Skip to content
    Back to Regulatory Radar
    ImportantDeadlineSeptember 30, 2026

    Cybersecurity Information Sharing Act of 2015 Liability Protections Sunset Again on September 30, 2026

    The Cybersecurity Information Sharing Act of 2015 is scheduled to lapse on September 30, 2026. The statute was enacted with a ten-year sunset that ran out on September 30, 2025; Congress then passed a series of short-term extensions before reauthorizing it through September 30, 2026 in the spending bill signed on February 3, 2026. While in force it gives organizations that share qualifying cyber threat indicators and defensive measures a set of legal protections: exemption from Freedom of Information Act disclosure, limits on liability arising from the sharing itself, and protection against waiver of legal privilege.

    CISA 2015NIST CSFCIRCIASaaSHealthcareFinTechDefense

    Key Analytics

    September 30, 2026
    Event Date
    Time Remaining
    August 14, 2026
    Last Verified
    3
    Frameworks Affected

    Impact Analysis

    This is a legal-exposure question rather than a technical one, and it is easy to miss because nothing about your security stack changes on the day it lapses. Threat intelligence sharing through ISACs, sector partnerships, and informal peer groups has operated for a decade against the assumption that participation is shielded. If the protections expire, the analysis of whether to share a given indicator shifts from routine to something counsel may want to see, particularly where an indicator contains anything that could be read as customer data. Organizations that already went through the brief lapse between September 2025 and the first extension will recognize the pattern; those that did not should note that this is now the second sunset in twelve months and plan for the possibility of a third rather than treating reauthorization as automatic.

    Recommended Actions

    • Identify every channel through which your organization currently shares threat indicators, including ISAC membership, sector working groups, and vendor threat exchanges
    • Ask counsel what your sharing posture should be if the protections lapse, and agree that position before September 30 rather than during an incident
    • Review whether shared indicators are scrubbed of personal information, since the FOIA and liability protections are conditioned on sharing that complies with the statute's requirements
    • Track reauthorization activity rather than assuming renewal; this is the second sunset in twelve months and the previous one produced an actual gap in coverage
    • Document the date and legal basis of past sharing, because protections attach to sharing that occurred while the statute was in force

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Modeled estimate
    Moderate50-130 hours
    Key Workstreams
    • Gap assessment against current controls
    • Readiness assessment
    • Remediation sprint to date
    • Attestation or filing preparation

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowModerate · 50-130 hours
    Start cold under pressureSignificant · 100-340 hours

    Roughly 50 to 210 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events