LogRiteLogRite

You cannot pass M-26-14 on logs that were never written.

Score it, close the gaps, and export the plan.

M-26-14 grades every agency on its weakest link, and for most that's the two things no one has been measuring: whether the logs that matter actually exist, and whether anyone can see what their AI is doing. LogRite was built for exactly that.

Storage was the easy part

The last mandate told agencies to store everything. They did, and drowned in petabytes nobody could read, let alone act on. M-26-14 throws that out.

And there is a category almost nobody can evidence yet: the AI your people and systems now use. Attackers already move at machine speed, and most agencies cannot say what their own AI did last quarter.

M-21-31 asked for

  • Retain everything
  • Prove you stored it
  • Volume as the metric

M-26-14 grades on

  • Capture what matters
  • Monitor in real time
  • Hunt threats in it
  • Evidence, not assertions

How the score works

You're graded on your weakest category, not your average

M-26-14 scores your agency across several logging categories, then sets your maturity at the lowest one. A single weak spot drags the whole grade down.

Log coverage, for most agencies the lowest category
AI visibility, the one almost nobody can evidence

Two things no tool has been able to measure, and exactly what LogRite fixes.

LogRite M-26-14 Maturity dashboard scoring all five Appendix-C elements, with the overall grade set by the lowest watermark and capped by Collection Operations
The M-26-14 Maturity dashboard: five Appendix-C elements, live-measured, overall set by the lowest watermark.

The clock starts at the LRA, not the memo

Every deadline in M-26-14 counts from the day CISA publishes the Logging Reference Architecture. Agencies that wait for it to land are already inside the window.

  1. Day 0

    CISA publishes the LRA

    Expected August 2026

  2. +90 days

    Agency logging plans due

    Scope, gaps, and the path to each level

  3. +120 days

    Maturity Level 1

    First graded checkpoint

  4. +180 days

    Maturity Level 2

    Coverage and monitoring have to be real

  5. +320 days

    Advanced maturity

    Graded on your weakest category

Coverage is the metric that moves slowest, because closing it means writing logs that were never there. LogRite measures it per system and takes it from a typical starting point of about 7% to 100%, at the code level, before a grader ever asks.

What each level asks for, and how you close it

The memo grades maturity across categories in its Appendix C matrix. LogRite maps your posture to that matrix, shows the categories holding you down, and closes them in the order the deadlines arrive. Flip a level to see the tools that get you there.

LogRite is a supporting control and a source of evidence. It does not by itself make an agency compliant, and the grading criteria follow CISA's Logging Reference Architecture once it is published.

AI visibility is the gap that caps the score

It's the gap most agencies have no answer for. Your people use AI tools; your systems call models in the background; and none of it lands in a log you control. That single blind spot is usually what holds an agency at a lower maturity level.

AI Warden closes it. Every AI call your agency makes is seen, held to your controls, and recorded, with a federal rule-set ready out of the box, so AI visibility moves from your weakest element to a column you can demonstrate.

  • Demonstrable visibility into every AI call your systems make
  • Sensitive data kept in before it can leave in a prompt
  • A complete, audit-ready record of AI activity
  • A federal M-26-14 rule-set, ready on day one
AI Warden request log in LogRite showing every relayed AI call with its allow, notify, or block verdict, the compliance frameworks it triggered, and latency
Every relayed AI call on the record: verdict, framework hits, and latency.

What agencies ask about M-26-14

What does OMB M-26-14 require?

M-26-14 replaces prescriptive log retention with a risk-based maturity model built on two objectives: Continuous Event Monitoring, meaning real-time detection and alerting in the SOC, and Threat Hunting, Investigation, Response and Forensics. Agencies must show visibility into identity activity, network traffic, object access, privilege changes and infrastructure events, and report their maturity as it improves.

How long must federal logs be kept and searchable?

Retained logs must stay actively searchable for at least six months. Storage alone does not satisfy the requirement: the memo grades whether the logs can actually be queried and acted on, which is why agencies that met M-21-31 by storing petabytes can still score poorly.

What replaced M-21-31, and what changed?

M-26-14 rescinds M-21-31. The old memo told agencies to store everything; the new one asks whether the events that matter were captured, whether anyone is watching them in real time, and whether an agency can evidence its posture. The bar moved from volume to usefulness.

When does the compliance clock start?

The clock starts when CISA publishes the Logging Reference Architecture, not when the memo was issued. From that publication date agencies have 320 days to reach advanced logging maturity, with logging plans and interim maturity levels due before it.

Why does AI visibility affect an agency's maturity score?

Agencies are graded on their weakest category rather than their average, so one blind spot sets the whole score. Model and agent calls made by agency systems usually land in no log the agency controls, which makes AI visibility the category most likely to cap the grade.

Federal-grade logging and AI governance, on your estate

Request a briefing to see coverage, AI visibility, and maturity mapping running on your own systems.