When we wrote about OMB M-26-14 in June, one open question loomed over every federal cyber conversation: what would CISA’s Logging Reference Architecture actually require, and when would it land? That question is now answered. CISA published the Logging Reference Architecture on August 20, 2026, and with it, the deadlines in M-26-14 are live. Agencies have 90 days to submit an Agency Logging Plan to OMB and CISA through CyberScope, 120 days to reach Basic Maturity, 180 days to reach Intermediate, and 320 days to reach Advanced.
The good news is that the LRA rewards agencies that prepared. It is not a product blueprint, a mandated tech stack, or a restatement of policy. It is a decision framework that helps agencies convert M-26-14 requirements into architecture, data, and governance choices. For teams that already understand their current state, the LRA reads like a roadmap. For teams that waited, it reads like a very long to do list with a countdown attached.
The LRA’s core principle is one Swish has championed for years: design logging around the security outcomes you must deliver, not around what your platforms happen to collect. CISA is explicit that tool capabilities should not dictate the approach. Instead, agencies should work backward from five questions:
That last question deserves emphasis. The LRA repeatedly warns that a source can be onboarded and still fail operationally because events arrive late, fields are missing, parsers drift, or data sits in a tier nobody can search. Baseline alignment is demonstrated through usable capability, not connector presence. Agencies that treat their Agency Logging Plan as an inventory exercise will miss the point and likely miss the maturity mandates.
The LRA decomposes M-26-14’s two priority objectives into four outcomes agencies must design for and each comes with concrete operational tests:
CISA also directs agencies to measure monitoring coverage against adversary behavior frameworks such as MITRE ATT&CK, and to define latency expectations in the Agency Logging Plan. Readiness is measured by whether the agency can monitor, hunt, respond, and reconstruct with acceptable speed and confidence, not by how many collectors are deployed.
The heart of the document is a set of architectural decisions every agency must make explicitly. Collect as close to the authoritative source as practical and preserve provenance end to end. Favor durable, decoupled transport over brittle point to point integrations. Normalize events for cross source operations without flattening away the investigative context analysts need. Distinguish clearly between actively searchable data, retrievable retained data, and designated immutable evidentiary datasets. Apply minimization, redaction, and sharing decisions through a controlled policy enforcement point. And build validation into the pipeline so degradation is detected before an incident exposes it.
For most maturing agencies, CISA recommends a default operating model of source appropriate collection with common downstream handling. The LRA also evaluates common patterns, including repository first, dual replication, selective feeds, and SIEM first, and it cautions against treating a SIEM as the central data store for all logs. One line should be posted on every SOC wall: centralization is not the same as usefulness.
Agencies should read the retention guidance closely, because two requirements interact in a way that is easy to misread. The M-26-14 baseline requires logs to be actively searchable for six months and retrievable for one year. The maturity model, however, requires only three months of searchable retention at Advanced (Level 3), with six months appearing at Optimal (Level 4). Reaching Advanced within 320 days satisfies maturity reporting, but agencies must still meet the six-month searchable baseline to comply with the memorandum. Architectures should be designed against the baseline, not the maturity milestone.
The LRA carries forward M-26-14’s expansion beyond traditional IT. Baseline logging categories explicitly cover IoT and OT device activity, including environments without native logging, where gateway aggregation, network-based monitoring, and store and forward patterns can satisfy expectations without degrading operational safety. The standard does not drop just because collection is harder.
AI systems get their own treatment. Agencies should log user prompts, system prompts, model outputs, agent decisions and actions, and model lineage, with enough context to distinguish expected behavior from guardrail bypasses or prompt manipulation. And where agencies use AI to enhance CEM and THIRF, from anomaly detection to timeline reconstruction, the LRA sets clear boundaries: AI outputs must remain traceable to source records, must not alter evidence, and must keep humans in the loop for consequential actions. For agencies building agentic SOC capabilities, this is the governance framework those investments will be measured against.
The Agency Logging Plan due in 90 days is a strategy document, not an engineering spec. CISA expects it to document:
The LRA’s Appendix C checklist sets a high bar: an implementation team should be able to use the plan to build, validate, or improve the capability without inferring major design decisions. That is a demanding deliverable on a compressed timeline, and it depends on something many agencies still lack: a clear, current picture of what they collect today, where the gaps are, and which ones matter most.
Swish has spent more than 20 years helping federal agencies modernize IT operations, strengthen cybersecurity, and build resilient enterprise architectures. Our M-26-14 Readiness Assessment now incorporates the published LRA. We evaluate all five maturity capability areas, benchmark your environment against the baseline coverage and fidelity requirements in the LRA, and map your current state to the architectural decisions your Agency Logging Plan must document. You walk away with maturity scoring, prioritized gaps, quick wins, and a roadmap aligned to the deadlines now in motion.
The thesis that you cannot defend what you cannot see remains valid. The difference is that the guidance is no longer forthcoming. It is here, the requirements are concrete, and the clock is running. Agencies that move in the next 90 days will set the trajectory for the next three years of their cyber visibility.