OMB M-21-31 Compliance Made Easy With Splunk CES

Software supply chain attacks are increasingly complex and damaging — underscoring the importance of increased government visibility throughout a cybersecurity incident. Over the last two years, the U.S. Office of Management and Budget (OMB) Memorandum M-21-31 has challenged federal enterprises to achieve and demonstrate compliance with its security logging, log retention, log management and centralized access and visibility provisions to improve the federal government’s ability to identify and remediate cyber threats.

With the Compliance Essentials for Splunk (CES) app, agencies of any size have a flexible, customizable and scalable solution to meet the specific requirements of the OMB M-21-31 memorandum at different levels.

Protecting Our Nation’s Most Critical Assets With Splunk

The M-21-31 memorandum is a prescriptive plan to improve how organizations protect information and infrastructure in the United States. It helps them better respond to cyber threats and defend our nation’s most critical assets. As time passes, organizations that don't use technology to automate their security efforts will have to work harder to follow the rules and keep up with changing standards.

To help federal agencies meet these requirements on deadline, the Compliance Essentials for Splunk app helps agencies track their progress across the four Event Logging (EL) tiers, as described in OMB M-21-31. With CES, organizations can continually monitor their compliance posture across various control frameworks like:

About the Splunk Platform

Splunk is an all-in-one security platform that includes:

With flexible deployment options and customized pricing and log management features, Splunk streamlines cybersecurity compliance by aggregating logs, detecting anomalies with AI and machine learning, and securing assets against advanced threats — helping organizations meet the specific requirements of M-21-31.

Partnering With Splunk for M-21-31 Implementation

Splunk works with agencies at different stages of their M-21-31 compliance journey, whether at the beginning or closer to EL 3, by providing a consolidated set of vendor-agnostic analytics and visualizations based on the M-21-31 security requirements.

This solution provides a vendor- and data-agnostic framework that leverages Splunk's Common Information Model (CIM) to normalize data from multiple, disparate data sources and easily visualize and report on these security controls at scale — no matter the size or sophistication of the team responsible for monitoring and reporting on these requirements.

A dashboard visualizing the status of each Tier Level with percentages of data in Splunk rendered in green, yellow, orange and red.

Getting Started With CES

The CES app is available as a free download from Splunkbase and can run in Splunk Cloud Platform or in a customer on-premises environment. CES is built on Splunk Enterprise and is complementary to Splunk Enterprise Security (ES), our market-leading Security Information and Event Management (SIEM) platform. CES provides a fully customizable and tailored approach to meet the needs of any mission in any environment while allowing the organization to mature and adopt enhanced capabilities as their missions require.

Splunk recently released Compliance Essentials 2.0.1 which maps specifically to OMB M-21-31. Specifically, Version 2.0.1:

If you want to explore the technical aspects of your compliance journey more deeply, please contact us.

Related Articles

How Splunk is Helping Shape the Future of Higher Education IT by Tackling EDUCAUSE 2026 Top Issues
Industries
3 Minute Read

How Splunk is Helping Shape the Future of Higher Education IT by Tackling EDUCAUSE 2026 Top Issues

Dive into how Splunk aligns with key priorities highlighted at EDUCAUSE 2025.
Enhancing Government Resilience: How AI and Automation Empower Public Sector Missions
Industries
3 Minute Read

Enhancing Government Resilience: How AI and Automation Empower Public Sector Missions

Splunk helps government agencies boost security and efficiency with powerful, mission-ready AI and automation.
Solving Manual Mayhem in Telecom with Agentic AI
Industries
3 Minute Read

Solving Manual Mayhem in Telecom with Agentic AI

Agentic AI cuts downtime, improves security, and boosts customer experience, and with unified data from Splunk and Cisco, teams can build more resilient operations.
Upgrading to Splunk Enterprise 10.0 and Splunk Cloud Platform 10.0: Key Resources for Public Sector Customers
Industries
2 Minute Read

Upgrading to Splunk Enterprise 10.0 and Splunk Cloud Platform 10.0: Key Resources for Public Sector Customers

Splunk Enterprise 10.0 and Splunk Cloud Platform 10.0 deliver the most secure, stable, and modernized platform for a digitally resilient and compliance-ready future.
Building the Next Generation of Defenders: From the Classroom to the SOC of the Future
Industries
3 Minute Read

Building the Next Generation of Defenders: From the Classroom to the SOC of the Future

Resilience in the AI era doesn’t just happen – it's built one student, one SOC, and one organisation at a time.
Analytics That Work: 3 Approaches for the Future of Contact Centers
Industries
3 Minute Read

Analytics That Work: 3 Approaches for the Future of Contact Centers

Splunker Khalid Ali explains how unified, real-time intelligence connects data, empowers agents, and builds lasting customer loyalty.
Observability + Security: Real-Time Digital Resilience for SLED
Industries
1 Minute Read

Observability + Security: Real-Time Digital Resilience for SLED

Cisco and Splunk are helping public sector organizations build digital resilience.
Digital Resilience for State and Local Governments (Part Two)
Industries
3 Minute Read

Digital Resilience for State and Local Governments (Part Two)

Discover how collaboration—powered by shared data platforms like Splunk—can enhance incident response and overall digital resilience.
Reflections from SIBOS 2025: How will advances in technology (and especially AI) change the financial services industry over the next 5 years?
Industries
2 Minute Read

Reflections from SIBOS 2025: How will advances in technology (and especially AI) change the financial services industry over the next 5 years?

Discover key insights from SIBOS 2025 on how AI, collaboration, and data will reshape financial services over the next 5 years—prepare for rapid change and exciting opportunities ahead.