21-31 (2021–2026)M-26-14 (now)
FrameworkPrescriptive EL1–EL3 event-logging tiersRisk-based CEM + THIRF objectives
Retention floor30 months (12 active + 18 cold)6 months searchable / 12 months retrievable
What gets gradedLog categories collected% of assets covered — inventory, collection, alerting, retention, log management (Levels 0–4)
ScopeAgency information systemsExplicitly includes IoT and OT, even without native logging
GuidanceStatic memoCISA Logging Reference Architecture, re-evaluated at least annually
Log productionCISA access on requestCISA and FBI, "within the timeframes requested"

National security systems, DoD, and IC systems are excluded — this is a civilian-agency reset. But every civilian agency is now on the same countdown.

02The clock

CISA must publish the Logging Reference Architecture (LRA) within 90 days of the memo — on or about August 20, 2026. Every deadline below runs from the LRA's publication date, and resets in part with every annual LRA update.

LRA + 90 DAYS

Agency Logging Plan due to OMB and CISA — the documented operational steps to achieve CEM and THIRF across your estate.

PLAN DUE ~NOV 2026

LRA + 120 DAYS

Level 1 across every maturity element: inventory visibility, collection coverage, collection operations, retention, log management.

LEVEL 1 ~DEC 2026

LRA + 180 DAYS

Level 2: 80% collection coverage, periodically tuned detections, 12-month retrievable retention.

LEVEL 2 ~FEB 2027

LRA + 320 DAYS

Level 3: 90% coverage, routinely tuned detections, encrypted and integrity-hashed log management.

LEVEL 3 ~JUL 2027

Under a year from LRA publication to Level 3 — across every element, for every reportable system, with maturity scored by the lowest watermark. Agencies that wait for the LRA to start planning will spend their first 90-day window catching up.

03The part nobody is saying out loud: coverage is the new cost driver

The incumbent-SIEM story about M-26-14 will be that lower retention minimums mean lower bills. Look at what actually gets measured. The maturity model grades agencies on the percentage of inventoried assets whose logs are searchable and retrievable — 50% at Level 1, 80% at Level 2, 90% at Level 3, 95% at Optimal — with IoT and OT explicitly in scope and alert coverage graded against an eleven-item baseline.

Under per-GB pricing, every asset you bring into coverage raises the invoice. Coverage benchmarks and ingestion-based licensing are structurally opposed: the meter punishes exactly the behavior the memo requires. And CEM is continuous by definition — real-time monitoring means the ingest never stops.

Per-agent pricing inverts the math. With SecureWatch, enrolling the next asset costs a flat per-agent rate — never a per-GB penalty — so driving coverage from 50% to 95% is a predictable, linear line item. AI-generated decoders onboard the long tail (mainframes, SCADA, bespoke systems — the assets that keep agencies below 95%) in minutes instead of onboarding quarters.

Retention: the floor dropped. Don't build to the floor.

THIRF explicitly requires hot and cold storage with the ability to centralize logs from multiple sources to map attack patterns. Records schedules still bind. The LRA is directed to recommend retention practices that exceed the minimums. And the maturity model's top level requires 6 months searchable and 12 retrievable — a bar most per-GB platforms make expensive to clear at full coverage.

Every SecureWatch subscription ships above that bar: 90 days hot with sub-second query, searchable through 18 months of warm storage, retrievable through 30 months of WORM-locked cold archive — included at every tier, with extended archive to 7 years for records schedules and litigation hold.

The only technology the maturity model names is AI

Level 4 collection operations requires detections "routinely evaluated and tuned using advanced techniques such as machine learning or artificial intelligence." That is the single place the model names a technology — and it describes the SecureWatch Agentic AI layer: AI-tuned detections, natural-language threat hunting for THIRF, and automated evidence generation, included in the base subscription and delivered through AWS Bedrock inside GovCloud, where Microsoft Security Copilot is not available in GCC, GCC High, or DoD environments.

04How SecureWatch maps to the maturity model

Maturity elementSecureWatch capability
Inventory visibilityHardware/software inventory from every enrolled agent, refreshed on check-in; syslog-sourced visibility for unagentable IoT/OT
Collection coverageFlat per-agent pricing makes 95% coverage the default; AI auto-decoders onboard non-standard sources in minutes
Collection operations4,000+ MITRE ATT&CK-mapped rules with automated alerting; AI-tuned detections — the model's Level 4 language, at every tier
Data retentionSearchable ~18 months, retrievable 30 — above the Level 4 requirement of 6 searchable / 12 retrievable, included
Log managementFIPS 140-2 encryption in transit and at rest, per-tenant keys, WORM immutability, full query provenance
CISA / FBI productionCentralized search plus in-place SQL over cold archives — log production in hours, not restore-weeks

Get ahead of your Agency Logging Plan

We're offering a free M-26-14 Readiness Assessment: a maturity-model-scored review of your inventory visibility, collection coverage, alerting, retention, and log management — delivered as a per-system scorecard and gap plan formatted to drop directly into your Agency Logging Plan.

Request a Readiness Assessment →

The CISA Logging Reference Architecture is pending publication at cisa.gov/Logging. This brief will be updated when it lands.