CISA 2015 Faces September 30 Expiration
Updated:
August 22, 2026
The Cybersecurity Information Sharing Act of 2015 is legally scheduled to expire on September 30, 2026, as of August 20, 2026. Congress is actively considering extensions, but none has yet changed that statutory deadline. The Senate passed legislation on August 8, 2026 that would move the expiration to December 11, 2026, while the House has backed a much longer renewal through its fiscal 2027 defense bill.
The distinction is important. The Senate’s 90-6 vote on H.R. 6500 approved an amended continuing-resolution package containing the short CISA 2015 extension. That Senate action alone does not amend current law. The House must accept the Senate amendment or Congress must resolve the chambers’ differences before a measure can reach the president. Current statutory text still says September 30, 2026.
What Happened With CISA 2015
CISA 2015 created a voluntary legal framework for private companies and federal agencies to exchange cyber threat indicators and defensive measures. Companies acting within the law can receive liability protection for qualifying monitoring and information-sharing activities. The statute contains an antitrust exemption for certain cybersecurity information exchanges and sets privacy requirements for information sent to the federal government.
The law should not be confused with the Cybersecurity and Infrastructure Security Agency, which is commonly called CISA. The information-sharing law dates to 2015. The federal agency using the same acronym was created in 2018.
Timeline: From 2015 Enactment To The Latest Update
The current deadline follows several extensions and one actual lapse.
- December 18, 2015: The Cybersecurity Information Sharing Act of 2015 took effect with an original expiration date of September 30, 2025.
- July 10, 2025: The Government Accountability Office said federal implementation had positively contributed to cyber threat information sharing. GAO said participating agencies had created required procedures and privacy protections.
- September 30, 2025: The original authorization expired after Congress failed to pass an extension before the deadline.
- November 12, 2025: Public Law 119-37 restored and temporarily extended the relevant authorities through January 30, 2026.
- February 3, 2026: Public Law 119-75 changed the CISA 2015 expiration date to September 30, 2026. That is the deadline currently written into 6 U.S.C. § 1510.
- July 22, 2026: The House passed its fiscal 2027 National Defense Authorization Act, 216-212. The bill contains a long-term CISA 2015 renewal derived from the WIMWIG proposal.
- August 8, 2026: The Senate passed H.R. 6500, as amended, 90-6. Section 2011 of the Senate package would replace September 30, 2026 with December 11, 2026.
- August 20, 2026: The enacted deadline remains September 30, 2026. The proposed December 11, 2026 date is not yet the controlling statutory date.
What Legal Protections And Systems Are Affected
Expiration would primarily affect the statutory protections surrounding future information sharing. CISA 2015 states that qualifying private entities cannot face a cause of action for certain monitoring or sharing activities performed under the statute. The framework covers exchanges of cyber threat indicators and defensive measures between private entities and government agencies.
Expiration would not necessarily shut down every technical threat-sharing system. Before the 2025 lapse, the Department of Homeland Security said the Automated Indicator Sharing system would remain online even if the law expired. The larger concern was whether companies would continue contributing sensitive threat intelligence after losing CISA 2015’s legal protections.
The statute contains an important continuity provision. Information obtained and actions authorized before the expiration date continue to receive the law’s applicable treatment after the sunset. The legal uncertainty concerns activity that occurs after the authorization ends.
Who Supports Or Opposes CISA 2015 Reauthorization
CISA 2015 has received broad support from cybersecurity companies, critical-infrastructure groups, and lawmakers who view voluntary information sharing as a central part of collective cyber defense. GAO’s 2025 review said federal policies and activities under the law had contributed positively to threat information sharing.
Long-term renewal has faced political obstacles. Sen. Rand Paul has linked his opposition to concerns about the separate Cybersecurity and Infrastructure Security Agency’s involvement in work related to online disinformation. The Record noted that the 2015 statute and the agency created in 2018 are legally distinct.
What The 2025 Lapse Showed
The 2025 expiration provided a practical test of what a CISA 2015 sunset could mean. The Washington Post reported on October 2, 2025 that some corporate legal departments were reconsidering threat-sharing activity after the legal shield expired. The lapse occurred during a broader federal government shutdown that sharply reduced staffing at the Cybersecurity and Infrastructure Security Agency.
Bloomberg Law reported on September 30, 2025 that the Automated Indicator Sharing platform would remain operational. Keeping the platform running did not replace the statutory protections companies relied on when deciding whether to send potentially sensitive threat intelligence to government or industry partners.
Latest Congressional Action
The House and Senate currently offer different paths.
The House-passed fiscal 2027 defense authorization legislation would provide a long-term renewal. The House approved that bill 216-212 on July 22, 2026. The Record reported that its CISA 2015 provision would extend the information-sharing framework for another decade. The Senate’s defense bill did not contain an equivalent provision at that stage.
The Senate has taken a shorter route through H.R. 6500. Its August 8, 2026 version contains a continuing resolution and multiple program extensions. Section 2011 changes CISA 2015’s proposed deadline to December 11, 2026. The Senate passed the package 90-6, with 1 senator voting present and 3 not voting.
That proposal remains distinct from enacted law. Organizations planning around CISA 2015 should therefore treat September 30, 2026 as the current legal sunset until legislation changing the date becomes law.
Financial, Legal, And Business Impact
The largest immediate business risk from expiration is legal uncertainty around voluntary sharing rather than the technical loss of every threat-intelligence channel. Companies could still exchange information under other lawful authorities, but the specific liability protections provided under CISA 2015 would no longer govern new activity once the effective period ends.
Reduced participation could leave companies and government agencies with less information about malicious infrastructure, attack indicators, and defensive techniques. GAO found that the law contributed to federal and private-sector information exchanges and supported automated information-sharing tools.
Threat intelligence remains only one part of cyber risk management. A continuous vulnerability management program gives organizations an ongoing process for finding, prioritizing, and correcting weaknesses inside their own systems even when external threat-sharing arrangements change.
What Remains Unclear About The CISA 2015 Renewal
The principal unresolved issue is the duration and form of the next extension. Congress could adopt the Senate’s short extension to December 11, 2026, enact a long-term renewal through defense legislation, pass separate legislation, or permit another lapse.
The Senate’s December 11 proposal would provide only a short negotiating window. A long-term extension would give companies more certainty, but House and Senate negotiators still need common legislative language before that outcome can become law.
How Bright Defense Can Reduce Cyber Risk Beyond CISA 2015
Bright Defense can reduce dependence on external threat-sharing protections through technical testing and continuous security oversight. Regular penetration testing can expose exploitable weaknesses in applications, APIs, networks, and cloud environments before attackers use them. Testing frequency depends on system changes, risk exposure, and regulatory requirements, as explained in Bright Defense’s guide on how often organizations should conduct penetration tests.
Security testing becomes more useful when organizations track corrective work after findings are reported. Continuous vulnerability management creates an ongoing cycle of finding vulnerabilities, assessing their severity, correcting weaknesses, and confirming remediation rather than relying only on periodic assessments.
Compliance controls require similar ongoing attention. Bright Defense’s continuous compliance guide explains how organizations can monitor control performance, collect evidence, track gaps, and maintain security requirements throughout the year.
Regular compliance monitoring can give teams visibility into control failures, unresolved risks, and missing evidence. That internal visibility becomes particularly useful when federal information-sharing rules are uncertain or external threat intelligence becomes less predictable.
Why The CISA 2015 Sunset Is Important
The September 30, 2026 deadline is a real statutory sunset, but it is not yet a confirmed final expiration. Congress is pursuing both short-term and long-term renewal options.
The most accurate status as of August 20, 2026 is that CISA 2015 remains in force through September 30, 2026. The Senate has passed language that would extend it to December 11, 2026, but that later date is not yet written into current law. The House has backed a longer renewal through its defense bill, leaving the final duration unresolved.
Sources
- U.S. House Office of the Law Revision Counsel – 6 U.S.C. § 1510: Effective Period (Current law, accessed August 20, 2026)
- U.S. Senate Appropriations Committee – Continuing Appropriations And Extensions Act, 2027, Division B-D Draft (August 2, 2026)
- U.S. Senate – Roll Call Vote 228: Passage Of H.R. 6500, As Amended (August 8, 2026)
- U.S. Senate – Commonly Searched For Legislation, 119th Congress (Accessed August 20, 2026)
- The Record – Extension Of CISA 2015 Info-Sharing Protections Passes As Part Of House’s Defense Bill (July 22, 2026)
- U.S. Government Accountability Office – Cybersecurity: Implementation Of The 2015 Information Sharing Act (July 10, 2025)
- U.S. Government Publishing Office – Public Law 119-37 (November 12, 2025)
- Congress.gov – H.R. 5371, Continuing Appropriations, Agriculture, Legislative Branch, Military Construction And Veterans Affairs, And Extensions Act, 2026 (November 12, 2025)
- Bloomberg Law – Federal Cyber Tip-Sharing Platform To Stay Online If Law Lapses (September 30, 2025)
- The Washington Post – Shutdown Guts U.S. Cybersecurity Agency At Perilous Time (October 2, 2025)
- Congress.gov – S. 754, Cybersecurity Information Sharing Act Of 2015 (2015)
- U.S. House Office of the Law Revision Counsel – 6 U.S.C. § 1505: Protection From Liability (Accessed August 20, 2026)


