Logging Reference Architecture

CISA’s Logging Reference Architecture: What Changed and What It Means for Your Organization

Prepared by Queen City Cyber Consulting  |  September 2026

Executive Summary

On August 20, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) published the Logging Reference Architecture (LRA), an 80-page guide that translates the Office of Management and Budget’s Memorandum M-26-14 into concrete architecture, coverage, and governance decisions. M-26-14 formally rescinds the 2021-era M-21-31 and replaces its prescriptive event-logging tiers with an outcome-driven model built around two objectives: Continuous Event Monitoring (CEM) and Threat Hunting, Investigation, Response, and Forensics (THIRF).

The LRA is written for federal civilian agencies, but CISA explicitly frames it as a benchmark for critical infrastructure operators and private-sector organizations. For QCC clients, it is the clearest signal yet of where logging and visibility expectations are headed — for regulated entities working with federal partners, and for any organization that wants its logging program to hold up to scrutiny after an incident.

Key Dates May 22, 2026 — OMB issues M-26-14, rescinding M-21-31 August 20, 2026 — CISA publishes the Logging Reference Architecture (LRA) November 18, 2026 — Agency Logging Plans due to OMB/CISA (90 days from LRA publication) 320 days from publication — Deadline to reach “Advanced” (Level 3) on the M-26-14 maturity model

What Changed: M-21-31 → M-26-14 / LRA

The prior regime (M-21-31, 2021) is best remembered for its EL0–EL3 event-logging tiers — a checklist agencies worked through largely irrespective of whether the resulting data was operationally usable. M-26-14 and the LRA replace that model outright. The shifts that matter most:

  • From tiers to outcomes. The LRA discards the EL0–EL3 tier structure entirely. Logging is now judged by whether it supports CEM and THIRF — not by which checklist tier a system nominally reached. A source that’s “logged” but delayed, unparsed, or inaccessible to the SOC no longer counts as compliant.
  • Defined retention floor, but not “keep everything.” Logs must be actively searchable for a minimum of 6 months and retrievable for 1 year. Beyond that floor, M-26-14 explicitly pushes back on the cost and impracticality of retaining large volumes of data without operational purpose — storage-tier decisions are expected to follow actual use, not default accumulation.
  • A four-stage maturity model with a hard deadline. M-26-14 Appendix C defines maturity across five elements — Inventory Visibility, Collection Coverage, Collection Operations, Data Retention, and Log Management. Advanced (Level 3) is required within 320 days of the LRA’s publication; note that Level 3 only requires 3 months of searchable retention, while the full 6-month baseline in Appendix B still applies regardless of maturity level reported.
  • Logging infrastructure treated as protected, mission-critical infrastructure. The LRA calls for least privilege, separation of duties, monitored privileged access, segmentation, and integrity controls around the logging pipeline itself — plus resilience expectations (health signals, tolerance for partial failure, replay/backfill) that weren’t spelled out under M-21-31.
  • A required governance artifact: the Agency Logging Plan. Where M-21-31 asked for tier attainment, M-26-14 requires a living plan that documents architecture, coverage, fidelity, schema, retention, and above-baseline decisions — due within 90 days of the LRA and subject to periodic updates.
  • Formal AI/ML governance for logging pipelines. The LRA is the first CISA logging guidance to directly address AI-assisted detection, correlation, and triage. AI-generated outputs must be treated as derived data, not authoritative source records, with metadata tracing outputs back to the original telemetry and model version.
  • Zero Trust alignment, not a new ZT mandate. The LRA maps logging visibility to CISA’s Zero Trust Maturity Model 2.0 — identity, device, network, application, and data pillars — clarifying how logging evidences ZT enforcement rather than creating separate ZT requirements.

Notably, the LRA is explicit that agencies (and by extension, organizations following it as a benchmark) do not need to start over: work done under M-21-31 — identity analytics, UEBA, existing source coverage — remains valuable and should be evaluated against the new outcome criteria rather than discarded.

Why This Applies Beyond Federal Agencies

The LRA carries no regulatory force outside the federal civilian executive branch, but three things make it relevant to QCC’s client base:

  • Regulated and contracting organizations: businesses providing services to federal agencies, or operating in critical infrastructure sectors, should expect these expectations to flow downstream through contract language, audits, and cyber insurance underwriting.
  • Incident defensibility: the CEM/THIRF framing — can you detect it, and can you reconstruct it later — is a practical test any organization’s logging program should pass, independent of federal applicability.
  • A free, detailed reference: few organizations have the budget to develop this level of architectural guidance internally. The LRA’s baseline coverage tables, event-fidelity requirements, and maturity model are directly reusable for private-sector logging programs.

Roadmap for Businesses

QCC recommends a staged approach, mirroring the LRA’s own maturity model:

Stage 1 — Baseline & Gap Assessment (Weeks 1–2)

  • Inventory current log sources against the LRA’s nine baseline categories (identity/authentication, network, object/data activity, privileged/admin activity, endpoint, security-tool alerts, cloud/SaaS admin activity, high-value assets, IoT/OT).
  • Identify where logging exists but fails operationally — delayed delivery, unparsed fields, missing context, or data the response team can’t actually reach.
  • Assess current retention design against the 6-month searchable / 1-year retrievable floor.

Stage 2 — Architecture & Coverage Remediation (Weeks 3–8)

  • Close highest-risk coverage gaps first — privileged/administrative activity and object/data activity are called out as the categories most likely to quietly undermine incident response.
  • Move toward event-driven collection (native export, streaming, brokered forwarding) for high-value sources; reserve polling for sources that only expose data via API.
  • Separate actively-searchable storage from lower-cost retrievable/archival tiers — rightsizing cost without breaking the retention floor.
  • Establish shared normalization and schema handling so sources don’t each require bespoke parsing.

Stage 3 — Governance, Resilience & Documentation (Weeks 9–12)

  • Protect the logging pipeline itself: least-privilege access, monitored administrative changes, and integrity controls for datasets that may carry evidentiary weight.
  • Build pipeline health monitoring — dropped feeds, schema drift, and parser failures should surface automatically rather than being discovered during an incident.
  • Document architecture, coverage, and retention decisions in a logging plan modeled on the Agency Logging Plan structure — useful both for internal governance and for demonstrating due diligence to auditors, insurers, or federal partners.
  • If using AI/ML-assisted detection or triage, document data lineage — which model, which source records, and which human validated the output.

Where QCC Can Help

  • Baseline coverage and fidelity assessments benchmarked against LRA Section 6
  • Logging architecture design and vendor-neutral pattern selection (repository-first, dual replication, SIEM-first, etc.)
  • Logging plan documentation for clients pursuing federal contracts, cyber insurance renewal, or compliance audits
  • Ongoing validation and pipeline health monitoring as a managed service

Key Terms at a Glance

CEMContinuous Event Monitoring — ongoing detection using log telemetry
THIRFThreat Hunting, Investigation, Response, and Forensics
M-21-312021 OMB memo, now rescinded, that introduced EL0–EL3 logging tiers
M-26-14May 2026 OMB memo replacing M-21-31 with outcome-based logging requirements
LRACISA’s Logging Reference Architecture (Aug 2026) — implementation guidance for M-26-14
Agency Logging PlanRequired governance document describing an agency’s logging architecture and decisions

Sources: CISA, Logging Reference Architecture (August 2026); OMB Memorandum M-26-14 (May 22, 2026). This briefing is an independent summary prepared by Queen City Cyber Consulting for client use and does not constitute legal or compliance advice.

Leave a Reply

Discover more from Dave Does Cyber Security

Subscribe now to keep reading and get access to the full archive.

Continue reading