U.S. Senate stalls CISA 2015 renewal
The cyber information-sharing law still lacks permanent renewal and is operating under short extensions through Dec. 11, 2026.
Permanent renewal of the Cybersecurity Information Sharing Act of 2015 remains stalled in the U.S. Senate, and the framework is operating under temporary extensions tied to federal funding. The latest extension, signed in September, keeps the protections in place through Dec. 11, 2026.
Permanent renewal of the Cybersecurity Information Sharing Act of 2015 remains stalled in the U.S. Senate, and the program continues to operate under short extensions tied to funding bills. The latest extension, signed in September, keeps the information-sharing protections in place through Dec. 11, 2026, which means Congress will need to act again before then.
What happened with the reauthorization of CISA 2015?
The permanent authority for the information-sharing protections expired at the end of fiscal 2025, and since then it has only been renewed through temporary extensions included in funding packages. That has left the framework exposed to new interruptions each time one of those extensions runs out.
The legislative picture shows bills in both chambers, but no final outcome. According to Government Technology, Sen. Gary Peters is advancing bipartisan proposals to extend it through fiscal 2035, while in the House, the bill backed by Homeland Security Committee Chair Andrew Garbarino passed committee unanimously but has not yet reached the floor.
What do the congressional records and private sector say?
Official House and Senate calendars list S. 2983, the bill introduced to reauthorize the Cybersecurity Information Sharing Act of 2015, as placed on their respective calendars. That is a formal procedural step, but it does not mean passage or enactment.
Pressure has also come from the private sector. In a letter to Congress, the U.S. Chamber of Commerce asked lawmakers to keep Section 1706 of H.R. 8800 in the fiscal 2027 NDAA, which would extend CISA 2015 through 2035. The group warned that without the law, defenders of critical infrastructure could lose a mechanism for sharing threat information involving state-backed actors and ransomware groups.
What operational risk remains open?
The immediate risk is that the regime could be interrupted again if Congress does not approve another extension before Dec. 11, 2026. Coverage from The Spokesman-Review says permanent renewal remains blocked in the Senate more than a year after the permanent authority expired.
That same outlet attributes the long-term blockage to Senate Homeland Security Committee Chair Rand Paul and says, without direct confirmation from legislative sources, that his conditions would include an amendment preventing the government from pressuring social media platforms on content moderation. Because that part is not directly confirmed in the legislative sources provided, it should be treated as an unverified account.
Sources
- Cyber information-sharing law stuck in Senate stalematespokesman.com· The Spokesman-Review
- Strategic Cyber Threat Intelligence Briefingcyberwarrior76.substack.com· Cyberwarrior76 Substack
- Federal Cyber Info-Sharing Law Languishes in Senategovtech.com· Government Technology
- Senate Calendars for October 6, 2026 — 119th Congress, 2nd Sessiongovinfo.gov· U.S. Government Publishing Office
- House Calendars for October 6, 2026 — 119th Congress, 2nd Sessiongovinfo.gov· U.S. Government Publishing Office
- Letter to Congress on the Fiscal Year 2027 National Defense Authorization Actuschamber.com· U.S. Chamber of Commerce



