The Law Protecting Your Threat Intel Sharing Now Expires December 11. That Is the Third Deadline in Twelve Months.
Resources/Blog

The Law Protecting Your Threat Intel Sharing Now Expires December 11. That Is the Third Deadline in Twelve Months.

The Law Protecting Your Threat Intel Sharing Now Expires December 11. That Is the Third Deadline in Twelve Months.
Compliance CISO
September 11 2026
8 min read

The Law Protecting Your Threat Intel Sharing Now Expires December 11. That Is the Third Deadline in Twelve Months.

The Law Protecting Your Threat Intel Sharing Now Expires December 11. That Is the Third Deadline in Twelve Months.

On September 2, 2026, the president signed H.R. 6500, the Continuing Appropriations and Extensions Act, 2027. Buried in it is a provision that moves the sunset of the Cybersecurity Information Sharing Act of 2015 from September 30, 2026 to December 11, 2026.

If you read anything in August about CISA 2015 expiring at the end of September, that reporting is now out of date. It was accurate when written.

That is the useful thing to notice here. This statute has moved three times in twelve months, and the U.S. Code itself has not caught up. If you look up 6 U.S.C. 1510 today, the prelim edition still shows September 30, 2026, because it is current only through August 3.

The sequence, because it explains the problem

CISA 2015 was enacted with a ten-year sunset that arrived on September 30, 2025.

Congress did not act, and the statute lapsed for roughly six weeks. A continuing resolution enacted November 12, 2025 extended it to January 30, 2026. It lapsed again briefly. The Consolidated Appropriations Act, 2026, signed February 3, 2026, extended it to September 30, 2026. The bill signed September 2 moved it to December 11, 2026.

Two lapses and three extensions inside a year. The current extension runs about fourteen weeks.

December 11 is also the date federal funding runs out under the same bill. Your threat-sharing protections and the appropriations calendar are now the same calendar, and that date falls about five weeks after the November midterms.

A longer fix exists on paper. S. 2983, introduced by Senators Peters and Rounds, would push the sunset to September 30, 2035. It has not moved. Reporting attributes the holdup to objections within Senate Homeland Security, though the current state of those negotiations is not something you should plan around.

What the statute actually gives you

Most people who say they rely on CISA 2015 cannot name what it does. That matters, because you cannot assess your exposure to a lapse without knowing which protections you are using.

CISA 2015 is voluntary. It applies to non-federal entities, defined broadly enough to cover essentially any private company. There is no sector limitation and no size threshold. A three-person fintech and a twenty-billion-dollar credit union stand in the same position.

When you share cyber threat indicators and defensive measures in accordance with the statute, the framework generally provides four things: an exemption from disclosure under FOIA and comparable state laws, protection from liability for the act of sharing, protection against waiver of privilege or trade secret status, and limits on regulators using what you shared against you.

That fourth one is why counsel cares. Without it, the calculation on volunteering indicators to a federal agency looks different.

What a lapse actually does, which is not what most coverage said

Last October, a great deal of commentary said the protections disappeared. The mechanics are more specific than that, and the specifics change what you should do.

The sunset provision, 6 U.S.C. 1510, has two subsections. Subsection (a) sets the end date. Subsection (b) is a savings clause providing that for any action authorized under the subchapter that occurred before the provisions cease to have effect, the subchapter continues in effect.

So sharing you did while the statute was live stays protected. That protection does not evaporate at the deadline.

The harder question is sharing done during a lapse, and CISA has taken a public position on it. Its guidance for non-federal entities, updated February 2026, states that indicators and defensive measures shared before September 30, 2026 are covered even if shared during the two lapse windows, which it identifies as October 1 to November 12, 2025 and January 31 to February 3, 2026.

Follow the reasoning, because it is the part that should shape your posture.

That protection does not come from the savings clause standing alone. It comes from Congress moving the subsection (a) date forward past the dates on which you shared, which retroactively pulls that sharing inside the effective period. The savings clause then holds it there.

During a lapse, you are not simply unprotected. You are making a bet, at the moment you share, that Congress will later extend the date past the day you shared. That bet has paid off twice. It is still a bet on a future act of Congress, and nobody can tell you the odds in advance. Treat a lapse as a decision point for counsel, not as a period where the answer is obviously no.

What to do before December 11

Find out which of your sharing channels actually depend on the statute. This is the step almost nobody does. Sharing that happens under an ISAC membership agreement, an NDA, or a vendor contract rests on contract terms, not on CISA 2015. Sharing indicators to a federal agency is where the statutory protections typically do the work. Sort your channels into those two buckets. The answer is usually more reassuring than people expect, and knowing it beats guessing during a shutdown week.

Get counsel's position in writing now, not in December. Ask one question: if the statute lapses, what does our practice change to, and for how long. Getting that answer while nothing is on fire produces a better answer.

Log your sharing with dates. If retroactive extension is the mechanism that protects lapse-period activity, then the date you shared is the fact that determines coverage. Most organizations do not record it in a way they could produce later. Start.

Do not build the December 11 date into anything durable. Three outcomes are plausible: another short extension, a long-term reauthorization, or a fourth lapse. Anything you write into a policy document should reference the statute and its current status, not a specific date that has moved three times already.

Check the source, not the summary. Given how fast this has moved and how much stale coverage is circulating, verify the current sunset date against congress.gov or CISA's own guidance pages before acting. The U.S. Code may lag by a month or more.

None of this argues for sharing less. The case for participating in sector threat sharing does not rest on this statute, and the operational value of an ISAC membership does not turn on an appropriations rider. It argues for knowing precisely what you would lose, so that a lapse produces a decision rather than a freeze.

Source note

This article is based on H.R. 6500, the Continuing Appropriations and Extensions Act, 2027, as passed and signed September 2, 2026; the text of 6 U.S.C. 1510 as published by the Office of the Law Revision Counsel; CISA's Guidance to Assist Non-Federal Entities to Share Cyber Threat Indicators and Defensive Measures with Federal Entities, February 2026 update; CISA's Privacy and Civil Liberties Final Guidelines, revised February 2026; S. 2983; and client alerts from Wiley, Covington, Hunton, and Davis Wright Tremaine on the 2025 and 2026 lapses.

This statute is under active consideration and its sunset date has changed three times in twelve months. Verify the current status before acting.

Disclaimer

This article is provided for general information and does not constitute legal advice. Regulatory requirements, compliance dates, examiner priorities, and enforcement posture change frequently. Verify current requirements against primary agency sources and your legal counsel before acting on anything described here.

Tags:

CISA 2015Threat Intel SharingCybersecurity Information SharingSunsetLegislative Risk

Prepare Your Threat Intel Sharing for a Potential Lapse

Compliance CISO brings Fortune 500 security expertise, including programs at Equifax, Capital One, and Visa, to fintech companies and credit unions building security and compliance programs. Schedule a free consultation at complianceciso.com/contact.

Recent Posts