Most security leaders have never read the Cybersecurity Information Sharing Act of 2015, and for a decade that was fine. It worked quietly in the background — the legal scaffolding that made it safe for a company to tell an ISAC, a peer, or the federal government “we’re seeing this indicator” without inviting an antitrust inquiry or a private lawsuit. Infrastructure you don’t notice is infrastructure that’s working.

It stopped working quietly in the autumn of 2025, and the reprieve since has been a series of increasingly short extensions. The current one expires on September 30, 2026 — six weeks from today.

How We Got Here

The law was enacted in 2015 with a ten-year sunset, which arrived on schedule and inconveniently.

  • September 30, 2025 — CISA 2015 sunsets during an extended government shutdown. The protections simply lapse.
  • November 12, 2025 — Congress passes a temporary renewal, effective only through January 30, 2026.
  • February 3, 2026 — the protections are reauthorized as part of a funding bill, extending them through September 30, 2026.
  • September 30, 2026 — expiration, again, absent congressional action.

Three deadlines in twelve months, each resolved late, none resolving the underlying question. Congressional interest in a long-term reauthorization exists; a durable path to one does not obviously exist, and observers of the process have been consistent that the outlook remains murky.

There is a pattern here that security leaders should name plainly: the legal foundation of threat intelligence sharing in the United States is now being managed on the same schedule as continuing resolutions, and with the same reliability.

What the Law Actually Does

The protections are narrower than most practitioners assume, which matters for planning.

Liability protection. Companies that share cyber threat indicators and defensive measures through authorized channels are shielded from private lawsuits arising from that sharing. Without it, an organization disclosing that it observed an indicator associated with a customer’s infrastructure has a genuine legal exposure question.

Antitrust safe harbor. Competitors may share threat information with each other without it constituting an antitrust violation. This is what makes sector ISACs function — banks sharing with banks, hospitals with hospitals.

Disclosure protections. Shared information receives protection from certain regulatory use and public disclosure requests, so a company sharing with the government isn’t handing over material that resurfaces in an enforcement action or a FOIA request.

Privacy obligations. The law also requires scrubbing personal information not directly related to the threat before sharing — an obligation, not a protection, and one that lapses along with everything else.

What the law does not do is compel sharing. Participation was always voluntary. The law’s function is to remove the legal reasons not to.

What the 2025 Lapse Actually Taught

The most useful thing about the six-week gap in late 2025 is that it was a live experiment, and the results were less catastrophic and more corrosive than either side of the debate predicted.

Sharing did not stop. Established relationships continued, because the practitioners in them trusted each other and the legal risk was theoretical rather than immediate. What changed was at the margins — and the margins are where most sharing actually happens.

Legal review appeared where it hadn’t been. Counsel that had been signing off on routine ISAC participation started asking questions, and each question added days. New sharing relationships slowed or paused, because nobody wants to establish a novel information flow with no liability protection. Companies with cautious general counsel became notably quieter. And the sharing that continued skewed toward the low-sensitivity end — indicators everyone already had, rather than the early, uncertain, high-value observations that make sharing worth doing.

That last effect is the one to worry about. The value of threat sharing is concentrated in the first few hours of a novel campaign, when the information is uncertain and the sharer is exposed. That is exactly the category of sharing that legal ambiguity suppresses first.

What This Means for Security Leaders

Get a written legal position before September 30, not after. Ask your general counsel a specific question: if the protections lapse on October 1, what changes about our participation in our ISAC, our vendor intel sharing, and our government reporting? Get the answer in writing while there is time to think about it. Organizations that had this conversation in September 2025 continued operating through the lapse; organizations that had it in October spent the lapse in review.

Inventory your sharing relationships and rank them by exposure. Not all sharing carries equal risk. Consuming intelligence is low-risk. Publishing indicators from your own environment to a broad audience is higher. Sharing with competitors sits squarely in the antitrust question. Know which of your flows fall where, so that if you have to reduce, you reduce deliberately rather than by reflex.

Check your ISAC and vendor agreements for lapse language. Some agreements written after 2025 include provisions addressing what happens if the statutory protections expire. Many predate the issue entirely and assume protections that may not exist in October. This is a contract review worth doing in the next four weeks.

Do not let this become a reason to stop sharing. The strategic case for threat intelligence sharing does not depend on the statute. The statute lowers the friction; the value was always the collective visibility. Organizations that treat every lapse as a reason to withdraw end up permanently less informed, and the withdrawal is much easier than the return. Mature intelligence programs have consistently found that collective visibility is where the leverage is — that doesn’t change on October 1.

Plan for this to recur. The realistic base case is not a long-term reauthorization; it is another short extension attached to another funding vehicle, resolved close to the deadline. Build your intelligence program so that a lapse is an inconvenience rather than a stoppage: documented legal positions, pre-approved sharing categories, and relationships robust enough to survive a quarter of ambiguity. Treat statutory uncertainty as a permanent operating condition, because on current evidence, it is one.

Brief the board once, briefly. This is the kind of issue that generates a panicked question at the wrong moment. A short written position — what the law does, what expiration would mean for us, what we’ve done about it — retires the question in advance.

What This Means for Careers

Cyber policy fluency is a genuine differentiator, and it is rare. The number of security practitioners who can explain CISA 2015’s protections accurately is small, and the number who can translate a statutory change into operational guidance is smaller. That translation skill — law to practice — is what separates senior security leaders from senior security engineers, and it is learnable without a law degree.

Threat intelligence roles are becoming legally sophisticated. A modern intelligence analyst needs to understand not just how to produce and consume intelligence but what may be shared, with whom, under what protections. Analysts who can operate confidently inside those constraints are more valuable than analysts who need counsel involved in every decision.

Government affairs and security are converging as a career track. Someone in every large organization has to track cyber legislation and translate it into internal action. That role has historically been filled ad hoc by whoever was interested. It is increasingly a defined position, and it sits at an unusually high leverage point between the security function and the executive team.

For anyone building toward a CISO role: this issue is a good proxy for the job. It is not technically difficult. It requires knowing that a statutory deadline exists, understanding what it affects, coordinating with counsel, making a risk decision under uncertainty, and communicating it upward in three sentences. That is what the work actually is at that level, and it looks very little like the work that gets people promoted into it.

The Bigger Picture

There is something quietly revealing about a country that treats its cyber information-sharing framework as a rider on funding bills. The law is not controversial in substance — the debate is about privacy provisions and duration, not about whether threat sharing should be legally safe. It lapses repeatedly not because anyone wants it to, but because it has been attached to a legislative process that produces deadlines rather than decisions.

For security leaders, the practical lesson is not about this statute. It is that the policy foundations the security profession depends on are less stable than the technical ones, and are moving in the direction of less stability rather than more. A program built on the assumption that the legal environment holds still is a program that will be surprised on a regular schedule.

Six weeks out, the reasonable planning assumption is another short extension arriving late — and the reasonable operating assumption is that you should be able to work through a lapse either way. Build for the second one, and the first stops mattering.

Sources: Covington Inside Privacy — “Cybersecurity Information Sharing Act of 2015 Reauthorized Through September 2026”; Davis Wright Tremaine — “Congress Extends CISA 2015 Through September 2026” (February 2026) and “CISA 2015 Has Sunset. Now What?” (October 2025); Hunton — “Congress Extends Cybersecurity Information Sharing Act of 2015 through September 2026”; Cybersecurity Dive — “Landmark US cyber-information-sharing program expires, bringing uncertainty”; Federal News Network — “Congress extends CISA 2015, but path to long-term reauthorization remains murky”; Congressional Research Service, “The Cybersecurity Information Sharing Act of 2015: Expiring Provisions” (IF12959); CNAS — “The Case for Long-Term CISA 2015 Reauthorization.”

This article is provided for informational purposes only and reflects the legislative status as of August 18, 2026. Congressional action before September 30 could change the outcome described here. Nothing in this article constitutes legal advice; organizations should consult counsel regarding their specific information-sharing arrangements.