Senate CR extends CISA 2015 threat-sharing shield to Dec. 11
A lapse would have paused industry threat-sharing with DHS and put the administration's GOLD EAGLE vulnerability-patching initiative at immediate risk.
TL;DR
The Senate continuing resolution unveiled this weekend includes a short-term reauthorization of the Cybersecurity Information Sharing Act of 2015, pushing the Sept. 30 expiration to Dec. 11. Without it, the liability and antitrust protections that underpin industry threat-intelligence sharing with DHS and among contractors would have lapsed, forcing companies to pause those relationships. The extension buys Congress a 10-week runway while tying CISA 2015's fate directly to GOLD EAGLE, the Trump administration's vulnerability-patching clearinghouse that the White House has said depends fundamentally on the 2015 law.
The Senate CR lands in a week where the chamber faces a Sept. 30 shutdown deadline and a scheduled five-week recess. CISA 2015 had already lapsed once before (briefly in 2025, before a previous stopgap restored it) and the current reauthorization push has been bumpy. The House passed its own CR in July but omitted a CISA 2015 extension entirely. Meanwhile, a long-term reauthorization through Sept. 30 sits inside the House-passed fiscal 2026 DHS appropriations bill and a compromise House-Senate DHS spending package, but neither has cleared the Senate.
What's different this round is the legislative framing. A July 17 industry letter led by Business Roundtable, signed by ITI, the U.S. Chamber, BSA, SIFMA, and eight other trade groups, made the case explicitly in operational terms: the administration's GOLD EAGLE initiative, stood up under a June 2 executive order, cannot function without CISA 2015 protections. The letter didn't argue from principle; it argued from program dependency.
That shift matters. CISA 2015 reauthorization has historically been a stand-alone cybersecurity argument. Tying it to a named Trump-administration priority changes the political calculus for a CR that needs to clear both chambers.
Noah Barger, ITI's director of government affairs, reinforced the urgency in a July 31 post: "Congress shouldn't let the program lapse while they work through the legislative process. At a minimum, lawmakers must extend CISA15 before the end of September."
The practical stakes for contractors and DIB participants are concrete. Without CISA 2015, sharing a threat indicator with DHS (or with another company) carries antitrust exposure and FOIA risk that in-house counsel won't tolerate. Companies don't gamble on liability gaps; they pause. If the CR fails or the Dec. 11 deadline arrives without a permanent fix, that's exactly what happens.
Ten weeks to avoid the same cliff
Dec. 11 gives lawmakers a narrow window. The long-term reauthorization already exists in multiple legislative vehicles (the NDAA, the DHS appropriations package) but none have reached the president's desk. If Congress burns the 10 weeks without resolving the underlying bill, the same stopgap scramble repeats in December, and GOLD EAGLE's operational continuity stays contingent on continuing resolutions rather than statutory footing.
Published ·Deep Fathom