Beyond the LRA: What OMB M-26-14 Means for Federal Cybersecurity Operations
Back to top
September 1, 2026
Beyond the LRA: What OMB M-26-14 Means for Federal Cybersecurity Operations
Until earlier this year, the official guidance for cyber event logging within civilian federal agencies could have been summarized in a single word: more. Over the past two decades, and most recently under the Office of Management and Budget (OMB) M-21-31 mandate, agency security teams had been advised to focus on increasing the volume of event logging, data retention, and SIEM ingestion.
With the May 2026 release of M-26-14, which formally rescinded M-21-31, OMB did more than update federal logging requirements: it changed the measure of success. How much telemetry agencies can collect and retain is no longer the point. What matters is whether visibility can be turned into the operational understanding needed to detect threats and prioritize responses faster, and ultimately reduce risk to mission. In that sense, M-26-14 marks a real shift from compliance-driven data collection toward outcome-driven cyber defense.
LRA release starts the implementation clock
The Logging Reference Architecture (LRA) has been officially published. This document gives federal civilian agencies a common reference guide to support architectural, operational, and governance decision-making supporting the development of the Agency Logging Plan. Agencies must submit their comprehensive logging plans within 90 days of the LRA release date. Within 30 days of that first milestone (LRA release + 120 days), agencies must demonstrate compliance with Initial (Level 1) maturity.
Continuous visibility and rapid response
M-26-14 is focused on two main operational objectives: Continuous Event Monitoring (CEM) and Threat Hunting, Investigation, Response and Forensics (THIRF). Together, they are essential in combining real-time threat detection with the ability to analyze large volumes of historical data to map attack patterns, determine incident scope, and ensure faster recovery.
It embraces the reality that modern cyber defense is not about simply retaining massive quantities of telemetry. It is about enabling operationally effective cyber defense through continuous monitoring, actionable analytics, AI-assisted detection, and rapid response, giving the SOC operator the decision advantage.
While the implementation timeline is aggressive, M-26-14 should not be viewed as an urgent administrative exercise. It is an opportunity for agencies to modernize data collection, gain enhanced visibility and coverage across their entire IT environment, and harden defenses against AI-accelerated cyber threats.
Zeroing in on the biggest strategic shifts for agencies
A close read of the memorandum and associated LRA is obviously important for compliance. But agency leaders should also take stock of the broader operational changes embedded in these documents. This mandate signals several major shifts in how federal cybersecurity programs will be measured and managed.
Design for outcomes, not ingestion
For years, federal security teams operated under a logging mandate that prioritized volume over value. M-26-14 changes that equation. The new framework is risk-based and operationally focused. The new standard is: can the data logged actually support investigation at speed, scope and scale of today’s threats, not how much data you can collect. The memorandum defines 11 measurable, activity-based outcomes, organized under the broader CEM and THIRF objectives, while avoiding vendor-specific log formats or protocols. Agencies now have greater flexibility in how they architect for those outcomes, but that flexibility also puts the burden on them to demonstrate that the data they collect is actually useful.
Logging coverage isn’t the same as operational visibility
Agencies need to ensure that CEM and THIRF capabilities extend to the entire enterprise, from cloud workloads to the infrastructure that supports mission-critical systems. This becomes particularly challenging in legacy OT and IoT environments where traditional agent-based logging may be limited or unavailable. It underscores the need for a more holistic approach to security, including real-time anomaly detection and lateral movement visibility.
The LRA emphasizes that while breadth of logging coverage across assets is a necessary baseline capability, the operational usability of the telemetry is what is most important. The standard of operational usability ensures that the data is searchable, structured, and actionable when the agency needs it most.
As defined in the LRA, coverage is measured by and must include the following elements:
- Timeliness: Speed of alert dissemination and mandated patching windows.
- Fidelity: Accuracy of threat signals and telemetry to minimize false positives and ambiguity.
- Context: Surrounding technical details like asset exposure, exploit automation, and post-exploitation impact.
- Validation: Verification procedures confirming that vulnerabilities are genuinely mitigated and systems are clean.
- Searchability: Ease of querying and indexing indicators of compromise (IoCs) and CVE entries across tracking tools.
- Correlation: Connecting isolated log events and alerts into a unified, actionable incident timeline.
- Integrity: Ensuring threat catalogs, feeds, and reporting dashboards remain tamper-proof and reliable.
CEM and THIRF require correlated visibility
Under the LRA (and aligned with Zero Trust principles), agencies must be able to correlate identity, endpoint, network, cloud, and administrative telemetry. Synthesizing these data sources is critical to gaining a comprehensive threat picture, especially in response to multi-stage attacks. It enables higher entity resolution, more effective event traceability and focused, actionable containment. Through the LRA, CISA makes this point clear: the ability to correlate identity, endpoint, network, and administrative data is essential. It is the foundation for accessing the high-fidelity decision-grade intelligence necessary to detect threats, run forensic investigations, and automate responses at machine speed.
Detection quality becomes a measure of maturity
The new maturity model introduced in M-26-14 spans five levels, from Ineffective (Level 0) to Optimal (Level 4), across the following five dimensions:
- Inventory Visibility – How completely an agency’s IT, OT, and IoT assets are captured in a centralized inventory
- Collection Coverage – The share of inventoried assets whose required logs are searchable and retrievable
- Collection Operations – How well logs generate actionable alerts that are evaluated and tuned over time
- Data Retention – How long logs remain searchable and retrievable
- Log Management – How logs are stored, encrypted, and protected
Under this new maturity model, the emphasis is on how effectively agencies can identify and eliminate threats. Detection quality (in terms of metrics like logging coverage, timeliness, fidelity, integrity, searchability, usability, and validation) stands in stark contrast to the previous weight given to SIEM ingestion volume.
Some anticipated challenges
One of the most critical challenges in implementing M-26-14 is the level of visibility it requires. Agencies need to achieve CEM and THIRF logging objectives across all information systems, explicitly including internet-of-things (IoT) devices and operational technology (OT) systems, whether owned, operated, or managed by third parties.
The new maturity model raises the bar. Each level of the five-tier model is tied directly to asset inventory visibility gates. Agencies cannot move beyond certain maturity thresholds without first meeting defined levels of asset discovery and coverage. This makes inventory visibility a foundational requirement. Agencies need to know what they have, where it resides, and whether it is covered before they can confidently assess gaps in logging, monitoring, and response.
Why network intelligence matters more than ever
With the release of M-26-14, targeted, high-signal network visibility is more important than ever. Agencies already collect logs from cloud services, applications, and endpoints. But those sources do not show what traversed the network between users, workloads, services, and unmanaged assets. The LRA clearly states that agencies should avoid reducing network activity logging to ‘coarse summaries that are insufficient for path reconstruction, segmentation analysis, or high confidence pivoting during incident response.” Network-derived, decision-grade intelligence provides an independent source of operational evidence. This intelligence complements authoritative identity, endpoint, cloud application, and administrative telemetry.
While Section 5.4 of the LRA outlines a number of architectural patterns for structuring logging, it clearly emphasizes that pattern selection should prioritize resilience, provenance, and operational usability. The LRA further states that agent-based and log-based telemetry are not sufficient to reconstruct east-west movement once an attacker is inside, especially through encrypted channels. Because network-derived telemetry fills these critical visibility gaps, the document makes it clear that network-level detection and response capabilities form a key pillar of mature operational readiness.
Continuous monitoring and digital forensics depend heavily on access to high-fidelity data and integrity protections across the full path (not only for data at rest). The LRA explicitly points out that the integrity of host and application logs can be degraded at several stages, including at collection, during forwarding, or through privileged administrative action. Network telemetry is inherently consistent and tamper-resistant, making it an important consideration for agencies looking to ensure a fully trustworthy logging architecture.
Network analysis and visibility tools like ExtraHop deliver value across all these requirements. These tools can
- Provide 100% visibility of all packets across an IP-based network to include the data center, cloud, and campus networks
- Provide OSI Layer 7 fluency across 100 protocols to understand the difference between an authentic vs malicious SQL transaction, kerberos request, file transfer, etc...
- Map to 92% of the MITRE attack framework.
- Provide Visibility, Analytics, and Forensics for the Network Operator, Security Operator, Systems Administrator, and Application Architect
- Provide over 400 behavioral detection models to provide instant notification of malicious attack
- Provide tamper proof Packet Capture for long term forensic analysis necessary
Practical next steps
The timeline defined by M-26-14 is aggressive. Agencies need to take a hands-on, methodical approach in line with the LRA requirements. Agency leaders should focus on three broad areas: assessing asset visibility; evaluating existing CEM and THIRF logging capabilities; and ensuring strategic alignment between SOC, threat-hunting; and application owners. Leaders should start by prioritizing the right set of questions to get a holistic picture of current coverage strengths and critical gaps. Below are the questions outlined in the LRA that every agency needs to ask:
- Are the required baseline telemetry categories present across the intended environments?
- Is the data timely enough, complete enough, and detailed enough to support monitoring, threat hunting, incident response, and digital forensics?
- Can analysts and responders search, pivot, retrieve, and reconstruct activity using the datasets the plan says they depend on?
- Are integrity, provenance, access, minimization, and sharing controls working as intended?
- Can the agency detect when the logging capability is degraded and recover from that degradation?
- Can the agency introduce change without silently breaking critical operational use cases?
Turn logging modernization into mission advantage
M-26-14 gives agencies an opportunity to modernize their threat detection, response, and forensics capabilities. One thing is clear: meeting the new LRA standard will require agency IT and security leaders to rethink their current approach. Agencies that augment existing logging architecture with the right tools to detect and understand all activity traversing their network will be better positioned to meet the maturity milestones outlined in the new mandate.
Learn more. Find out how ExtraHop can help you better prepare to meet the requirements of OMB M-26-14 and the corresponding LRA from CISA. Connect with one of our experts today.

Senior Strategic Advisor - Public Sector
Colonel Sarah Cleveland, USAF (Ret.), serves as Senior Director of Federal Strategy at ExtraHop Networks and brings more than 30 years of cyber operations, communications, and national security experience spanning military and federal missions.
Throughout her 26-year career in the United States Air Force as a Cyber Operations Officer, Sarah held leadership positions at the Squadron, Group Command, and Joint Directorate levels (J6, G6, and A6), leading communications, cyber operations, and mission-critical infrastructure supporting both garrison and deployed operations in disadvantaged, denied, degraded, intermittent, and limited (DDIL) environments.
Her operational experience includes deployments supporting combat operations in Iraq, Afghanistan, and across the Middle East, as well as training Colombian and Polish Special Operations Forces on communications tactics, techniques, and procedures. In her final Air Force assignment, Sarah led the global NC3 (Nuclear Command, Control, and Communications) sensor network for the Air Force Technical Applications Center (AFTAC), overseeing operations, sustainment, continuity planning, and global infrastructure supporting nuclear treaty monitoring and strategic national security missions.
Sarah advises the Department of Defense and Federal agencies on Zero Trust, cyber resilience, network detection and response (NDR), and the modernization of security operations in increasingly contested digital environments. She is a frequent speaker at cybersecurity and defense conferences, including Black Hat and NATO-related cyber defense exercises.
Share
Key Takeaways
- The publication of OMB M-26-14 and the corresponding LRA marks a real shift from compliance-driven data collection toward outcome-driven cyber defense.
- The LRA emphasizes that while breadth of logging coverage across assets is a necessary baseline capability, the operational usability of the telemetry is what is most important. The standard of operational usability ensures that the data is searchable, structured, and actionable when the agency needs it most.
- Through the LRA, CISA emphasizes that the ability to correlate identity, endpoint, network, and administrative data is essential. It is the foundation for accessing the high-fidelity decision-grade intelligence necessary to detect threats, run forensic investigations, and automate responses at machine speed.
- With the release of M-26-14, targeted, high-signal network visibility is more important than ever. Agencies already collect logs from cloud services, applications, and endpoints. But those sources do not show what traversed the network between users, workloads, services, and unmanaged assets. Network-derived, decision-grade intelligence provides an independent source of operational evidence. This intelligence complements authoritative identity, endpoint, cloud application, and administrative telemetry.


