The 2025 federal shutdown coincided with the lapse of key provisions of the Cybersecurity Information Sharing Act of 2015 (CISA 2015), creating concern about public-private cyber threat coordination. The House Homeland Security Committee said the combined disruption significantly constrained federal coordination with industry and the federal defensive cyber mission. That is the committee’s assessment—not a measured count of missed exchanges or proof that every sharing channel stopped. Congress later extended the relevant provisions through December 11, 2026.
What the shutdown meant for cyber threat sharing
On October 31, 2025, the House Committee on Homeland Security said the federal shutdown, together with the lapse of CISA 2015, significantly constrained federal coordination with industry and execution of the federal defensive cyber mission. The committee’s statement is the strongest contemporaneous characterization in the available sources, and should be read as an assessment rather than a quantified measurement.
The available evidence does not establish how many cyber indicators were shared, whether exchanges became slower, or which individual services or channels were interrupted specifically because of the shutdown. A disruption to federal operations and a lapse in statutory provisions are related but distinct issues; neither establishes that all cyber threat sharing stopped.
What expired—and what the lapse did not mean
GAO reported that CISA 2015 was set to sunset on September 30, 2025. The act encouraged federal and nonfederal entities to share cyber threat indicators and defensive measures. Its lapse affected the act’s provisions and protections; it was not a universal legal ban on organizations sharing cyber threat information.
#1 Best Overall
The broader statutory framework calls for collaboration and near-real-time sharing to address cyber risks and incidents, while also setting out procedures and constraints. The U.S. Code addresses privacy, civil liberties, classified information, and national security, among other considerations. The Congressional Research Service’s April 2025 overview provides background on the provisions and possible implications, but predates both the lapse and later extensions.
Is CISA 2015 still in effect?
Yes. Congress later extended the relevant effective period. Section 2011 of Public Law 119-103 changed the date from September 30, 2026, to December 11, 2026. The provisions therefore are not currently lapsed as of October 8, 2026. That date is a statutory sunset, not a guarantee of another extension.
What oversight reports say about federal sharing systems
Agencies had formal sharing policies
GAO reported that in 2023 all seven federal agencies it reviewed had developed government-wide policies, procedures, and guidelines to help federal and nonfederal entities receive and share cybersecurity information. That finding concerns the existence of agency policies; it does not measure operational performance during the 2025 shutdown.
Automated Indicator Sharing was subject to a review recommendation
DHS’s Office of Inspector General recommended that CISA assess the costs and benefits of Automated Indicator Sharing (AIS) and whether to maintain its capabilities beyond the original September 30, 2025 expiration. The recommendation identifies a relevant automated channel, but the report does not establish the later final disposition of that recommendation or whether AIS experienced a shutdown-related interruption.
What the evidence establishes—and what it does not
- Established: CISA 2015 was due to sunset on September 30, 2025; the House Homeland Security Committee said the shutdown and lapse significantly constrained coordination and mission execution; and Congress later extended the relevant provisions through December 11, 2026.
- Not established: a percentage or count of lost or delayed exchanges, a channel-by-channel account of service interruptions, or a measured causal effect of the shutdown on sharing volume.
Understanding the disruption requires separating legal authority and protections from agency staffing and operational capacity, automated-channel availability, and the actual timeliness and breadth of information exchange. The cited oversight and statutory sources illuminate those dimensions, but do not provide comparable shutdown-period measurements for them.
Quick Recap
Best Value
Rank #4
Sources
- Public Law 119-103, section 2011 — establishes the December 11, 2026 date.
- 6 U.S.C. § 1504 — statutory sharing framework and constraints.
- GAO-25-108509 — CISA 2015 and federal agency policy implementation.
- House Committee on Homeland Security, October 31, 2025 — committee assessment of shutdown-era effects.
- DHS OIG-25-46 — AIS review recommendation.
- Congressional Research Service, IF12959 — background analysis published in April 2025.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

