Skip to main content
Compliance

Congress Extends Cyber Info-Sharing Law Through December

Empty congressional hearing room with wooden table and chairs in soft natural light.

Dec. 11 is now the temporary cutoff for several core federal cyber authorities that were set to expire at the end of the federal fiscal year, under a short-term funding package passed by the House.

Cybersecurity Information Sharing Act of 2015 extended through Dec. 11

The House approved a continuing resolution on Tuesday that funds federal agencies through Dec. 11 and, among other measures, prevents the Cybersecurity Information Sharing Act of 2015 from sunsetting on Sept. 30. The legislation temporarily preserves the law’s key authorities while a longer-term reauthorization remains unresolved. The stopgap is part of a broader package that President Donald Trump is expected to soon sign to avert a fiscal year 2027 government shutdown before the midterm elections.

What the law protects: liability shields for voluntary sharing

The 2015 law provides liability protections to private sector companies that voluntarily share cyber threat intelligence with agencies like the NSA or the Cybersecurity and Infrastructure Security Agency. Those liability protections are designed to shield firms from lawsuits and regulatory penalties when sharing threat information with the government. The shared data often includes personal or proprietary information tied to individuals and companies affected in cyber intrusions.

Political friction around reauthorization

Efforts to secure a long-term reauthorization for the Cybersecurity Information Sharing Act have faced repeated delays over the past year despite what the source describes as broad support from officials and industry. The source notes continuing political pushback: "Senate Homeland Security and Governmental Affairs Committee Chair Rand Paul Paul, R-Ky., has routinely pushed back on clean extensions of the law." That resistance has helped produce the temporary stopgap rather than a multi-year renewal.

Technology Modernization Fund and federal intrusion detection authority kept alive

The continuing resolution also extends several other federal IT and cyber authorities scheduled to expire on Sept. 30. The Technology Modernization Fund, which provides capital for civilian agency IT upgrades, is extended; the measure authorizes around $5 million for the fund to continue approving and financing new agency tech modernization projects. The spending measure likewise extends the Federal Cybersecurity Enhancement Act, which authorizes the National Cybersecurity Protection System for federal network intrusion detection.

How technologists, federal cyber officials, and procurement leaders are affected

  • Technologists and security teams: With the liability protections preserved through Dec. 11, companies that share threat intelligence with agencies retain the statutory shields that, according to the source, industry groups warn are necessary to avoid legal risk and a drop in private-sector disclosures.
  • Federal cyber officials: The source reports federal cyber officials have stated that a lapse in the statutory authority would disrupt real-time threat intelligence sharing across public and private networks. The temporary extension maintains the legal basis for those operations, at least through the December deadline.
  • Procurement leaders and agency IT modernization programs: The Technology Modernization Fund’s continued authorization — and the roughly $5 million permitted to keep approving new projects — allows selected civilian agency modernization efforts to move forward without immediate funding interruption.

Conclusion

The continuing resolution buys a narrow runway: statutory authorities that underpin cross-sector threat intelligence sharing and core federal intrusion-detection programs remain in force through Dec. 11, and roughly $5 million is authorized to keep the Technology Modernization Fund approving projects. The stopgap avoids an immediate lapse that industry groups and federal cyber officials warned could curtail disclosures and disrupt real-time intelligence flows. It leaves in place the political and procedural questions that have blocked a long-term reauthorization for the Cybersecurity Information Sharing Act of 2015 — questions that, according to the record in this package, will need resolution before the December deadline.

Original story