Congress Punts CISA 2015 to December in Fourth Short-Term Patch
The liability shield that underpins industry-to-government threat sharing now runs on 90-day increments, just as AI vulnerabilities and critical-infrastructure attacks make it most urgent.
TL;DR
Congress extended the Cybersecurity Information Sharing Act of 2015 through early December in the continuing resolution passed Tuesday, the fourth short-term patch in 18 months for the law that underpins threat-data sharing between government and industry. The liability and privacy protections enable programs including Treasury's Gold Eagle AI vulnerability clearinghouse. Senate Homeland Security Chairman Rand Paul (R-Ky.) remains the obstacle to long-term reauthorization, holding out for free-speech restrictions on CISA. Practitioners get 90 days of certainty and the same open question they've had since last fall.
The continuing resolution that passed the House Tuesday extends CISA 2015 through early December. It's the fourth short-term extension in 18 months for a law that was supposed to be a settled framework a decade ago. The Senate has already passed the measure, and President Trump is expected to sign it.
The pattern is now the story. Congress hasn't managed a long-term reauthorization of the Cybersecurity Information Sharing Act since its authorities first lapsed during last fall's government shutdown. Each CR buys roughly 90 days. Each 90 days resets the same uncertainty for the primes, subs, and C3PAOs whose threat-sharing arrangements depend on the law's liability and privacy protections. Nobody rewrites their compliance program around a temporary extension. But everyone watches the clock.
The operational stakes have climbed during Congress's serial punting. The Treasury Department's Gold Eagle initiative, an AI vulnerability clearinghouse that pairs industry and critical-infrastructure operators with government agencies, runs on CISA 2015's liability shield. A coalition of industry associations told House leaders in July that "the program is fundamentally at risk if CISA 2015 is not extended." Recent cyberattacks on water and wastewater systems across multiple states have made the case for real-time threat sharing more concrete, not less. The Operational Technology Cybersecurity Coalition warned in late July that short-term patches are unsustainable: "We can no longer keep doing minor extensions of CISA 2015."
The Rand Paul problem
Senate Homeland Security and Governmental Affairs Committee Chairman Rand Paul (R-Ky.) has blocked otherwise bipartisan efforts at a clean, long-term reauthorization. Paul wants any CISA 2015 extension tied to restrictions on CISA's work countering disinformation. That free-speech objection has split what would otherwise be a broadly supported bill. The administration has pushed for a clean 10-year reauthorization. Industry groups want the same. Paul's committee controls whether either happens.
What changes Monday
Nothing. The liability protections stay in place. Threat sharing continues. Gold Eagle keeps running. The compliance director's job doesn't shift. What changes is that the clock resets to roughly 90 days, and the question of whether Congress can pass a permanent fix before the stopgap expires now lands in early December, when a lame-duck Congress will have even less bandwidth than it does now.
The continuing resolution also extends the Federal Cybersecurity Enhancement Act and the Technology Modernization Fund through December.
Published ·Deep Fathom