The Cybersecurity and Infrastructure Security Agency published a Logging Reference Architecture on August 20, 2026, to guide federal civilian executive branch agencies in establishing logging, visibility and operational standards. The agencies are required under Office of Management and Budget Memorandum M-26-14 to submit an Agency Logging Plan to OMB and CISA by November 18, 2026.

Developed with OMB and the Chief Information Security Officers Council, the guidance presents what CISA describes as a practical, risk-based and prioritized approach to logging. CISA said agencies can use it to update enterprise logging strategies and develop the required plans, while an accompanying M-26-14 Agency Logging Plan Template provides a structured planning format.

The reference architecture is designed to support priority logging capabilities for continuous event monitoring, threat hunting, incident response and forensics. It includes operational checklists intended to inform agencies’ logging architecture designs and organizational strategies, establish baseline logging fidelity, and assess whether plans are operationally ready to support required security outcomes.

“Cyber defense begins with insight. Robust logs provide the critical visibility needed to counter daily threats targeting federal systems. CISA is enhancing agency logging strategies to ensure security teams can rapidly detect and respond to cyber incidents,” said CISA Acting Executive Assistant Director for Cybersecurity Chris Butera. “The Logging Reference Architecture guides agencies away from fragmented practices, establishing a mature enterprise capability that maximizes the operational value of their data.”

CISA said the guidance will also inform agency decisions about integrating artificial intelligence into logging processes in ways that enhance operational value while maintaining required governance and oversight. The agency did not prescribe a single AI implementation in the release, instead placing those decisions within the broader planning and oversight framework.

Although the architecture was developed for federal agencies, CISA also encouraged critical infrastructure entities and state, local, territorial and tribal government organizations to review it as a benchmark for their own logging and monitoring plans. That recommendation does not extend the federal plan-submission requirement to those organizations.