AWS Public Sector Blog
What US federal agencies need to know about OMB memorandum M-26-14: Part 1

The US Office of Management and Budget (OMB) has issued Memorandum M-26-14, “Ensuring Effective and Efficient Agency Logging and Network Visibility to Defend Against Evolving Cyber Threats,” and, effective immediately, rescinded Memorandum M-21-31. For federal agencies and the teams who defend their networks, this is a meaningful shift. M-26-14 moves away from a single, prescriptive logging catalog toward an adaptive framework that asks agencies to employ a risk-based, prioritized logging approach. If your agency invested to meet M-21-31, that work still matters: M-26-14 is designed to build on it while giving you more flexibility. We covered the original requirements in a 2022 post, What US federal customers need to know about memorandum M-21-31.
In this post, we discuss what changed in federal logging requirements from M-21-31 to M-26-14, and how agencies can prepare ahead of the forthcoming Cybersecurity and Infrastructure Security Agency (CISA) logging reference architecture (LRA).
From M-21-31 to M-26-14: What changed
M-21-31, published in 2021, responded to the SolarWinds incident and Executive Order (EO) 14028. It defined event logging (EL) tiers and an extensive catalog of log data for agencies to capture and retain across their systems, so relevant data would be available after an incident.
M-26-14 keeps that underlying intent—visibility before, during, and after an incident—but changes how agencies get there. Rather than applying one fixed catalog uniformly, agencies now work within an adaptive, risk-based framework and organize logging based on outcomes. The memorandum directs the CISA to publish an LRA that will serve as the core source of implementation guidance, letting agencies build on their M-21-31 progress while accommodating different missions and risk profiles.
Two objectives: CEM and THIRF
M-26-14 asks agencies to prioritize two objectives:
- Continuous Event Monitoring (CEM) – The logging and infrastructure that lets you monitor network activity in real time, promptly flag anomalous activity, and respond in a timely manner. A Security Operations Center (SOC) typically ingests and monitors these logs.
- Threat Hunting, Investigation, Response, and Forensics (THIRF) – The capability to investigate and perform forensic analysis after a known or suspected compromise. THIRF depends on sufficient hot and cold storage, plus the ability to retrieve and centralize log data from many sources to map how an attack unfolded. This is where proactive threat hunting lives: searching for known indicators of compromise and anomalous activity, and reconstructing attacker behavior, including initial access and lateral movement.
A risk-based approach to logging
The central change is how agencies decide what to log, and how much. M-26-14 expects risk-based decisions—informed by an agency’s threat environment, risk profile, and mission—rather than one checklist applied everywhere. In practice, that means bringing the SOC, threat-hunting teams, and mission owners together to make deliberate choices. A few specifics support this approach:
- Scope now explicitly includes Internet of Things (IoT) devices and operational technology (OT) that are part of an agency’s information systems.
- Retention is tied to outcomes: logs must be searchable for at least 6 months (to support CEM) and retrievable for at least 12 months (to support THIRF).
- Storage can be centralized or decentralized, as long as logs are readily available to the agency’s top-level SOC. Centralizing storage, forwarding logs, federating access, or a hybrid of these are all acceptable.
A maturity model to plan against
M-26-14 introduces a revised maturity model in Appendix C that agencies use to measure and report progress as the percentage of systems operating at each level. It spans five levels, from Ineffective (Level 0) to Optimal (Level 4), across five elements:
- Inventory Visibility – How completely an agency’s IT, OT, and IoT assets are captured in a centralized inventory
- Collection Coverage – The share of inventoried assets whose required logs are searchable and retrievable
- Collection Operations – How well logs generate actionable alerts that are evaluated and tuned over time
- Data Retention – How long logs remain searchable and retrievable
- Log Management – How logs are stored, encrypted, and protected
One detail shapes strategy: a system’s overall maturity equals its lowest-scoring element, known as the “lowest watermark.” A single weak area sets the score, so it pays to find and close your lowest element first. Where the earlier EL tiers emphasized what you collected, this model measures how effectively you can see, retain, and act on it.
The following figure illustrates an example scoring across the five levels of the maturity model.
Figure 1: Sample self-assessment using the M-26-14 Logging Maturity Model. In this example, the agency scores unevenly across the five elements—illustrating how a single lagging area (here, Collection Operations at L1) constrains overall maturity regardless of strength elsewhere.
Where AWS fits
Because M-26-14 is technology-neutral and outcome-focused, there is no mandated product list. Amazon Web Services (AWS) supports both objectives with familiar building blocks. Services such as AWS CloudTrail, Amazon CloudWatch, and Amazon Virtual Private Cloud (Amazon VPC) Flow Logs help with the real-time visibility that CEM needs, while Amazon Simple Storage Service (Amazon S3) storage tiers and Amazon Security Lake and Unified Data Store support the retrievable, centralized-or-federated storage that THIRF depends on. If your agency is getting started on AWS or revisiting its logging strategy, the Landing Zone Accelerator on AWS (LZA) can help automate the deployment of many of these services and centralize logs in a dedicated log archive account as your environment grows.
Conclusion and next steps
The US OMB has issued Memorandum M-26-14, and, effective immediately, rescinded Memorandum M-21-31.
To prepare for this change, US Federal Agencies can review the following items:
- Read M-26-14 and communicate that M-21-31 is rescinded
- Begin framing logging as a risk-based decision across the five maturity elements, and identify your lowest-watermark gaps
- Bring your SOC, threat-hunting, and mission teams together to weigh centralize-or-federate options
- Watch for CISA’s LRA at cisa.gov/Logging
