Years of escalating nation-state threats and AI-enabled attack techniques, and learning hard lessons along the way, have led federal cybersecurity leaders to a clear conclusion: Real-time visibility, risk-based prioritization, and operational excellence are foundational capabilities for modern cyber defense.
U.S. federal cybersecurity policy has sought to balance mission outcomes with compliance through an evolving series of executive orders, Office of Management and Budget (OMB) memoranda, and Cybersecurity and Infrastructure Security Agency (CISA) directives.
Two recent mandates—OMB M-26-14: Ensuring Effective and Efficient Agency Logging and Network Visibility and CISA BOD 26-04: Prioritizing Security Updates Based on Risk—represent the clearest expression of that strategy to date. Together, they reinforce a broader shift already underway: Federal agencies are moving away from periodic, point-in-time compliance toward continuous cyber operations.
Federal civilian agencies must determine how to operationalize continuous risk management at scale while managing constrained resources, increasingly complex environments, and always-on adversaries.
The implementation timeline has already begun. Agencies must adopt BOD 26-04 by Dec. 7, 2026, while M-26-14 establishes new expectations around the CISA Logging Reference Architecture and modern security operations. Meeting those expectations requires an operational platform that connects people, processes, and technology.
These mandates aren’t isolated policy updates. They accelerate a transformation that’s been building through Zero Trust, the Continuous Diagnostics and Mitigation (CDM) program, the Federal Information Security Modernization Act (FISMA), OMB Circular A-130, and earlier CISA directives. Together, they establish consistent expectations:
- Continuously understand the environment.
- Prioritize based on actual risk.
- Respond within defined operational timelines.
- Demonstrate measurable outcomes with evidence.
This represents a significant departure from traditional compliance programs, where security activities were often performed periodically to satisfy reporting requirements. Today's federal cybersecurity environment demands uninterrupted visibility, decision-making, and assurance.
For years, agencies primarily answered a compliance question: Did we complete the required security activity?
Today's mandates require that they ask something fundamentally different: Can we continuously identify risk, prioritize what matters most, respond quickly, govern consistently, and demonstrate measurable reduction in mission risk?
That shift from documenting activity to proving operational outcomes is what distinguishes these mandates. BOD 26-04 moves agencies beyond vulnerability severity scores by requiring remediation decisions to account for operational risk factors such as:
- Known exploited vulnerabilities (KEVs)
- Exploit automation
- Asset exposure
- Technical impact
Critical vulnerabilities must be remediated within three days, requiring agencies to rapidly identify affected assets, coordinate remediation, and verify completion. M-26-14 modernizes expectations for logging and network visibility around two operational missions:
- Continuous event monitoring
- Threat hunting, investigation, response, and forensics
Success is no longer measured by how much log data an agency retains, but by whether that data enables timely detection, investigation, and response.
These mandates build on foundational federal initiatives that are already underway.
BOD 23-01 established continuous asset visibility as a prerequisite for effective cyber defense. Agencies cannot remediate vulnerabilities within mandated timelines if they can’t identify every connected asset—including software, hardware, operational technology, internet of things (IoT) devices, medical systems, cloud resources, and unmanaged endpoints.
Similarly, OMB M-22-09 and Zero Trust guidance reinforce continuous identity verification, least-privilege access, and ongoing governance rather than periodic access reviews. As agencies increasingly rely on service accounts, APIs, and autonomous systems, continuous identity governance becomes just as important as traditional user access management.
It’s not enough to discover vulnerabilities, collect logs, certify controls, or manage access in separate systems. Agencies need four interconnected capabilities that work together as one operating model. Each maps directly to mandate requirements.
Agencies must discover every asset and exposure across the estate, from managed IT to operational technology to IoT to medical devices to the cloud. Once assets are visible, agencies prioritize remediation by real-world risk variables:
- Exploitability
- Asset criticality
- Access paths
- Business impact
It’s possible to meet BOD 26-04's three-day remediation demand only if agencies understand what they have, what's exposed, and what matters most. Proof of readiness comes automatically as remediation work flows through the system, creating an audit trail that proves always-on risk reduction.
Every identity must be discovered and governed continuously. That includes humans, service accounts, API keys, and AI agents. Agencies must know who and what has access to what, whether that access is justified, and when access decisions change.
Least privilege is not an annual access review. It’s steady enforcement. Add dormant identities, shadow AI agents, and excessive privileges, and the interior attack surface becomes the primary threat vector.
Executive Order (EO) 14409 makes clear that AI agents are a new class of identity that must be governed like every other class. Access decisions must be auditable and enforceable in real time.
Continuous Authority to Operate (cATO) replaces the traditional periodic (often annual or every three years) Authority to Operate (ATO) review cycle with an ongoing, automated, risk-based authorization process. Findings must be tracked to closure with a plan of action and milestones.
Real-time control validation helps ensure audit readiness every day, not just before inspection season. When regulators ask for evidence, it already exists. Risk, controls, and evidence are continuously measured, validated, and generated, respectively.
Every asset and its behavior must be visible in real time. That means collecting and analyzing real-time telemetry from every asset in every environment into one system.
Detection happens with risk context: what the asset is, who can reach it, its potential impact, and whether the behavior matches policy. Response connects to proof. When an incident is investigated or a vulnerability is remediated, the action is recorded, traceable, and auditable.
As the administration continues to prioritize automation and AI in defending federal systems and data, the importance of streamlined collaboration between agencies and their technology vendors will only increase.
The administration has recognized this through its FedRAMP 20x program. On the Department of War (DoW) side, standards such as NIST SP 800-171 have been a contractual vendor requirement for years. The DoW is assessing next steps for the enforcement of these standards across the industrial base, prioritizing efficiency over simple, point-in-time box checks.
On July 13, the DoW suspended its transition to Phase II of the Cybersecurity Maturity Model Certification (CMMC) program and stood up a CMMC Reform Task Force to conduct a top-to-bottom review of how the department secures its supply chain.
Pausing a program mid-rollout to ask hard questions and listen to industry feedback directly takes conviction. It’s exactly the kind of leadership that produces durable policy.
Agencies can no longer rely on disconnected security tools, manual handoffs, or fragmented ownership to meet increasingly aggressive operational expectations. Success depends on connecting security operations with enterprise execution so that work flows efficiently from detection through remediation and governance.
ServiceNow provides the operational platform that enables this transformation. As the workflow and system of action for cyber operations, ServiceNow connects asset intelligence, exposure management, identity governance, incident response, remediation, and compliance into a unified operating model.
Security teams gain a common view of operational risk, automate routine work, coordinate complex response activities, and continuously generate the evidence required to demonstrate compliance and mission assurance.
Agencies gain the ability to reduce operational risk faster, improve resilience, accelerate decision-making, and support mission delivery through continuous cyber operations.
Agencies that build an operating model around continuous visibility, risk-based prioritization, coordinated execution, and measurable assurance will be positioned to meet today's requirements and to adapt to tomorrow's threats and federal expectations.
Find out how ServiceNow can help you deliver continuous cyber operations.