Cybersecurity Policy Report, Bipartisan Senate Bill Would Reauthorize Expiring Cyber Threat Info-Sharing Law, (Apr 16, 2025)

An expiring cyber threat information-sharing law would be reauthorized until 2035 under legislation introduced by Sens. Gary Peters (D., Mich.), ranking member of the Senate Homeland Security and Governmental Affairs Committee, and Mike Rounds (R., S.D.), chairman of the Senate Armed Services Committee’s cybersecurity subcommittee.
The Cybersecurity Information Sharing Extension Act (S.B. 1337, 119th Cong. (2025)) would reauthorize the Cybersecurity Information Sharing Act of 2015 for another 10 years.
The 2015 law was a consequential act by Congress that established the first formal cyber threat information-sharing regime in the federal government. It sought to encourage the private sector to voluntarily share information about cybersecurity vulnerabilities and attacks with the federal government by establishing a secure portal at the Department of Homeland Security and immunizing private-sector entities from legal liability that might stem from their information-sharing activities.
But the law expires on Sept. 30, and Sens. Peters and Rounds said its reauthorization was vital.
“As cybersecurity threats grow increasingly sophisticated, information sharing is not just valuable—it remains essential for our national security,” Sen. Peters said in a news release.
“For the past ten years, these critical protections have helped to address rapidly evolving cybersecurity threats, and this bipartisan bill will renew them so we can continue this collaborative partnership between the private sector and government to bolster our nation’s cybersecurity defenses against a wide range of adversaries,” he said.
“The Cybersecurity Information Sharing Act of 2015 has been instrumental in strengthening our nation’s cyber defenses by enabling critical information sharing between the private sector and government,” Sen. Rounds said. “Allowing this legislation to lapse would significantly weaken our cybersecurity ecosystem, removing vital liability protections and hampering defensive operations across both the defense industrial base and critical infrastructure sectors.”
MainStory: TopStory FederalLegislation DataSecurity