What Happened?
A federal cybersecurity law that lets government agencies and private companies quietly swap information about online threats will expire on Dec. 11 unless Congress acts. The Cybersecurity Information Sharing Act of 2015 (CISA) was originally authorized for 10 years and is now running out of time. The law created a legal framework for sharing what are called "cyber threat indicators." These are essentially technical signals that suggest a cyberattack is underway or has happened. It passed as part of a broader package in 2015.
Why Does it Matter to Me?
Right now, a company that spots a cyberattack and shares that information with the government is shielded from antitrust lawsuits, legal liability for the act of sharing, and public disclosure requirements. If CISA expires, those shields disappear. That matters because the companies covered include operators of critical infrastructure, the kind that keeps the power on, the water running, and the financial system moving. Less sharing between companies and federal agencies could mean slower warnings when large-scale attacks hit systems people rely on daily.
The main tool built under the law is the Automated Indicator Sharing program, a voluntary, real-time system that moves technical threat data between government and private networks automatically, machine-to-machine. Recent inspector general reviews found no violations of the law's privacy rules, which require that personal information be stripped from all shared data before it moves.
Both Sides, Now
Several industry groups have pushed for long-term renewal of the law as written. They argue that the existing framework works and that letting it lapse would remove legal certainty that encourages companies to participate.
Others see the expiration as a chance to update a decade-old statute. The law does not specifically address operational technology, the systems that connect physical infrastructure like industrial controls to networks, or artificial intelligence. Nation-state actors and cybercriminals have increasingly targeted both. Congress could extend the law as written, rewrite it to cover those gaps, or let it expire and leave companies relying on other legal authorities that may not offer the same protections.
Congress also enacted the Cyber Incident Reporting for Critical Infrastructure Act of 2022 to work alongside CISA, with one law handling ongoing threat intelligence and the other capturing data after attacks occur. The two are not substitutes for each other.
What Happens Next?
Congress must decide before Dec. 11 whether to renew, rewrite, or let CISA lapse. Lawmakers could also use the deadline to debate whether participation in threat-sharing should remain voluntary or become mandatory for certain entities, such as critical infrastructure operators. No vote is scheduled as of this report, and the window for action is narrowing.
Access the AllCiv platform for comprehensive political news, data, and insights.
---
Spot something wrong? Report an issue with this article