Summary:
The Cybersecurity Information Sharing Act of 2015 is scheduled to expire September 30, 2026. Its framework provides important protections supporting voluntary cyber threat-information sharing between private organizations and government. This article examines the expiration as a governance and defensibility issue: organizations should understand what they share, under what authority, which legal protections apply, who owns the decision, and what must change if the statutory framework expires. Cyber threat sharing is an operational security capability, but the authority and evidence supporting it are governance responsibilities.
Nine days from now, an important piece of the legal infrastructure supporting cybersecurity information sharing in the United States is scheduled to expire.
The Cybersecurity Information Sharing Act of 2015—usually called CISA 2015—was designed to make it easier for private organizations and the federal government to share cyber threat information without creating unnecessary legal exposure.
Its protections currently expire on September 30, 2026.
That deadline deserves attention from cybersecurity leaders.
But it deserves even more attention from legal counsel, risk executives, CISOs, CIOs, and boards whose organizations participate in cyber threat-information-sharing arrangements.
Because the question is not simply whether threat intelligence will continue to flow.
The governance question is:
Does your organization know what legal authority and protections it relies upon when it shares cyber threat information—and what changes if those protections disappear?
What CISA 2015 Actually Does
Cybersecurity depends heavily on information sharing.
An organization discovers a malicious IP address.
Another identifies a phishing campaign.
A financial institution detects a new attack technique.
A critical-infrastructure operator discovers indicators associated with a nation-state actor.
Sharing that information can allow other organizations to defend themselves before they become victims.
But sharing information creates legal questions.
Can the information be shared without violating privacy obligations?
Could sharing create liability?
Could competitors exchanging cybersecurity information raise antitrust concerns?
Could information provided to the government become subject to disclosure laws?
Could sharing information waive legal privileges or other protections?
CISA 2015 created a statutory framework intended to reduce some of those barriers and encourage voluntary cyber threat-information sharing.
The Congressional Research Service has described protections under the law that include liability protection for certain authorized activities, antitrust protections for specified cybersecurity information sharing, protections against certain disclosure requirements, and requirements governing personally identifiable information.
The framework also supports sharing between private organizations and the federal government and among private-sector entities.
These protections helped create legal confidence around something cybersecurity professionals have long understood operationally:
No organization sees the entire threat landscape alone.
The Clock Has Run Before
This is not the first time CISA 2015 has approached expiration.
The original authorization was scheduled to expire on September 30, 2025.
Congress did not enact a permanent extension before that deadline, creating a temporary lapse. Short-term legislative extensions followed.
Congress ultimately amended the expiration date from September 30, 2025, to September 30, 2026.
That bought another year.
It did not permanently resolve the issue.
Unless Congress acts again, the statutory framework reaches another expiration point at the end of this month.
For organizations relying upon its protections, that creates a governance deadline—not merely a legislative one.
Cyber Threat Sharing Is Also a Risk Decision
Cybersecurity teams often think about threat intelligence operationally.
What indicators are useful?
Which feeds should we consume?
Which intelligence should we contribute?
Which ISAC or ISAO should we participate in?
How quickly can we distribute indicators internally?
Those are important questions.
But information sharing also exists within a legal and governance architecture.
Someone should know:
What We Share → With Whom → Under What Authority → What Protections Apply → Who Approves → What Evidence Is Retained
That chain matters because the technical ability to share information does not establish the legal authority to do so.
And a practice that was defensible under one statutory environment may need to be reconsidered when that environment changes.
September 30 Should Not Be the First Governance Meeting
Organizations should not wait until September 30 to determine whether the expiration affects them.
The appropriate response is not necessarily to stop sharing information.
Nor should organizations assume that every cyber-information-sharing activity becomes unlawful if CISA 2015 expires.
Other contractual, statutory, regulatory, common-law, or organizational authorities may apply depending upon the information being shared and the circumstances.
The governance requirement is more basic:
Know which protections you are relying upon.
If an organization’s threat-information-sharing program depends upon CISA 2015, leadership should understand what changes if the statute expires.
That analysis belongs before the deadline.
Not after it.
The Legal Architecture Behind Cyber Collaboration
Cybersecurity collaboration often looks simple from the security operations center.
A threat indicator is identified.
Someone shares it.
Another organization blocks it.
But underneath that exchange may sit an extensive legal architecture.
Privacy requirements.
Confidentiality obligations.
Contractual restrictions.
Data-handling requirements.
Antitrust considerations.
Government disclosure rules.
Liability concerns.
Sector-specific regulation.
Privilege questions.
CISA 2015 was intended, in part, to reduce friction created by those concerns.
Its potential expiration therefore provides a useful reminder:
Cyber collaboration depends upon governance infrastructure that security teams may never see.
When that infrastructure changes, operating procedures may need to change with it.
The Defensibility Question
Suppose an organization shares cyber threat information after September 30.
Months later, someone challenges that disclosure.
The important governance question will not simply be whether sharing the information was useful.
Leadership may need to demonstrate why the organization believed the disclosure was authorized and appropriate.
That requires evidence.
What information was shared?
Who received it?
Why was it shared?
What authority permitted the sharing?
What privacy review occurred?
What information was removed or minimized?
Which protections applied at the time?
Who approved the process?
Those questions illustrate why threat intelligence belongs inside a defensible governance model.
Good intentions are not evidence of appropriate authority.
Operational necessity is not automatically legal authorization.
And historical practice is not necessarily a sufficient basis for continuing an activity after the law changes.
Information Sharing Needs an Evidence Trail
Organizations should be able to demonstrate the governance surrounding significant information-sharing arrangements.
A useful evidence chain might look like this:
Threat Information → Classification → Sharing Authority → Privacy Review → Recipient → Disclosure → Retention → Evidence
The exact process will vary by organization and sector.
The principle should not.
Someone must know why the organization is permitted to share what it shares.
And that conclusion should be documented.
The Board Does Not Need to Approve Threat Indicators
This does not mean directors should become involved in operational threat-intelligence decisions.
A board should not be deciding whether the SOC shares a malicious IP address with an ISAC.
That would be governance theater.
But boards overseeing organizations materially dependent upon public-private cybersecurity collaboration should have reasonable assurance that management understands the legal environment governing those activities.
The board-level question is not:
What indicators did we share today?
It is:
Do we have a governed process for sharing cybersecurity information appropriately, and can management adapt that process when the governing legal framework changes?
That is a materially different question.
Questions Every Executive Should Ask Before September 30
- Does our organization currently rely upon CISA 2015 protections for any cybersecurity information-sharing activities?
- Which ISACs, ISAOs, government programs, vendors, partners, or industry groups receive cyber threat information from us?
- What categories of information do we share, and could any contain personal, confidential, privileged, regulated, or contractually restricted information?
- Which legal protections currently apply to each sharing arrangement?
- If CISA 2015 expires, which protections change or disappear?
- Do alternative legal authorities or contractual arrangements support continued sharing?
- Who has authority to modify, suspend, or continue information-sharing practices if the statutory environment changes?
- Can we produce evidence demonstrating why our information-sharing practices were considered appropriate?
Those questions should already have answers.
If they do not, nine days is enough time to begin asking them.
Governance Takeaway
CISA 2015 illustrates something easy to overlook in cybersecurity.
Technology does not operate independently of legal infrastructure.
Threat intelligence may move at machine speed.
The authority permitting organizations to exchange it does not.
When legislation changes, organizations need governance mechanisms capable of identifying what changed, determining which activities are affected, assigning decision authority, modifying controls, and preserving evidence explaining why those decisions were made.
That process can be expressed simply:
Legal Change → Applicability Assessment → Risk Analysis → Decision Authority → Control Change → Evidence
Whether Congress extends CISA 2015 again is a legislative question.
Whether your organization is prepared if it does not is a governance question.
The deadline is September 30.
Nine days remain.
The time to discover that your cybersecurity program depends upon a legal protection is before that protection disappears.


