October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

CISA 2015 Reauthorization: Current Deadline and What Congress May Change

CISA 2015 has a December 11, 2026, statutory deadline after temporary extensions. Renewal has support, but Congress has not settled a long-term extension or modernization package.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Congress has extended the Cybersecurity Information Sharing Act of 2015 (CISA 2015) through December 11, 2026, but the record does not show agreement on a long-term extension or a package of modernization changes. The statute supports voluntary sharing of cyber threat information and includes legal and privacy safeguards. Lawmakers and witnesses have discussed updating it, but their proposals differ on timing, duration, and substance.

What is the current status of CISA 2015?

The current preliminary text of 6 U.S.C. § 1510 says the relevant subchapter is effective through December 11, 2026. Public Laws 119-75 and 119-103 extended the date, first to September 30, 2026, then to December 11, 2026. That is the operative date; the September 30, 2025 expiration date in the Congressional Research Service’s April 2025 explainer was overtaken by later legislation.

The expiration date applies to the law’s specified subchapter. It is not a claim that all cybersecurity information sharing becomes illegal on December 12. The practical consequences of expiration depend on the authorities and protections at issue; CRS outlined potential implications but did not establish that every form of sharing or every program would stop.

Is there consensus on reauthorization?

There is documented support for renewing the law, but support for renewal is not the same as agreement on a permanent extension, its length, or whether changes should be attached. At a May 15, 2025 House Homeland Security Committee hearing, Chairman Andrew R. Garbarino said, “I strongly support reauthorizing CISA 2015.” Witnesses at that same hearing raised differing views on whether Congress should renew the law cleanly before making changes or address statutory ambiguities as part of the work.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The record of proposals underscores those differences:

Record What it establishes What it does not establish
House hearing, May 15, 2025 The committee chair publicly supported reauthorization. Witnesses discussed clean renewal, ambiguities, privacy, legal certainty, and possible updates. Hearing record A shared committee position on duration or a final modernization package.
Senate record, October 8, 2025 A floor exchange addressed a proposed ten-year extension and an objection to immediate consideration of S. 1377. Congressional Record That the proposal became law or reflects agreement on the eventual extension.
Public Laws 119-75 and 119-103 Temporary extensions moved the statutory effective date to December 11, 2026. Current U.S. Code A settled long-term reauthorization or adopted modernization terms.

Separately, S. 2983, the Extending Expired Cybersecurity Authorities Act, was introduced by Senators Gary Peters and Mike Rounds and placed on the Senate calendar in October 2025. Its GovInfo record documents the bill and its listed action at that time; it does not establish its later disposition.

What does CISA 2015 do?

Enacted as Title I of the Cybersecurity Act of 2015, the law established federal procedures for sharing cyber threat information and authorized voluntary sharing by private entities. As summarized by CRS, federal agencies with such information can establish classified and unclassified sharing procedures. Private entities may share information related to identifying and defending against cyber threats with government and other private entities.

The statute also provides specified protections and responsibilities for covered activities. These include antitrust protections for authorized information sharing, liability protections for certain monitoring, protective actions, and sharing, protection from certain disclosure requirements, and a duty to remove personally identifiable information from information shared under the statute. DHS and DOJ are directed to issue guidance, including guidance addressing civil liberties. These are particular statutory provisions, not a blanket immunity for any cybersecurity activity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How the Automated Indicator Sharing Program fits

The Automated Indicator Sharing Program (AIS) is one voluntary way to implement the law. Participants can use an AIS client server for real-time, machine-to-machine exchange of indicators—technical artifacts or observables that may point to an imminent or ongoing attack or a possible compromise. CRS notes that manual reporting and other methods may also qualify for statutory protections when the required agreement is in place. AIS is a mechanism for sharing; it is not the whole of CISA 2015.

How is CISA 2015 different from CIRCIA?

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) and CISA 2015 serve different, complementary functions. CRS describes CISA 2015 as enabling potentially preventive, continual, multidirectional sharing. CIRCIA establishes mandatory reporting for certain covered entities and specified cyber incidents or ransomware payments. In broad terms, one supports ongoing exchange that may help prevent or defend against threats; the other collects reports about defined events. CRS says they operate in tandem, not as substitutes.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What changes are under discussion?

Modernization ideas have been raised in testimony and CRS analysis, but they have not become an agreed legislative package. The May 2025 hearing is a record of individual witness positions, not proof that Congress settled what to change or when.

  • Definitions and scope: Clarify terms and coverage related to cyber threat indicators, defensive measures, substantial incidents, third-party incidents, and “damage.” CRS also identifies adapting definitions to new attack vectors or technology as a possible legislative choice.
  • Technology-neutral language: Keep the statute useful as defensive tools and attack methods change.
  • Privacy and civil liberties: Examine how safeguards work alongside timely exchange of threat information.
  • Trust and coordination: Improve communication and collaboration between public- and private-sector participants.
  • Sharing programs: Review AIS effectiveness and participation, and consider whether AIS or the Joint Cyber Defense Collaborative (JCDC) should be modernized or expanded.
  • Voluntary or required sharing: Decide whether the voluntary model should remain as written or whether particular aggregators or critical-infrastructure sectors should have specific sharing requirements.

These choices involve trade-offs. A clean extension could preserve the existing framework while leaving contentious amendments for later; pairing renewal with amendments could address uncertainties sooner but requires agreement on what those amendments should be. The hearing record contains both calls to renew first and testimony urging attention to ambiguities, so neither approach should be described as a settled congressional plan.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What can be said about the law’s effectiveness?

The cited CRS, statutory, and congressional records establish the law’s provisions, its sunset date, and the proposals and views described above. They do not establish a named, comparable statistic that measures the law’s overall effectiveness. A hearing submission refers to an organization’s report count without identifying the organization in the cited passage, so it cannot support a representative program-wide figure.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase09 OCT 267 minMortgage Escrow FAQs: Taxes, Insurance, Shortages, and Refunds
  2. The Money DeskBlogTheFinanceBase09 OCT 265 minHow Mortgage Escrow Accounts Work and What Homeowners Pay For
  3. The Money DeskBlogTheFinanceBase09 OCT 265 minHow to Read a Stock Chart, Volume and Market-Cap Data
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.