cisatrade-pressNewsThe Broadside2 min read

House recess stalls CISA 2015 vote before Sept. 30 lapse

Threat sharing keeps getting treated as an NDAA bargaining chip, which is a management failure masquerading as floor procedure.


TL;DR

Inside Cybersecurity reports that House recess has delayed floor action on the fiscal 2027 National Defense Authorization Act, pushing the Cybersecurity Information Sharing Act of 2015 and the PILLAR Act toward Sept. 30 expirations. Companies could lose liability and antitrust protections for cyber threat sharing with DHS and peers. States and municipalities face a grant-program cliff. This is the third near-lapse cycle for CISA 2015; the system is now the problem.

House recess stalls CISA 2015 vote before Sept. 30 lapse
Editorial illustration · drawn by The Broadside

Inside Cybersecurity reports that the House left for recess after GOP disagreements blocked floor consideration of the fiscal 2027 National Defense Authorization Act, taking the Cybersecurity Information Sharing Act of 2015, CISA 2015, with it. The House Armed Services Committee had already folded a 10-year reauthorization into the NDAA through the Widespread Information Management for the Welfare of Infrastructure and Government Act. That would carry the law through fiscal 2035. For now, the statute still lapses Sept. 30.

The practical issue is legal plumbing. CISA 2015 gives companies liability and antitrust protections when they share cyber threat information with the Department of Homeland Security and with each other. If those protections lapse, the sharing culture Congress says it wants becomes a counsel-by-counsel risk call. That does not mean every threat feed dies at midnight. It means the statutory comfort that lets industry share quickly becomes contingent, negotiated and slower.

The state and local side is uglier because both the authorization and the money are exposed. Rep. Andy Ogles tried to add the Protecting Information by Local Leaders for Agency Resilience Act, the PILLAR Act, to the House NDAA, but the Rules Committee did not include it in the June 29 amendment package. The bill would reauthorize the CISA and Federal Emergency Management Agency cyber grant program through 2033. Congress has not approved additional appropriations for the program, which began in the 2021 infrastructure law with $1 billion over four years, so state CISOs and municipal IT shops are staring at both a statutory deadline and a funding gap.

The Senate path is available but crowded. Sens. Gary Peters and Mike Rounds are trying to add a 10-year CISA 2015 reauthorization to the Senate NDAA, while more than 700 amendments are pending and no parallel Senate measure reauthorizes the state and local grant program. Senate Majority Leader John Thune has signaled floor action the week of July 13. The House returns the same week with eight session days before August recess under the current schedule.

This is the third legislative cycle in which CISA 2015 reauthorization has drifted toward a near-lapse scramble. At that point the story is no longer just about calendar pressure. Congress has made a core cyber information-sharing shield dependent on NDAA timing, amendment triage and unrelated party fights. Contractors should review where their sharing programs rely on CISA 2015 protections. State and local teams should map which projects depend on the CISA/FEMA grant program, and whether they survive on state budgets if Congress misses the date.


Published ·Deep Fathom