In May 2026, OMB rescinded the memo that defined federal log retention for five years — and replaced it with something agencies should take just as seriously: a risk-based framework with coverage benchmarks, a maturity model, and hard deadlines that start the moment CISA publishes its Logging Reference Architecture.
OMB Memorandum M-26-14 (May 22, 2026) rescinds M-21-31 effective immediately. The EL1–EL3 event-logging tiers and the 30-month retention mandate are gone. In their place, agencies must organize logging around two objectives: Continuous Event Monitoring (CEM) — real-time SOC monitoring, anomaly flagging, and timely response — and THIRF — threat hunting, investigation, response, and forensics after a known or suspected compromise, backed by sufficient hot and cold storage with centralized retrieval.
The minimums are lower, but the scope is wider. Logs must be searchable for 6 months and retrievable for 12 — down from 30 months of mandated retention — while coverage obligations now explicitly reach every IT, OT, and IoT asset in agency systems, including devices with no native logging capability. And the memo is explicit that its minimums do not relieve agencies of records-schedule obligations, which often run far longer.
| Dimension | M-21-31 (2021–2026) | M-26-14 (now) |
|---|---|---|
| Framework | Prescriptive EL1–EL3 event-logging tiers | Risk-based CEM + THIRF objectives |
| Retention floor | 30 months (12 active + 18 cold) | 6 months searchable / 12 months retrievable |
| What gets graded | Log categories collected | % of assets covered — inventory, collection, alerting, retention, log management (Levels 0–4) |
| Scope | Agency information systems | Explicitly includes IoT and OT, even without native logging |
| Guidance | Static memo | CISA Logging Reference Architecture, re-evaluated at least annually |
| Log production | CISA access on request | CISA and FBI, "within the timeframes requested" |
National security systems, DoD, and IC systems are excluded — this is a civilian-agency reset. But every civilian agency is now on the same countdown.
CISA must publish the Logging Reference Architecture (LRA) within 90 days of the memo — on or about August 20, 2026. Every deadline below runs from the LRA's publication date, and resets in part with every annual LRA update.
Agency Logging Plan due to OMB and CISA — the documented operational steps to achieve CEM and THIRF across your estate.
Level 1 across every maturity element: inventory visibility, collection coverage, collection operations, retention, log management.
Level 2: 80% collection coverage, periodically tuned detections, 12-month retrievable retention.
Level 3: 90% coverage, routinely tuned detections, encrypted and integrity-hashed log management.
Under a year from LRA publication to Level 3 — across every element, for every reportable system, with maturity scored by the lowest watermark. Agencies that wait for the LRA to start planning will spend their first 90-day window catching up.
The incumbent-SIEM story about M-26-14 will be that lower retention minimums mean lower bills. Look at what actually gets measured. The maturity model grades agencies on the percentage of inventoried assets whose logs are searchable and retrievable — 50% at Level 1, 80% at Level 2, 90% at Level 3, 95% at Optimal — with IoT and OT explicitly in scope and alert coverage graded against an eleven-item baseline.
Under per-GB pricing, every asset you bring into coverage raises the invoice. Coverage benchmarks and ingestion-based licensing are structurally opposed: the meter punishes exactly the behavior the memo requires. And CEM is continuous by definition — real-time monitoring means the ingest never stops.
Per-agent pricing inverts the math. With SecureWatch, enrolling the next asset costs a flat per-agent rate — never a per-GB penalty — so driving coverage from 50% to 95% is a predictable, linear line item. AI-generated decoders onboard the long tail (mainframes, SCADA, bespoke systems — the assets that keep agencies below 95%) in minutes instead of onboarding quarters.
THIRF explicitly requires hot and cold storage with the ability to centralize logs from multiple sources to map attack patterns. Records schedules still bind. The LRA is directed to recommend retention practices that exceed the minimums. And the maturity model's top level requires 6 months searchable and 12 retrievable — a bar most per-GB platforms make expensive to clear at full coverage.
Every SecureWatch subscription ships above that bar: 90 days hot with sub-second query, searchable through 18 months of warm storage, retrievable through 30 months of WORM-locked cold archive — included at every tier, with extended archive to 7 years for records schedules and litigation hold.
Level 4 collection operations requires detections "routinely evaluated and tuned using advanced techniques such as machine learning or artificial intelligence." That is the single place the model names a technology — and it describes the SecureWatch Agentic AI layer: AI-tuned detections, natural-language threat hunting for THIRF, and automated evidence generation, included in the base subscription and delivered through AWS Bedrock inside GovCloud, where Microsoft Security Copilot is not available in GCC, GCC High, or DoD environments.
| Maturity element | SecureWatch capability |
|---|---|
| Inventory visibility | Hardware/software inventory from every enrolled agent, refreshed on check-in; syslog-sourced visibility for unagentable IoT/OT |
| Collection coverage | Flat per-agent pricing makes 95% coverage the default; AI auto-decoders onboard non-standard sources in minutes |
| Collection operations | 4,000+ MITRE ATT&CK-mapped rules with automated alerting; AI-tuned detections — the model's Level 4 language, at every tier |
| Data retention | Searchable ~18 months, retrievable 30 — above the Level 4 requirement of 6 searchable / 12 retrievable, included |
| Log management | FIPS 140-2 encryption in transit and at rest, per-tenant keys, WORM immutability, full query provenance |
| CISA / FBI production | Centralized search plus in-place SQL over cold archives — log production in hours, not restore-weeks |
We're offering a free M-26-14 Readiness Assessment: a maturity-model-scored review of your inventory visibility, collection coverage, alerting, retention, and log management — delivered as a per-system scorecard and gap plan formatted to drop directly into your Agency Logging Plan.
Request a Readiness Assessment →The CISA Logging Reference Architecture is pending publication at cisa.gov/Logging. This brief will be updated when it lands.