Stopgap funding bill temporarily extends key cyber info-sharing law

Finn Gomez/Getty Images

The short-term package pushes the sunset date for the bedrock cyber legislation to Dec. 11, in addition to setting extensions for the Technology Modernization Fund and National Cybersecurity Protection System.

The House approved a continuing resolution on Tuesday that funds federal agencies through Dec. 11 and extends key federal cybersecurity authorities and tech programs past their Sept. 30 expiration date, including the Cybersecurity Information Sharing Act of 2015.

The legislation, part of a broader package that President Donald Trump is expected to soon sign to avert a fiscal year 2027 government shutdown before the midterm elections, temporarily prevents the cyber information-sharing law from sunsetting at the end of the month when the federal budget resets.

That law provides liability protections to private sector companies that voluntarily share cyber threat intelligence with agencies like the NSA or the Cybersecurity and Infrastructure Security Agency. Efforts to secure a long-term reauthorization for the law have faced repeated delays over the past year despite broad support from officials and industry. Senate Homeland Security and Governmental Affairs Committee Chair Rand Paul Paul, R-Ky., has routinely pushed back on clean extensions of the law. 

The key liability protections in the CISA 2015 law are designed to shield firms from lawsuits and regulatory penalties when sharing threat information with the government. That data often includes personal or proprietary information tied to individuals and companies affected in cyber intrusions.

Industry groups have consistently warned lawmakers that allowing the Cybersecurity Information Sharing Act to lapse would create legal risks for companies sharing breach data, leading to a drop in private sector threat disclosures. Federal cyber officials have similarly stated that the loss of statutory authority would disrupt real-time threat intelligence sharing across public and private networks.

The spending measure extends several other federal IT and cyber authorities scheduled to expire on Sept. 30, including the Technology Modernization Fund, which provides capital for civilian agency IT upgrades. Around $5 million is authorized for the fund to continue approving and financing new agency tech modernization projects. Also extended is the Federal Cybersecurity Enhancement Act, which authorizes the National Cybersecurity Protection System for federal network intrusion detection.