CISA publishes Logging Reference Architecture to guide federal agencies on enterprise logging standards

Original title: CISA Publishes Logging Reference Architecture for FCEB Agencies Under OMB M-26-14, Agency Logging Plans Due November 18, 2026

CISA has published the Logging Reference Architecture, an outcome-driven guide developed with OMB and the CISO Council to help federal civilian executive branch (FCEB) agencies establish enterprise logging, visibility, and operational standards. Agencies must use this guidance to develop an Agency Logging Plan and submit it to OMB and CISA by November 18, 2026, as required by OMB Memorandum M-26-14. The guidance supports continuous event monitoring, threat hunting, incident response, and forensics, and also addresses integration of AI into logging processes with appropriate governance.

What changed

  • CISA published the Logging Reference Architecture, a new practical, risk-based, prioritized guide for FCEB agencies to design and mature enterprise logging capabilities in line with OMB M-26-14.
  • The guidance includes operational checklists to help agencies design logging architecture, achieve baseline logging fidelity, and verify that logging plans are operationally ready to support required security outcomes.
  • CISA provides the M-26-14 Agency Logging Plan Template — a structured format to help agencies prepare the mandatory submission to OMB and CISA by November 18, 2026.
  • The guidance addresses integration of artificial intelligence (AI) into logging processes, directing agencies to maintain required governance and oversight when doing so.
  • Although developed for federal agencies, CISA explicitly encourages critical infrastructure entities and state, local, territorial, and tribal governments to use the guidance to benchmark their own logging and monitoring programs.

What the document requires

Federal agencies are required to establish an Agency Logging Plan and submit it to OMB and CISA by November 18, 2026, in accordance with OMB Memorandum M-26-14.

Who is affected

Primary: US federal civilian executive branch (FCEB) agencies — all sizes, required to comply with OMB M-26-14. Secondary: critical infrastructure entities and state, local, territorial, and tribal government organizations (encouraged, not mandated).

Summary generated by a language model; the official text prevails. Not legal advice.