CISA 2015 Expiration Looms: Imperiling Cyber Defense and Information Sharing Activities
Reauthorization efforts for the Cybersecurity Information Sharing Act of 2015 (CISA 2015) are underway as the law faces expiration at the end of September 2025. Negotiations between House and Senate leaders are critical to ensuring the continuation of the vital law, which has facilitated crucial cyber collaboration and defense efforts over the past decade. If CISA 2015 expires without replacement, organizations across the United States will face increased risk in conducting essential cyber hygiene, defensive work, and information sharing activities.
Key Takeaways:
- CISA 2015 is set to expire on September 30, 2025, after a 10-year sunset period, and reauthorization efforts are currently underway.
- The law has provided critical clarity on the lawfulness of information sharing, deployment of defensive measures, and network monitoring activities, leading to enhanced cyber collaboration and defense efforts.
- Without CISA 2015, organizations may lose liability protections, antitrust protections, and exemptions from FOIA and state disclosure laws, making them vulnerable to frivolous litigation over cybersecurity activities.
- Organizations may also face increased risks in sharing threat indicators, deploying defensive measures, and conducting network monitoring for cybersecurity purposes due to the potential for costly, time-consuming, and ongoing litigation.
- The House Committee on Homeland Security has unanimously approved the Widespread Information Management for the Welfare of Infrastructure and Government Act (WIMWIG), a proposed replacement for CISA 2015, and Congress is considering other proposals.
- House Homeland Security Chair Andrew Garbarino (R-NY) has introduced a draft to reauthorize CISA 2015 and make clarifying changes, which was voted out of Committee on September 3, 2025, on a 25-0 vote.
- A Senate Select Committee on Intelligence-approved 10-year reauthorization of CISA 2015 as part of its 2026 intelligence authorization bill is also being considered.
Statistics:
- CISA 2015 has been in effect for 10 years, providing clarity on lawfulness of information sharing, defensive measures, and network monitoring activities.
- Organizations across the United States may face a 26-day window to negotiate a replacement for CISA 2015.
- 100% of the House Committee on Homeland Security voted in favor of the WIMWIG proposal.
- Estimated financial losses for organizations facing frivolous litigation may be substantial, with some cases resulting in multi-million dollar settlements.
- In 2021, a federal appeals court ruled that a plaintiff did not suffer harm from alleged tracking on a website, but defendants in similar cases still face ongoing and costly litigation.
Sources:
- House Committee on Homeland Security, "Widespread Information Management for the Welfare of Infrastructure and Government Act (WIMWIG)"
- Senate Select Committee on Intelligence, "2026 Intelligence Authorization Bill"
- Mondaq, "CISA 2015 Expiration Looms: Imperiling Cyber Defense and Information Sharing Activities"
- Wiley Rein, "Cybersecurity Information Sharing Act of 2015 (CISA 2015)"