cisatrade-pressNewsThe Broadside2 min read

CISA 2015 liability shield extended to Dec. 11 in stopgap spending bill

The extension buys seven weeks. Congress still hasn't found a permanent home for the law, and the clock running out in December isn't a theoretical problem, it's a tort-liability cliff for every company that shares threat intel with CISA.


TL;DR

The House approved a continuing resolution that extends the Cybersecurity Information Sharing Act of 2015's liability and antitrust protections through December 11. The Senate added the CISA 2015 extension to the CR in August; the House had omitted it from its July version. The stopgap now heads to the White House. Without the extension, the law's protections would lapse September 30. The House-passed fiscal 2027 NDAA includes a nine-year CISA 2015 reauthorization, but the Senate hasn't acted on it, leaving a narrow window and no clear legislative vehicle for a permanent fix before the December cliff.

The extension is a patch, not a plan. CISA 2015 lets companies share cyber threat indicators with DHS and with each other without facing antitrust claims or civil liability. Those protections have been set to expire on September 30 since the law was enacted, and Congress has treated the deadline like a recurring calendar reminder it keeps snoozing.

The Senate forced the issue. The House's July CR didn't include CISA 2015 at all. Senators added the seven-week extension in August, and the House accepted it last week in a 370, 48 vote. The result: the law survives through December 11, but no further.

What happens after that is the open question. The House passed its fiscal 2027 NDAA in July with a nine-year CISA 2015 reauthorization tucked inside, on a 216, 212 vote. That bill is now in the Senate's hands. But the NDAA is a heavy lift in any year, and tying CISA 2015's fate to it means the info-sharing law is one stalled negotiation away from a lapse.

The December 11 cliff

Lapse wouldn't be a bureaucratic inconvenience. It would remove the liability shield that makes operational threat-sharing possible. Every indicator a defense contractor or critical-infrastructure operator passes to CISA (or to a peer) carries potential tort exposure without the statutory protections. A December 11 deadline with no fallback vehicle means companies should be watching the NDAA markup calendar as closely as they watch their own patch schedules.

What the next seven weeks look like

The Senate hasn't scheduled floor action on the NDAA. If the defense bill stalls, CISA 2015 needs another CR extension or a standalone reauthorization bill, neither of which has been introduced. The two-week DHS CR and full-year appropriations package the House sent to the president alongside this stopgap didn't carry a CISA 2015 fix either.

For now, the law is alive. But on borrowed time, for the third time this year.


Published ·Deep Fathom

CISA 2015 liability shield extended to Dec. 11 in stopgap spending bill — The Broadside