executive-ordertrade-pressNewsThe Broadside2 min read

Senate NDAA amendments push CISA 2015 renewal to 2036

Congress is treating cyber information sharing as plumbing now, while hanging sector-specific mandates off the same defense-policy pipe.


TL;DR

Inside Cybersecurity reports senators have filed more than 700 amendments to the fiscal 2027 National Defense Authorization Act, including a Gary Peters measure to reauthorize the Cybersecurity Information Sharing Act of 2015 through fiscal 2036 before its Sept. 30 lapse. Other amendments target healthcare, satellites, semiconductors, connected vehicles, quantum, artificial intelligence and Federal Acquisition Security Council changes. Primes, contractors, managed service providers and state CISOs should watch what survives floor debate and conference, not the amendment pile itself.

The Senate NDAA amendment stack is doing what NDAA amendment stacks do: turning a defense-policy bill into the place where cyber programs either get renewed, redirected or quietly become everyone’s problem. Inside Cybersecurity reports that senators have filed more than 700 amendments to the fiscal 2027 National Defense Authorization Act, including a Peters amendment to extend the Cybersecurity Information Sharing Act of 2015 through fiscal 2036. The law is otherwise set to lapse Sept. 30, and its renewal effort now sits alongside healthcare, satellite, semiconductor and procurement-security measures.

That mix is the signal. CISA 2015 is no longer being treated like a standalone cyber policy debate. It is baseline infrastructure, the liability-and-antitrust-protection regime that lets private entities share cyber threat information with the Department of Homeland Security, according to prior Inside Cybersecurity coverage: https://insidecybersecurity.com/daily-news/senate-intelligence-reauthorization-bill-features-10-year-cisa-2015-extension-lawmakers. The fourth reauthorization cycle now arrives bundled with sector bills that would push Commerce toward voluntary satellite cybersecurity recommendations, HHS toward healthcare cyber resilience work, and SelectUSA toward semiconductor supply-chain investment coordination.

For practitioners, the procurement piece may matter more than the headline renewal. Peters also filed an amendment to change the Federal Acquisition Security Council, and the House version of the fiscal 2027 NDAA already includes legislation to revamp FASC. That is where a policy amendment can become a contractor-screening problem. Primes, subcontractors and managed service providers do not need to rewrite controls because an amendment was filed. They do need to track whether the Senate and House converge on language that changes how federal supply-chain security reviews are performed.

The Senate is expected to begin floor work the week of July 13. Until the chamber finishes floor debate and the bill goes to conference, this is a watch list, not binding law. The open questions are straightforward: whether CISA 2015 reauthorization survives the House-Senate process, and which FASC changes escape the amendment pile with legal force.


Published ·Deep Fathom