Stopgap Extends Cyber Info-Sharing Law to December 11
Congress moved a short-term continuing resolution that funds federal agencies through 11 December 2026 and carries the sunset of the Cybersecurity Information Sharing Act of 2015 (CISA 2015) to the same date — averting a 30 September lapse of the protections behind voluntary cyber threat-sharing.
Why It Matters
CISA 2015 supplies the liability and antitrust protections that let companies voluntarily exchange cyber threat indicators with each other and with the federal government. Those protections briefly lapsed in late 2025, and industry warned that everyday sharing became legally riskier overnight. The continuing resolution keeps them alive — but only to 11 December, and only once the CR is signed at the 30 September funding boundary.
This is the latest in a run of short extensions rather than the durable reauthorization industry groups have pressed for, which remains stalled in the Senate. Treat 11 December as a hard checkpoint, not a resolution. It also lands in a crowded fortnight: five cyber and cloud deadlines fall within the next two weeks, led by a 30 September cluster.
Action Items
Confirm the CR is signed — verify CISA 2015 protections stay continuous through 11 December, and watch for any brief gap at the 30 September boundary.
Diarise 11 December as your next checkpoint, and document your reliance on CISA 2015 protections in existing threat-sharing agreements.
Map the fortnight's deadlines — the 30 September FedRAMP OSCAL date and the 1–3 October NIS2 registrations are the tightest (see the calendar in the Deep Dive).
Get the full analysis. Pro subscribers receive the complete deep dive, all 5 action items, source documents, and jurisdiction-specific compliance checklists.
Subscribe to Pro to read the rest.
Become a paying subscriber of Pro to get access to this post and other subscriber-only content.
UpgradeA subscription gets you:
- Deep dives of each updated regulation
- Source verification documents
- Extended jurisdiction-specific analysis
- Compliance deadline tracker
- Regulation crosswalk