When investigators started digging into SolarWinds, many federal agencies hit the same wall. They could tell they’d been breached. They couldn’t tell how far the attackers got, because the logs were thin, scattered, or already deleted.
OMB’s answer, in August 2021, was Memorandum M-21-31. It told agencies what to log, how long to keep it, and how fast to mature. Agencies spent the next four years, and a lot of money, chasing OMB M-21-31 compliance.
In May 2026, OMB tore it up.
The replacement, M-26-14, keeps the goal and drops much of the method. OMB Director Russ Vought wrote that some of the old requirements, especially keeping huge volumes of log data with no clear use, had proved neither practical nor cost-effective. Agencies now get a risk-based model instead.
That’s a reasonable correction. It also lands at an awkward moment, because attackers have started using AI agents that move faster and touch more systems than any human team. The question M-21-31 was really trying to answer hasn’t gone away. Months after an intrusion, can you prove what happened?
What Did M-21-31 Actually Require?
The old memo built a four-tier maturity ladder, EL0 to EL3. EL0 meant not meeting the basics. EL1 was the minimum: core event categories, collected centrally. EL2 and EL3 added more data types, deeper analysis, and tighter links to security operations. Agencies were supposed to reach EL3 by August 2023.
Most didn’t. The Government Accountability Office found in December 2023 that 20 of 23 agencies had missed that deadline, citing staff shortages, technical problems, and weak threat-information sharing.
The retention rules were where the costs piled up. Most logs had to stay searchable for 12 months, then sit in cold storage for 18 more, for 30 months in total. Full packet capture was the exception, and it surprises people. The National Archives schedule that formalized the memo set PCAP retention at just 72 hours, with longer retention allowed but not required.
That short window drew criticism almost immediately. In 2023, experts told NextGov that 72 hours of packets was close to useless for forensics, since most breaches are discovered long after the fact. One put it simply: the breach happened long before the 72 hours started.
So when a vendor talks about “long-term packet evidence,” it’s describing practice that goes beyond the old memo, not something the memo required. That distinction matters.
What Does M-26-14 Change?
Quite a lot, at least on paper.
| M-21-31 (2021) | M-26-14 (2026) | |
| Approach | Fixed log categories for every agency | Risk-based, prioritized logging |
| Retention baseline | 12 months active + 18 months cold | Logs retained and searchable for six months |
| Packet capture | 72 hours where PCAP is used | No fixed figure in the baseline; driven by investigation needs |
| Measuring progress | EL0–EL3 tiers per agency | Share of systems at each of four maturity levels |
| Core goals | Visibility and forensic reconstruction | Continuous event monitoring (CEM) and threat hunting, investigation, response and forensics (THIRF) |
CISA has 90 days to publish a Logging Reference Architecture. Agencies then have 90 days after that to submit updated logging plans built around CEM and THIRF. Further maturity deadlines fall at 120, 180, and 320 days. The baseline also requires timestamps synced over NTP and logs readily available to the agency’s top-level SOC.
One line deserves attention. To support THIRF, agencies must keep enough hot and cold storage to rebuild attack patterns from multiple sources. OMB has dropped the universal 30-month rule, but not the expectation that agencies can investigate after the fact. Each agency now has to decide for itself how much history it needs.
Why Do AI-Driven Attacks Raise the Stakes?
In mid-September 2025, Anthropic caught a Chinese state-sponsored group it calls GTG-1002 using Claude Code as an attack engine. The group pointed AI agents at about 30 targets, including tech firms, banks, chemical manufacturers and government agencies. By Anthropic’s estimate, the AI did 80 to 90% of the hands-on work: reconnaissance, exploitation, credential harvesting, lateral movement and data theft. It fired off thousands of requests, sometimes several per second, a pace no human team could sustain. Only a handful of intrusions succeeded, but it was the first documented campaign of its kind.
Think about what that does to an investigation. An agent can map a network, try dozens of credential pairs, and move sideways across systems in the time a human attacker spends on coffee. Host logs on compromised machines are exactly what a capable attacker, human or automated, tries to disable or clean up. And the cybersecurity race now moves on product release cycles rather than years, on both sides.
Packet data matters here because it doesn’t depend on the compromised host telling the truth. It records what actually crossed the wire. If an agent exfiltrated data at 3 a.m., the packets show it, even if the endpoint’s logs were wiped by 3:05.
Can Agencies Afford to Keep Packet Data?
This is the honest tension. Full packet capture is heavy. Keeping months of it across a large agency network costs real money, and M-26-14 was written partly because data hoarding hadn’t paid off.
The middle ground most practitioners describe looks like this. Keep full packets for the segments that matter most: internet gateways, links into sensitive enclaves, and traffic to and from crown-jewel systems. Keep flow records and metadata much longer and much more widely. Store everything tamper-resistant, with a documented chain of custody, so it holds up when CISA or the FBI ask for it, which the new memo still requires agencies to support.
Risk-based logging actually helps that argument. An agency that can show its packet retention is tied to specific threats and specific systems is doing exactly what M-26-14 asks.
Where Does AI Help on the Defensive Side?
Here’s the part the old memo underestimated. Collecting 30 months of logs was one problem. Making sense of them was a bigger one. Even Federal News Network’s coverage of the new memo noted that the data volumes ended up requiring AI and machine-learning tools just to understand them.
That’s where AI earns its keep for defenders:
- Hunting through archives. Models can search months of flow and packet metadata for patterns no analyst would think to query, such as beaconing, odd data volumes, or a service account suddenly talking to a new region.
- Encrypted traffic. Earlier FedRAMP guidance already pointed out that traffic agencies can’t decrypt can still be analyzed through metadata and machine learning.
- Faster triage. LLM-based assistants can summarize a suspicious session, draft timelines and pull related events across sources, which is the kind of AI-versus-AI defense work security teams increasingly rely on.
The catch is the same as always. AI hunting is only as good as the history it can search. A model can’t find a pattern in data you deleted.
How Should Agencies Plan Their Logging Now?
A few practical moves stand out as agencies rewrite their plans:
- Map retention to real threats. Long-dwell, state-backed intrusions justify longer windows on critical systems. Commodity threats may not.
- Separate ground truth from self-reported data. Use packets and network flows to check what host and application logs claim.
- Make archives searchable. Data you can’t query in a crisis is barely better than no data.
- Treat logs as evidence. Tamper-resistant storage and clear custody records still matter under the new memo.
- Plan for AI on both sides. Budget for analysis tools, not just storage, and assume attackers are automating.
FAQ
Q. Is OMB M-21-31 still in effect?
No. OMB rescinded it in May 2026 and replaced it with M-26-14, which requires risk-based logging plans focused on monitoring and forensics.
Q. Did M-21-31 require long-term packet capture?
No. Where packet capture was used, the formal retention was 72 hours. Most other logs had a 30-month total retention period.
Q. Why keep packet data if the rules don’t require it?
Because serious intrusions are often found weeks or months late, and packets give an independent record that host logs can’t. That matters even more when attackers use AI to move quickly and cover their tracks.
The Bottom Line
M-21-31 asked agencies to keep almost everything, and most couldn’t. M-26-14 asks them to keep what they actually need. That’s a better rule, but it puts the judgment back on each agency. With attackers now using AI agents that work at machine speed, the agencies that come out ahead will be the ones that can still reconstruct last spring’s network traffic when an investigator asks for it.
Related: AI Phishing Is Beating DMARC — Here’s What Still Works
