The Law Behind US Threat Sharing Expires on 30 September. The House Just Voted to Extend It by Ten Years.
On 25 July the US House of Representatives passed its $1.15 trillion fiscal year 2027 National Defense Authorization Act by 216 votes to 212. Buried in a bill mostly about defence procurement is a provision that matters to anyone who shares cyber threat information with the American government or with other companies: it would reauthorise the Cybersecurity Information Sharing Act of 2015through 2036.
The urgency is a date. CISA 2015 currently expires on 30 September 2026. That is roughly two months away, and the Senate's own draft of the defence bill does not contain a matching provision.
What the law actually does
CISA 2015 is not a mandate and never was. It is a set of legal protections that make voluntary sharing safe to do. Companies that exchange cyber threat indicators and defensive measures — with each other, or with the federal government through the designated channels — get liability protection, antitrust protection, and an exemption from Freedom of Information Act disclosure.
Remove those protections and the technical act of sharing stays possible while the legal calculus changes completely. A general counsel asked to approve sending indicators to a government portal without liability cover, or to a competitor without antitrust cover, will reasonably say no. That is the mechanism by which a lapse reduces sharing: not prohibition, but caution.
Why it keeps nearly expiring
This is not the first cliff. The law lapsed once already before being reauthorised through January 2026, then extended again to 30 September 2026 in a February appropriations package. Each extension has been short and attached to must-pass legislation rather than passed on its own.
The obstacle to a long-term renewal is specific rather than general. Senate Homeland Security and Governmental Affairs Committee Chairman Rand Paul has said he will block a lengthy reauthorisation unless it includes language barring the Cybersecurity and Infrastructure Security Agency from work countering online disinformation. That is a dispute about agency remit, not about whether threat sharing is useful — but it is sufficient to hold the renewal, and it is why the House provision faces what reporting describes as an uphill climb.
What this means outside the United States
European organisations often read this as domestic American politics. It is not, entirely. Threat intelligence sharing is transnational: indicators contributed by US companies flow through ISACs, vendor feeds and government partnerships that European defenders consume. A durable reduction in US private-sector sharing thins feeds that are relied on well beyond American borders.
It is also an instructive contrast with the EU's direction. NIS2 makes incident reporting compulsory for entities in scope, with deadlines and supervisory consequences. The US model has leaned on voluntary sharing made attractive through legal safe harbours. One approach is currently arguing about renewal deadlines; the other is arguing about implementation burden. Neither has obviously solved the problem, and organisations subject to both need to plan for each on its own terms.
What to do before 30 September
- Find out whether you rely on this. Many organisations share indicators through an ISAC, a vendor programme or a government portal without anyone tracking which legal protection underpins it. Ask which of your sharing arrangements depend on CISA 2015 cover.
- Talk to counsel now, not on 1 October. If the protections lapse, the question of whether to continue sharing becomes a legal decision with a deadline. Getting a position agreed in advance beats pausing your feeds while it is debated.
- Check contractual language. Sharing agreements sometimes reference the statute directly. A lapse may change what those clauses mean.
- Do not let intelligence become your only control. Feeds are valuable and they are also the part of a defence most exposed to policy weather. Controls that do not depend on knowing about a specific threat — patching cadence, least privilege, encryption of data at rest and in transit, tested backups — keep working regardless of what Congress does in September.
The honest summary
Nothing is decided. The House has voted, the Senate has not matched it, a named senator has committed to blocking long-term renewal over an unrelated dispute, and the clock runs out on 30 September. The realistic outcomes are another short extension attached to a funding bill, a ten-year renewal if the disinformation language is resolved, or a lapse.
Planning for the third outcome costs little and is the only one that hurts if you have not. That is usually the right way round.
Sources
- GovInfoSecurity: US House Votes to Extend Cyber Sharing Law for 10 Years
- Hunton: Congress Extends CISA 2015 Through September 2026
- Congressional Research Service: The Cybersecurity Information Sharing Act of 2015 — Expiring Provisions
- Congressional Research Service: FY2027 NDAA — Status of Legislative Activity
