Cybersecurity Information Sharing Act Expires Amid U.S. Government Shutdown
The Cybersecurity Information Sharing Act of 2015 expired on October 1 after Congress failed to reach a renewal agreement, increasing legal risks for threat intelligence sharing.
The Cybersecurity Information Sharing Act of 2015 expired on October 1, 2025, after the United States Congress failed to secure a renewal agreement. The law previously offered antitrust, privacy, and legal liability protections to government agencies and private companies that shared cyber threat intelligence. Its expiration coincides with a federal government shutdown, further complicating efforts to reauthorize the statute.
Senator Gary Peters had introduced the Cybersecurity Information Sharing Extension Act to provide a clean extension of the law through 2035. Despite broad bipartisan support, the measure failed due to objections and last-minute demands from Senator Rand Paul.
Industry groups, including the Bank Policy Institute and the Protecting America’s Cyber Networks Coalition, warned that the lapse leaves critical infrastructure more vulnerable. While the Financial Services Information Sharing and Analysis Center stated that data sharing may continue, other financial sector leaders privately cautioned that the increased legal risks could cause companies to halt the flow of information, creating new opportunities for threat actors.