Senate impasse leaves cybersecurity information-sharing law in limbo

Permanent authority for the Cybersecurity Information Sharing Act of 2015 expired more than a year ago, and a long-term renewal remains stalled in the Senate. Sen. Rand Paul is blocking the extension unless an amendment protecting speech is added, while Sen. Gary Peters says Paul is the obstacle. The program has continued only through short-term funding measures, leaving it vulnerable to lapses.
The 2015 statute shields firms from certain legal exposure, including antitrust claims, when they pass along cyber threat data to federal agencies or one another. Its permanent authorization ended with fiscal 2025, so Congress has kept it alive only through stopgap spending bills, making it susceptible to funding disputes.
Sen. Gary Peters has offered two bipartisan measures to extend it through fiscal 2035: one unchanged, another from the fall 2025 shutdown that would apply protections retroactively and rename the effort. The House Homeland Security Committee unanimously advanced a separate reauthorization with changes, but it has not reached the floor.
Companies that rely on sharing threat data may face legal uncertainty if authority lapses, potentially slowing voluntary reporting and leaving networks more exposed