Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The future of the Automated Indicator Sharing (AIS) program is uncertain, but its status is no longer tied to the September 30, 2025 expiration date anticipated in the original watchdog coverage. The Cybersecurity Information Sharing Act of 2015 expired on January 30, 2026, after a temporary extension. The available sources do not establish whether Congress later reauthorized it or whether the Cybersecurity and Infrastructure Security Agency (CISA) finalized a long-term plan for AIS.

What AIS shares—and why its continuation matters

AIS is a voluntary Department of Homeland Security program established after passage of the Cybersecurity Information Sharing Act of 2015. It exchanges automated, unclassified, machine-readable cyber threat indicators (CTIs) and defensive measures (DMs). A CTI can be a malicious IP address; a defensive measure is an activity intended to protect information systems from cyber threats. The program is designed to let participants share this information in a format that can be processed by systems rather than only read by people. CyberScoop’s report on the watchdog findings describes the program and its role.

The policy question is not simply whether AIS would switch off automatically when the statute expired. The Department of Homeland Security inspector general found that CISA had not finalized a plan for continued use of AIS if the law expired. The watchdog warned: “Without finalizing this plan, CISA could be hindered in how it shares information on cyber threats, which would reduce its ability to protect the Nation’s critical infrastructure from cyber threats.” That is a warning about a planning gap and potential operational consequences, not a finding that the program had already stopped.

What the watchdog reported about AIS participation and volume

Indicator volume rose, but contributions were concentrated

As reported by CyberScoop from the DHS Office of Inspector General’s 2025 report, AIS shared 10 million CTIs in 2024, up from 1 million in 2023. However, one unnamed private-sector partner contributed more than 4 million CTIs and DMs to each of the federal and public collections in 2024. Those contributions represented 83 percent of the federal collection and 89 percent of the public collection. The partner is not identified in the article, so its identity cannot be inferred from these figures. CyberScoop reported the statistics and the watchdog’s concern that dependence on a small number of contributors could make results inconsistent and constrain long-term growth if leading partners stopped participating.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
SecuX PUFido USB-C Security Key with PUF Technology, FIDO2/U2F Certified, Hardware-Rooted Unclonable Security for Passwordless Login and 2FA Authentication
  • A FIDO security key with PUF technology provides a unique, hardware-rooted trust anchor that resists tampering and cyber attacks, offering stronger security than conventional designs.
  • FIDO2 Certified Protection – Enjoy phishing-resistant security with FIDO2 certification, ensuring top-tier account safety across Windows, macOS, Linux, iOS iOS, Android and more.
  • Easy to use & Portable – Designed with a compact USB-C interface, Clife key fits easily on your keychain for secure access anywhere. Simply plug in and authenticate with ease.
  • Universal Compatibility – Works seamlessly with hundreds of FIDO2/U2F compliant services, including popular cloud, email, and social platforms.
  • Backup recommended – To ensure continuous access, register a backup Clife security key as a spare in case your primary key is lost.

Reported participant counts fell from their peak

The same reporting puts AIS participation in 2024 at 18 federal and 87 non-federal participants, compared with a peak of 304 total participants in 2020. These counts do not directly measure how many organizations are represented: some non-federal participants are sector-specific information sharing and analysis centers (ISACs), which may include hundreds of organizations.

Operational cost

The watchdog report put AIS’s average operational cost at $1 million per month, as reported by CyberScoop. That figure describes the program’s reported average operating cost; it does not by itself establish what funding would remain available after the statute’s expiration or how CISA would allocate resources.

Rank #2
SecuX PUFido® Drive Clife Key USB C Security Key with PUF Technology and Built in Flash Drive, FIDO2 U2F Certified Hardware Rooted Unclonable Security for Passwordless Login and 2FA Authentication (1)
  • Hardware-Rooted Security with PUF Technology – PUFido Drive Clife Key uses Physical Unclonable Function technology to generate a unique, hardware-based identity that cannot be duplicated, delivering stronger resistance against tampering and cyber attacks than conventional security keys.
  • FIDO2 Certified Phishing-Resistant Protection – Fully compliant with FIDO2/U2F standards, enabling secure passwordless login and two-factor authentication to help protect accounts from phishing and credential theft.
  • Security Key + Flash Drive in One Device – Combines a FIDO security key with a built-in USB flash drive, allowing you to carry files and a hardware authentication key together in a single compact device.
  • Easy to Use & Portable – Compact USB-C design fits easily on a keychain or in a pocket. Simply plug in the Drive Clife Key to authenticate or access stored files with no extra software required.
  • Universal Compatibility – Works with hundreds of FIDO2/U2F compatible services and supports Windows, macOS, Linux, iOS, Android, and other major platforms.

What CISA said about keeping AIS operating

In a response quoted by CyberScoop, Madhu Gottumukkala, then acting director of the Cybersecurity and Infrastructure Security Agency, said: “It is important for readers of this report to understand that automated threat intelligence and information sharing with our global partners and stakeholders remains a priority for CISA, and that there are no immediate or near-term plans to discontinue the Automated Information Sharing [sic] service, regardless of the status of the Cybersecurity Act of 2015.” The bracketed “[sic]” reflects the wording in the quoted response; AIS is the Automated Indicator Sharing program.

Gottumukkala also wrote: “Subject to available appropriations, CISA remains authorized to operate Automated Information Sharing irrespective of the possible sunset of the Cybersecurity Information Sharing Act of 2015 on September 30, 2025, and CISA will continue to modernize and evolve Automated Information Sharing to meet the needs of its partners and stakeholders.” This is CISA’s stated position in its response, not an independent legal determination. The response expressed near-term commitment while making continued operations subject to available appropriations.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Separately, CISA officials told the watchdog that if the law expired, the agency would assess AIS’s value, likely lower CTI and DM volume, available resources, and leadership priorities before deciding whether resources could be redirected. The agency’s near-term statement and this conditional decision process are not the same as a finalized long-term operating plan. CyberScoop’s account reports both the response and the officials’ explanation.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How the expiration date changed—and what is known now

The original coverage anticipated that the Cybersecurity Information Sharing Act of 2015 would expire on September 30, 2025. A January 22, 2026 Congressional Record text proposed replacing that sunset date with September 30, 2026. The Congressional Research Service’s February 3, 2026 update says the law, as amended by P.L. 119-37, expired on January 30, 2026. The sequence matters: September 30, 2025 was the expected date in the earlier coverage, not the final expiration date. The January 22 Congressional Record text and the CRS update document the later timeline.

Rank #4
Thetis Pro FIDO2 Security Key Passkey with Complex Pin [PinPlex], Hardware Device Supports USB A, Type C &NFC, TOTP/HOTP Authenticator APP, PIV Certificates, FIDO 2.0 Two Factor Authentication 2FA MFA
  • Dual USB-A and USB-C Security Key – Features both USB-A and USB-C connectors for seamless compatibility across desktops, laptops, and tablets. Supports plug-and-stay use or keychain carry.
  • NFC-Enabled for Mobile Access – Built-in NFC allows fast, wireless authentication with Android and iPhone devices. Ideal for mobile logins and on-the-go security.
  • FIDO Certified for Strong Authentication – [CHECK COMPATIBILITY before purchase] Fully compliant with FIDO2 and FIDO U2F standards. Works with major platforms like Google, Microsoft, GitHub, and Dropbox.
  • Passwordless Login with PinPlex – Supports secure passkey login via WebAuthn and CTAP2 with added protection from PinPlex, a complex PIN system that enhances physical security.
  • Multi-Layer Authentication Support – Includes PIV certificates and supports both TOTP and HOTP for strong 2FA/MFA coverage across enterprise and consumer apps.

The available sources establish the law’s January 30, 2026 expiration, but do not establish a subsequent reauthorization or a later CISA decision about AIS’s long-term operation. They therefore do not support a definitive claim that AIS has been discontinued, or that a durable continuation plan is now in place.

What the figures do—and do not—show

The reported rise in CTI volume is one measure of activity, but it sits alongside substantial concentration in a single unnamed partner’s contributions. The participant counts add another dimension, though ISAC participation means a participant is not necessarily one organization. Together, the measures describe activity, breadth, and dependence; they do not quantify AIS’s effectiveness against another platform or prove how much protection the program provides to critical infrastructure.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For readers assessing the program’s outlook, the central distinction is between CISA’s stated intention to continue AIS in the near term and the unresolved questions of statutory status, appropriations, contributor resilience, and a finalized long-term plan.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.