A new logging memorandum
OMB M-26-14 establishes logging and network visibility requirements that rescind M-21-31. Agencies still need comprehensive event logging—but the reference architecture and maturity milestones have moved.
What technical volumes should emphasize
- IT, OT, and IoT coverage—not only traditional enterprise endpoints
- SIEM and pipeline architecture that can retain and search at the required maturity
- Agency logging plans that match the CISA logging reference architecture when published
- Realistic sequencing from late 2026 through 2027 rather than overnight "full maturity"
Our related offering
Logging and Continuous Event Monitoring Readiness is the 4–8 week package we use when a prime needs a maturity gap analysis, draft agency logging plan, and SIEM/pipeline design for a defined boundary.
Proposal tip
Do not paste M-21-31 language into a 2026 volume. Evaluators will notice. Map explicitly to M-26-14 and show how your logging design supports detection and response, not only retention checkboxes.
