What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Congress has extended the Cybersecurity Information Sharing Act of 2015 (CISA 2015) through December 11, 2026, but that temporary extension is not evidence of agreement on a long-term renewal or a package of upgrades. The law’s future duration and whether changes should accompany renewal remain unsettled in the congressional record available through September 28, 2026.

What is CISA 2015, and what is its current status?

CISA 2015 is the Cybersecurity Information Sharing Act of 2015, not the Cybersecurity and Infrastructure Security Agency, which is also commonly abbreviated CISA. Enacted as Title I of the Cybersecurity Act of 2015, it established procedures for federal sharing of cyber threat information and authorized voluntary sharing between private entities and government. The Congressional Research Service (CRS) summarizes the law and its provisions in its April 8, 2025 explainer.

The current preliminary text of 6 U.S.C. § 1510 makes the relevant subchapter effective through December 11, 2026. Public Law 119-75 first extended it through September 30, 2026; Public Law 119-103, enacted September 2, 2026, moved the date to December 11. The statute is the best source for the current date. An earlier CRS explainer described the then-scheduled September 30, 2025 expiration, which later legislation superseded.

What has Congress agreed on—and what remains disputed?

There is recorded support for reauthorization, including from House Homeland Security Committee Chairman Andrew R. Garbarino, who said at a May 15, 2025 hearing, “I strongly support reauthorizing CISA 2015.” That statement establishes his position, not unanimous support across Congress. The hearing record also shows differences over the law’s ambiguities, safeguards, and whether renewal should be clean or paired with changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The distinction matters: extending the law’s effective date keeps its framework in force for a specified period; it does not settle how long the next authorization should last or what the statute should say. For example, the October 8, 2025 Congressional Record documents a proposed ten-year extension and an objection to immediate consideration of S. 1377. Separately, GovInfo records S. 2983, the Extending Expired Cybersecurity Authorities Act, as introduced by Senators Gary Peters and Mike Rounds and placed on the Senate calendar. These records describe proposals and debate at that time, not a final long-term agreement or the bills’ later disposition: see the Senate floor record and S. 2983 bill record.

Date Action or record What it establishes
December 18, 2015 CISA 2015 became effective. The law created the information-sharing framework described by CRS.
May 15, 2025 House Homeland Security Committee hearing, “In Defense of Defensive Measures.” Committee leadership and witnesses discussed reauthorization, safeguards, implementation, and possible changes; testimony reflected more than one view.
October 8, 2025 Senate floor exchange and S. 2983 record. A ten-year proposal and a procedural objection were recorded; S. 2983 was introduced and placed on the Senate calendar.
February 3, 2026 Public Law 119-75 extended the effective period through September 30, 2026. A temporary extension.
September 2, 2026 Public Law 119-103 extended the period through December 11, 2026. The current statutory end date, subject to any later legislation.

What does the law do in practice?

CISA 2015 provides a legal framework for sharing cyber threat information. Under the framework summarized by CRS, federal agencies with relevant information can establish classified and unclassified sharing procedures, while private entities may share information related to identifying and defending against cyber threats with government and other private entities.

  • Sharing protections: The statute provides specified legal protections for covered activities, including antitrust protection for authorized sharing; liability protections for certain monitoring, protective actions, and sharing; and protection from certain disclosure requirements.
  • Privacy safeguards: Entities have duties to remove personally identifiable information from shared information in specified circumstances. DHS and DOJ are directed to issue guidance, including on civil liberties.
  • Automated Indicator Sharing: The voluntary AIS program supports real-time, machine-to-machine sharing through an AIS client server. CRS notes that other methods, such as manual reporting, may also qualify for statutory protections when the required agreement is in place. Indicators can include technical artifacts suggesting an imminent or ongoing attack or possible compromise.

These provisions are the framework Congress is extending; they do not by themselves establish a particular level of effectiveness. The CRS and hearing materials cited here do not supply a named, comparable statistic that measures the law’s overall results.

How is CISA 2015 different from CIRCIA?

The Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA) serves a different function. CRS describes the laws as complementary rather than interchangeable:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Feature CISA 2015 CIRCIA
Basic approach Voluntary sharing of cyber threat information among private entities and with government. Mandatory reporting for certain covered entities and specified cyber incidents or ransomware payments.
Information flow Potentially preventive, continual, and multidirectional exchange. Generally occasional, unidirectional reports about incidents or payments that have occurred.
Relationship Supports ongoing threat-information sharing. Collects required reports under its own framework; it does not replace CISA 2015.

This distinction is important when evaluating proposals to change CISA 2015: a reporting mandate under CIRCIA is not the same thing as voluntary, potentially real-time sharing under CISA 2015.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What changes have witnesses proposed?

The May 15, 2025 House hearing is a record of testimony and proposals, not an adopted modernization plan. Witnesses raised several possible areas for congressional attention, with differing views on whether they belong in a renewal bill or later legislation. The hearing record includes testimony on:

  • Clarifying definitions and scope: Potential subjects included cyber threat indicators, defensive measures, substantial incidents, third-party incidents, and “damage.”
  • Keeping the law technologically useful: Some testimony called for language that can accommodate changing attack methods and defensive technologies.
  • Privacy, civil liberties, and legal certainty: Witnesses discussed how protections should operate alongside timely information sharing and whether statutory ambiguities create uncertainty.
  • Improving sharing channels: Suggestions included reviewing AIS participation and effectiveness and considering modernization or expansion of AIS or the Joint Cyber Defense Collaborative (JCDC), as well as better trust and communication between public- and private-sector participants.
  • Considering who should share: Testimony addressed whether the voluntary model should remain as written or whether particular aggregators or critical-infrastructure sectors should face sharing requirements.

CRS also identifies changing definitions to accommodate new threats or technologies, and whether participation should remain voluntary, as choices Congress could consider. Some hearing testimony favored a clean extension first and further work later; other testimony argued that ambiguities merited attention. Neither position should be presented as an agreed congressional sequence.

Best Value

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.