Congress has extended the Cybersecurity Information Sharing Act of 2015 (CISA 2015) through December 11, 2026, but the record does not show agreement on a long-term extension or a package of modernization changes. The statute supports voluntary sharing of cyber threat information and includes legal and privacy safeguards. Lawmakers and witnesses have discussed updating it, but their proposals differ on timing, duration, and substance.
What is the current status of CISA 2015?
The current preliminary text of 6 U.S.C. § 1510 says the relevant subchapter is effective through December 11, 2026. Public Laws 119-75 and 119-103 extended the date, first to September 30, 2026, then to December 11, 2026. That is the operative date; the September 30, 2025 expiration date in the Congressional Research Service’s April 2025 explainer was overtaken by later legislation.
The expiration date applies to the law’s specified subchapter. It is not a claim that all cybersecurity information sharing becomes illegal on December 12. The practical consequences of expiration depend on the authorities and protections at issue; CRS outlined potential implications but did not establish that every form of sharing or every program would stop.
Is there consensus on reauthorization?
There is documented support for renewing the law, but support for renewal is not the same as agreement on a permanent extension, its length, or whether changes should be attached. At a May 15, 2025 House Homeland Security Committee hearing, Chairman Andrew R. Garbarino said, “I strongly support reauthorizing CISA 2015.” Witnesses at that same hearing raised differing views on whether Congress should renew the law cleanly before making changes or address statutory ambiguities as part of the work.
Free tools Windows power users keep installed
One-click scans. No signup required.
#1 Best Overall
The record of proposals underscores those differences:
| Record | What it establishes | What it does not establish |
|---|---|---|
| House hearing, May 15, 2025 | The committee chair publicly supported reauthorization. Witnesses discussed clean renewal, ambiguities, privacy, legal certainty, and possible updates. Hearing record | A shared committee position on duration or a final modernization package. |
| Senate record, October 8, 2025 | A floor exchange addressed a proposed ten-year extension and an objection to immediate consideration of S. 1377. Congressional Record | That the proposal became law or reflects agreement on the eventual extension. |
| Public Laws 119-75 and 119-103 | Temporary extensions moved the statutory effective date to December 11, 2026. Current U.S. Code | A settled long-term reauthorization or adopted modernization terms. |
Separately, S. 2983, the Extending Expired Cybersecurity Authorities Act, was introduced by Senators Gary Peters and Mike Rounds and placed on the Senate calendar in October 2025. Its GovInfo record documents the bill and its listed action at that time; it does not establish its later disposition.
Rank #2
What does CISA 2015 do?
Enacted as Title I of the Cybersecurity Act of 2015, the law established federal procedures for sharing cyber threat information and authorized voluntary sharing by private entities. As summarized by CRS, federal agencies with such information can establish classified and unclassified sharing procedures. Private entities may share information related to identifying and defending against cyber threats with government and other private entities.
The statute also provides specified protections and responsibilities for covered activities. These include antitrust protections for authorized information sharing, liability protections for certain monitoring, protective actions, and sharing, protection from certain disclosure requirements, and a duty to remove personally identifiable information from information shared under the statute. DHS and DOJ are directed to issue guidance, including guidance addressing civil liberties. These are particular statutory provisions, not a blanket immunity for any cybersecurity activity.
Crashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minutePC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11Rank #3
How the Automated Indicator Sharing Program fits
The Automated Indicator Sharing Program (AIS) is one voluntary way to implement the law. Participants can use an AIS client server for real-time, machine-to-machine exchange of indicators—technical artifacts or observables that may point to an imminent or ongoing attack or a possible compromise. CRS notes that manual reporting and other methods may also qualify for statutory protections when the required agreement is in place. AIS is a mechanism for sharing; it is not the whole of CISA 2015.
How is CISA 2015 different from CIRCIA?
The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) and CISA 2015 serve different, complementary functions. CRS describes CISA 2015 as enabling potentially preventive, continual, multidirectional sharing. CIRCIA establishes mandatory reporting for certain covered entities and specified cyber incidents or ransomware payments. In broad terms, one supports ongoing exchange that may help prevent or defend against threats; the other collects reports about defined events. CRS says they operate in tandem, not as substitutes.
Rank #4
What changes are under discussion?
Modernization ideas have been raised in testimony and CRS analysis, but they have not become an agreed legislative package. The May 2025 hearing is a record of individual witness positions, not proof that Congress settled what to change or when.
- Definitions and scope: Clarify terms and coverage related to cyber threat indicators, defensive measures, substantial incidents, third-party incidents, and “damage.” CRS also identifies adapting definitions to new attack vectors or technology as a possible legislative choice.
- Technology-neutral language: Keep the statute useful as defensive tools and attack methods change.
- Privacy and civil liberties: Examine how safeguards work alongside timely exchange of threat information.
- Trust and coordination: Improve communication and collaboration between public- and private-sector participants.
- Sharing programs: Review AIS effectiveness and participation, and consider whether AIS or the Joint Cyber Defense Collaborative (JCDC) should be modernized or expanded.
- Voluntary or required sharing: Decide whether the voluntary model should remain as written or whether particular aggregators or critical-infrastructure sectors should have specific sharing requirements.
These choices involve trade-offs. A clean extension could preserve the existing framework while leaving contentious amendments for later; pairing renewal with amendments could address uncertainties sooner but requires agreement on what those amendments should be. The hearing record contains both calls to renew first and testimony urging attention to ambiguities, so neither approach should be described as a settled congressional plan.
Best Value
What can be said about the law’s effectiveness?
The cited CRS, statutory, and congressional records establish the law’s provisions, its sunset date, and the proposals and views described above. They do not establish a named, comparable statistic that measures the law’s overall effectiveness. A hearing submission refers to an organization’s report count without identifying the organization in the cited passage, so it cannot support a representative program-wide figure.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




