Skip to main content
CISA 2015 Just Got Extended Again. Here's What That Means for Your Threat Sharing ProgramLaws & Executive Orders
5 min readFor Compliance Officers

CISA 2015 Just Got Extended Again. Here's What That Means for Your Threat Sharing Program

Understanding the Current Situation

The Cybersecurity Information Sharing Act of 2015 (CISA 2015) has been extended once more. The House approved a continuing resolution that extends the law's liability protections through December 11. If you're managing a threat intelligence sharing program or coordinating breach disclosures with federal agencies, you're likely facing questions about what happens if this law expires without a permanent reauthorization.

These questions are pressing because the legal framework your organization relies on to share threat data with federal partners is operating on borrowed time.

What Does CISA 2015 Protect?

CISA 2015 provides liability protections to companies that voluntarily share cyber threat intelligence with federal agencies. It shields your organization from lawsuits and regulatory penalties when you share threat information that includes personal or proprietary data tied to individuals or companies affected by cyber intrusions.

Without these protections, your legal exposure increases every time you disclose breach indicators, malware samples, or attack patterns containing customer data, employee information, or business partner details. The law covers both civil litigation and regulatory enforcement actions that might otherwise arise from sharing this information.

This matters because useful threat intelligence often includes sensitive information. Reporting an active intrusion may involve email addresses, IP ranges, domain registrations, or transaction records that identify real people and companies. CISA 2015 allows you to share that context without risking privacy lawsuits or regulatory penalties under state data breach notification laws.

Can We Still Share Threat Intel if the Law Lapses?

Yes, but your legal risk profile changes significantly. You can still voluntarily disclose threat information to CISA, FBI, or NSA without statutory liability protections, but your legal team will need to evaluate each disclosure against state privacy laws, contractual obligations, and potential civil litigation exposure.

Currently, CISA 2015 provides a clear safe harbor. If the law expires, you're back to common-law defenses and case-by-case legal analysis. Your counsel will need to assess whether sharing specific indicators could trigger breach notification obligations, violate confidentiality agreements, or expose the organization to claims from affected parties.

The practical result: you'll share less, share slower, and share with more redactions. Federal cyber officials have stated publicly that losing this statutory authority would disrupt real-time threat intelligence sharing across public and private networks. Every disclosure becomes a legal review instead of an operational decision.

How Does CISA 2015 Affect DFARS 252.204-7012 Obligations?

CISA 2015 and DFARS 252.204-7012 serve different purposes, but they intersect when reporting incidents involving Controlled Unclassified Information. DFARS 252.204-7012 mandates a 72-hour reporting requirement when covered defense information is compromised. That's a contract obligation, not a voluntary disclosure.

CISA 2015 protections apply when you voluntarily share threat intelligence beyond what your contract requires. If you're providing additional context, sharing indicators from related incidents, or participating in information sharing and analysis organizations that feed data to federal partners, those voluntary disclosures benefit from the liability protections.

Practically, your DFARS incident report goes to DoD through the DoD Cyber Crime Center portal. If you're also sharing indicators with CISA's Automated Indicator Sharing program or participating in a sector-specific information sharing organization, CISA 2015 covers those additional disclosures. Without the law, you'd need to evaluate each voluntary disclosure separately from your mandatory DFARS reporting.

What Happens if Companies Stop Sharing?

Industry groups have warned that allowing CISA 2015 to lapse would create legal risks leading to a drop in private sector threat disclosures. The volume impact is hard to quantify because federal agencies don't publish real-time metrics on voluntary submissions versus mandatory reports, but the quality impact is easier to predict.

The most valuable threat intelligence comes with context: how the attacker moved laterally, which vulnerabilities they exploited, what data they targeted, how long they persisted. That context almost always includes information that could identify affected parties. When legal risk increases, organizations strip that context out or delay sharing until they've completed a full legal review.

You'll still get mandatory incident reports under sector-specific regulations. What you lose is the early warning network, the rapid sharing of novel techniques, and the detailed tradecraft analysis that helps defenders anticipate the next move. Federal cyber officials rely on this voluntary intelligence stream to issue timely alerts and update threat signatures across government networks.

Why Can't Congress Pass a Clean Reauthorization?

Senate Homeland Security and Governmental Affairs Committee Chair Rand Paul has routinely pushed back on clean extensions of the law, despite broad support from officials and industry. The political challenge isn't about whether threat sharing is valuable; it's about privacy concerns and oversight mechanisms.

Some lawmakers want to attach additional privacy protections, use restrictions, or transparency requirements before reauthorizing the liability protections. Others want to expand the law to cover emerging technologies or new threat vectors. These policy debates take time, and time runs out when you're operating on continuing resolutions that fund the government in 60-to-90-day increments.

For compliance officers, this creates planning uncertainty. You can't build a long-term threat intelligence strategy when the legal framework expires every few months. You can't negotiate information sharing agreements with sector partners when the liability protections might disappear mid-contract. The operational impact of legislative uncertainty compounds over time.

Preparing for a Potential Lapse

Document your current threat sharing practices and identify which disclosures are mandatory versus voluntary. Work with your legal team to assess your exposure if CISA 2015 protections expire. Consider whether your existing cyber insurance policies cover liability arising from voluntary threat intelligence sharing, because most standard policies don't.

Review your participation in information sharing and analysis organizations. Understand what data flows from your organization to federal partners through these channels. If the law lapses, you'll need to make rapid decisions about which sharing relationships to maintain and which to suspend pending legal review.

Finally, engage your industry associations. The strongest argument for permanent reauthorization comes from the private sector demonstrating the operational value of threat sharing. If your organization benefits from receiving federal threat intelligence, document those use cases and share them with your trade groups.

Where to Go for More

Monitor CISA's website for guidance on threat intelligence sharing procedures if the law's status changes. The Cyber AB and defense sector trade associations typically publish compliance guidance when legislative changes affect threat sharing obligations. Your legal team should track the continuing resolution timeline, because December 11 will arrive faster than Congress typically moves on permanent reauthorizations.

The liability protections in CISA 2015 aren't just legal niceties. They're the operational foundation that makes voluntary threat sharing viable at scale. When that foundation operates on 60-day extensions, your threat intelligence program operates on borrowed time.

You Might Also Like