Why It Matters A key cybersecurity law that enables federal agencies and private companies to share threat information is set to expire on December 11, forcing Congress to decide whether to renew, modify, or let the Cybersecurity Information Sharing Act of 2015 (CISA) lapse entirely.

The expiration would strip away explicit protections that shield private entities from antitrust liability, shield them from legal liability for monitoring and sharing cyber threat information, and exempt shared data from public disclosure requirements.

The Big Picture The Cybersecurity Information Sharing Act of 2015 was originally authorized for ten years and passed as Title I of the Cybersecurity Act of 2015, creating a legal framework for federal agencies and private companies to voluntarily exchange cyber threat indicators and defensive measures.

The law requires federal agencies to establish procedures for sharing classified and unclassified cyber threat information with federal and nonfederal entities, while mandating that personally identifiable information be stripped from all shared data and that the Departments of Homeland Security and Justice issue guidance on protecting civil liberties.

Lawmakers could also consider whether to require certain entities, such as critical infrastructure operators or cyber threat information aggregators, to participate in sharing rather than keeping it voluntary, fundamentally reshaping how the government receives warning of threats.