OMB M-26-14 replaces M-21-31 with a risk-based logging maturity model (levels 0–4) that ties every milestone to asset inventory completeness. Agencies must demonstrate 70–95% IT/OT/IoT asset capture across levels 1–4, with level 1 due 120 days and level 3 due 321 days after CISA publishes the logging reference architecture. Because overall maturity is scored at the lowest-performing element, incomplete asset inventories block all progress. OT and IoT devices are explicitly in scope, making passive discovery tools essential. Tenable positions its CDM-approved platform as the solution for building authoritative inventories, safe OT scanning, and AI-driven risk prioritization to help agencies meet the aggressive deadlines.
Table of contents
Key takeawaysYou can’t log what you can’t see, and you can’t measure logging maturity against an incomplete inventoryWhat M-26-14 requires, and why it’s different from M-21-31The denominator problem: Why incomplete inventories break the maturity modelHow Tenable maps to M-26-14’s requirementsBeyond inventory: Prioritizing logging resources where threat intelligence risk is highestThe pre-LRA window: What agencies should do before the clock startsLogging maturity starts with knowing what you haveDon’t wait for the clock to start: Secure your OMB M-26-14 foundation now48 Impressions