This website uses cookies

Read our Privacy policy and Terms of use for more information.

Stopgap Extends Cyber Info-Sharing Law to December 11

Congress moved a short-term continuing resolution that funds federal agencies through 11 December 2026 and carries the sunset of the Cybersecurity Information Sharing Act of 2015 (CISA 2015) to the same date — averting a 30 September lapse of the protections behind voluntary cyber threat-sharing.

Why It Matters

CISA 2015 supplies the liability and antitrust protections that let companies voluntarily exchange cyber threat indicators with each other and with the federal government. Those protections briefly lapsed in late 2025, and industry warned that everyday sharing became legally riskier overnight. The continuing resolution keeps them alive — but only to 11 December, and only once the CR is signed at the 30 September funding boundary.

This is the latest in a run of short extensions rather than the durable reauthorization industry groups have pressed for, which remains stalled in the Senate. Treat 11 December as a hard checkpoint, not a resolution. It also lands in a crowded fortnight: five cyber and cloud deadlines fall within the next two weeks, led by a 30 September cluster.

Action Items

  1. Confirm the CR is signed — verify CISA 2015 protections stay continuous through 11 December, and watch for any brief gap at the 30 September boundary.

  2. Diarise 11 December as your next checkpoint, and document your reliance on CISA 2015 protections in existing threat-sharing agreements.

  3. Map the fortnight's deadlines — the 30 September FedRAMP OSCAL date and the 1–3 October NIS2 registrations are the tightest (see the calendar in the Deep Dive).

Get the full analysis. Pro subscribers receive the complete deep dive, all 5 action items, source documents, and jurisdiction-specific compliance checklists.

logo

Subscribe to Pro to read the rest.

Become a paying subscriber of Pro to get access to this post and other subscriber-only content.

Upgrade

A subscription gets you:

  • Deep dives of each updated regulation
  • Source verification documents
  • Extended jurisdiction-specific analysis
  • Compliance deadline tracker
  • Regulation crosswalk