Skip to main content
AdvisoryBy Jason LeeAugust 27, 20268 min read

CISA 2015 Expires September 30: What It Means for Threat Intel Sharing

CISA 2015 Expires September 30: What It Means for Threat Intel Sharing

The direct answer: the Cybersecurity Information Sharing Act of 2015 is in effect today, but it expires again on September 30, 2026, about a month from now. Its liability protections already lapsed once, for roughly six weeks after the original September 30, 2025 sunset. Congress restored them temporarily on November 12, 2025, then extended them through September 30, 2026 in the spending bill signed February 3, 2026. Whether the protections survive past September 30 depends on Congress acting again, and as of today no long-term reauthorization has passed. If your company shares or consumes threat intelligence through an ISAC, an MSSP, or CISA's Automated Indicator Sharing program, this deadline is yours, not just Washington's.

Status verified August 27, 2026. This page is updated when the regulatory status changes.

What CISA 2015 actually does

The Cybersecurity Information Sharing Act of 2015 is the legal foundation under most private-sector threat intelligence sharing in the United States. Its core function is a liability shield: companies that share cyber threat indicators with each other or with the federal government under the Act's framework receive express legal protection for doing so. That shield is what lets a hospital push an indicator of compromise to H-ISAC, a bank contribute to FS-ISAC, or a utility feed E-ISAC without each disclosure becoming a bespoke legal review. A Congressional Research Service summary of the Act and its sunset is available at congress.gov.

The shield is easy to take for granted because it works invisibly. Nobody notices it until it is gone, which is exactly what happened in the fall of 2025.

The timeline: lapse, renewal, extension, and the next cliff

Date What happened Status of the liability shield
September 30, 2025Original sunset date passed without reauthorizationLapsed
October to mid-November 2025Roughly six weeks with no statutory protectionLapsed
November 12, 2025Temporary renewal signed, running through January 30, 2026Restored
February 3, 2026Spending bill signed extending the Act through September 30, 2026In force
September 30, 2026Next expiration unless Congress actsUnknown

Law firm coverage of the February extension is consistent on these dates; see the analyses from Hunton and Davis Wright Tremaine. Industry groups are lobbying for a long-term reauthorization rather than another short extension, but as of August 27, 2026 nothing has passed. Honest assessment: we do not know whether Congress will act before September 30. The one thing the past year proves is that a lapse is not a theoretical risk. It has already happened once.

Three acronyms, three different things

Part of the confusion around this deadline, including in AI search results, is that three separate things get conflated under one acronym. If you ask an AI engine whether "CISA expires," you can get an answer about the wrong one. The distinctions:

CISA the law is the Cybersecurity Information Sharing Act of 2015. It is the liability shield for threat intelligence sharing, and it is the thing that expires September 30, 2026.

CISA the agency is the Cybersecurity and Infrastructure Security Agency, the DHS component created in 2018. The agency does not expire. It operates programs, including the Automated Indicator Sharing (AIS) program, whose participants rely on the 2015 law's protections. The law lapsing does not shut the agency down, but it removes the statutory shield under one of the agency's flagship sharing programs.

CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act of 2022, a different law entirely. It will require covered entities to report substantial cyber incidents to CISA within 72 hours and ransomware payments within 24 hours, once its final rule publishes. That rule is currently targeted for September 2026, which means both stories may break in the same month. We track that rulemaking separately in our CIRCIA final rule status page. CISA 2015 is about voluntary sharing with protection; CIRCIA is about mandatory reporting with deadlines. Renewing one does nothing for the other.

Who actually depends on this law

ISAC and ISAO members. If your company participates in a sector sharing body, such as H-ISAC for healthcare, FS-ISAC for financial services, E-ISAC for electric utilities, or WaterISAC for water systems, the 2015 Act is the statutory backdrop for what you contribute. The sharing communities themselves keep operating during a lapse, but each member's contribution shifts from statutorily protected to contractually and common-law governed. For OT-heavy sectors, where E-ISAC and WaterISAC feeds inform defense of control systems, the stakes of degraded sharing are physical, not just informational. Our primer on OT security covers why those environments depend on early, specific indicators.

MSSP and MDR customers. Managed detection providers pool telemetry and indicators across their customer base. That pooling is a sharing activity, and the Act's protections are part of the legal architecture behind it. If you outsource detection, this is a vendor question worth asking directly: what is your provider's position on sharing during a lapse, and does your contract address it? This is standard third-party diligence, the same discipline we describe in our guide to third-party risk management: know which legal assumptions your vendors are operating on, and what changes when one of them falls away.

CISA AIS participants. Companies connected to the agency's Automated Indicator Sharing program are sharing with the federal government under the framework the 2015 law created. A lapse puts that participation into the least-charted legal territory of the three groups.

The common thread: large enterprises have counsel who can re-derive a sharing position from contracts and existing privacy law within days. Mid-market companies mostly do not. During the 2025 lapse, the uncertainty landed hardest on firms that consume and contribute intelligence without a legal team on standby to tell them whether to keep doing it.

Not sure which of your intel feeds depend on this law?

A Z Cyber advisor can review your ISAC memberships, MSSP contracts, and sharing arrangements and brief you on what changes if the shield lapses, so the decision stays yours and informed.

Talk to an Advisor →

What to do in the next month

Inventory your sharing arrangements. List every channel where your company shares or receives threat intelligence: ISAC memberships, MSSP and MDR contracts, AIS participation, informal peer exchanges. Most companies have never written this list down, and it is the prerequisite for every other step.

Ask your providers the lapse question now. Your MSSP, MDR provider, and ISAC each have a position on what changes if the protections expire. Get it in writing before September 30, not during the scramble after.

Decide your own posture in advance. The practical lesson of the 2025 lapse is that sharing largely continued, but each organization had to make its own call under uncertainty. Make that call now, calmly, with whatever counsel you have access to, rather than in the first week of October. For most mid-market firms the reasonable default is to keep consuming intelligence, which carries little sharing risk, and to take a deliberate, documented position on what you contribute.

Do not confuse this deadline with CIRCIA. If your incident response planning has a reporting workstream, that is CIRCIA preparation and it continues regardless of what happens to CISA 2015. The two deadlines landing in the same month is a coincidence of the calendar, not a connection in the law.

What to watch next

September 30, 2026: CISA 2015's current extension expires. The possible outcomes are a long-term reauthorization, another short extension attached to a spending vehicle, or a second lapse. The February 2026 extension arrived through a spending bill, so end-of-fiscal-year budget negotiations are the most likely vehicle again.

September 2026: the CIRCIA final rule is currently targeted for publication in the same window, per the July 2026 Unified Agenda preview. That date has slipped three times before, so treat it as a target rather than a promise. Track it on our CIRCIA status page.

After any renewal: check whether Congress passed a multi-year reauthorization or another stopgap. A stopgap means this page gets another row in the table, and your sharing arrangements stay on a short leash. We will update this page when the status changes. If you want the implications for your specific feeds and contracts walked through before the deadline, talk to a Z Cyber advisor.

Frequently Asked Questions

Is the Cybersecurity Information Sharing Act of 2015 still in effect?

Yes, but only through September 30, 2026. The law's liability protections originally sunset on September 30, 2025 and lapsed for roughly six weeks. Congress temporarily renewed them on November 12, 2025 through January 30, 2026, then extended them through September 30, 2026 in the spending bill signed February 3, 2026. Unless Congress acts again, the protections expire on that date. Industry groups are lobbying for a long-term reauthorization, but no long-term bill had passed as of late August 2026.

What happens to threat intelligence sharing if CISA 2015 lapses?

The underlying sharing channels do not switch off, but the federal liability shield for sharing cyber threat indicators goes away. Companies that share through ISACs, ISAOs, or CISA's Automated Indicator Sharing program would be sharing without the Act's express legal protection, which pushes the risk analysis back onto contracts, existing privacy law, and each company's own counsel. During the roughly six-week lapse in late 2025, that uncertainty fell hardest on mid-market firms that rely on the shield without in-house counsel to assess sharing risk.

What is the difference between CISA 2015, the CISA agency, and CIRCIA?

Three different things share the acronym. CISA 2015 is the Cybersecurity Information Sharing Act, a 2015 law that gives companies liability protection for sharing cyber threat indicators. CISA the agency is the Cybersecurity and Infrastructure Security Agency, part of DHS, created in 2018. CIRCIA is the Cyber Incident Reporting for Critical Infrastructure Act of 2022, a separate law that will require 72-hour incident reporting once its final rule publishes. The expiration deadline of September 30, 2026 applies only to CISA 2015, the information sharing law.

Who is affected if CISA 2015 expires?

Anyone who shares or consumes cyber threat intelligence under the Act's liability shield. That includes members of sector ISACs and ISAOs such as H-ISAC, FS-ISAC, E-ISAC, and WaterISAC, customers of MSSP and MDR providers whose services depend on pooled threat intelligence, and participants in CISA's Automated Indicator Sharing program. Mid-market companies are the most exposed group because they typically rely on these feeds without dedicated counsel to evaluate sharing risk during a lapse.

Has CISA 2015 already expired before?

Yes. The law's protections sunset on September 30, 2025 and lapsed for approximately six weeks while Congress negotiated. A temporary renewal signed November 12, 2025 restored the protections through January 30, 2026, and the spending bill signed February 3, 2026 extended them through September 30, 2026. That history matters: the next deadline is not hypothetical, because a lapse has already happened once within the past year.

Subscribe for Updates

Get cybersecurity insights delivered to your inbox.