The Cybersecurity Information Sharing Act of 2015 (CISA), a cornerstone of U.S. public-private cybersecurity collaboration, is scheduled to expire on December 11, 2026. This law provides a legal framework and liability protections that encourage private sector organizations to share cyber threat indicators and defensive measures with the federal government and each other. As the deadline approaches, the U.S. Congress must decide on the future of the act. Industry stakeholders are pushing for a long-term renewal, arguing its expiration would weaken the nation's collective defense capabilities. The debate also includes potential amendments to address evolving threats from artificial intelligence and operational technology (OT) that were not prominent when the law was first enacted.
The Cybersecurity Information Sharing Act of 2015 was designed to break down barriers to information sharing. Its key provisions include:
The law affects virtually all private sector companies in the United States, as it provides the legal safe harbor for them to participate in threat intelligence sharing programs. It is particularly critical for organizations in Critical Infrastructure sectors, such as energy, finance, and healthcare, which are primary targets for sophisticated cyberattacks. U.S. federal agencies, especially CISA and others in the intelligence community, are also heavily affected as they rely on the data shared under this act to build a national-level picture of the threat landscape.
While sharing under the 2015 CISA law is voluntary, it sets the rules of engagement for those who participate. It complements the mandatory reporting required by the Cyber Incident Reporting for Critical Infrastructure Act of 2022 (CIRCIA), which compels certain organizations to report significant cyber incidents. CISA 2015 focuses on the proactive sharing of threat indicators (e.g., malicious IP addresses, malware signatures) before or during an attack, whereas CIRCIA focuses on reporting after an incident has occurred.
The key date is December 11, 2026, when the law's provisions are set to expire. Congress must pass legislation to renew the act before this date to prevent a lapse in its protections. Lawmakers are currently debating the length of the renewal and what, if any, amendments should be included.
If the law is not renewed, it could have a significant chilling effect on public-private threat intelligence sharing. Without liability protections, companies may become more hesitant to share information about threats they are seeing, fearing potential lawsuits or public disclosure of sensitive operational details. This would fragment the national view of the threat landscape, making it harder for the government to spot widespread campaigns and warn other potential victims. Industry groups argue this would be a major setback for U.S. cybersecurity. Conversely, privacy advocates may argue for stronger PII removal requirements if the law is renewed.
There are no penalties associated with not sharing information, as the program is voluntary. The law's primary function is to provide legal protection, not to compel action.
Organizations currently relying on the liability protections of CISA 2015 should:
The Cybersecurity Information Sharing Act (CISA) is signed into law.
The Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) is passed, complementing CISA 2015.
The Cybersecurity Information Sharing Act of 2015 is set to expire.

Cybersecurity professional with over 10 years of specialized experience in security operations, threat intelligence, incident response, and security automation. Expertise spans SOAR/XSOAR orchestration, threat intelligence platforms, SIEM/UEBA analytics, and building cyber fusion centers. Background includes technical enablement, solution architecture for enterprise and government clients, and implementing security automation workflows across IR, TIP, and SOC use cases.
CyberNetSec.io uses automation to assist source monitoring, deduplication, observable extraction, and structured intelligence generation. Published analysis follows human-defined editorial standards and adds defensive context including MITRE ATT&CK, D3FEND, STIX, and Sigma where applicable. Read our editorial policy.
Help others stay informed about cybersecurity threats
Every tactic, technique, and sub-technique used in this threat has been identified and mapped to the MITRE ATT&CK framework for consistent, actionable threat language.
Observables and indicators of compromise (IOCs) have been extracted and cataloged. Risk has been assessed and correlated with known threat actors and historical campaigns.
Detection rules, incident response steps, and D3FEND-aligned mitigation strategies are included so your team can act on this intelligence immediately.
Structured threat data is packaged as a STIX 2.1 bundle and can be visualized as an interactive graph — relationships between actors, malware, techniques, and indicators.
Sigma detection rules are derived from the threat techniques in this article and can be converted for deployment across any major SIEM or EDR platform.