Congress quietly extends cybersecurity data-sharing law for a decade
S. 2983 — Extending Expired Cybersecurity Authorities Act · Filed by Gary Peters (D-MI) · 15 cosponsors · Introduced Oct 7, 2025
Your members of Congress
Enter a ZIP to see where your representative and both senators stood on this bill.
Looked up on this device — your ZIP is never stored on our servers.
What it does
This bill extends the Cybersecurity Information Sharing Act of 2015 (CISA) by ten years, moving its expiration date from September 30, 2025 to September 30, 2035. It also retroactively applies this extension to October 1, 2025, and renames the law the 'Protecting America from Cyber Threats Act.' The extension allows the federal government and private companies to continue sharing cybersecurity threat information under the existing legal framework.
Why we flagged it
The bill's sole operative function is a ten-year reauthorization of an existing cybersecurity information-sharing regime. It is a routine extension of expiring statutory authority, not a new policy or structural change.
What the text implies
- Retroactive effective date (Oct 1, 2025) means the law was technically expired for one day; retroactive application erases that gap and validates any information-sharing that occurred during that window without new statutory authority.
- Renaming from 'Cybersecurity Information Sharing Act' to 'Protecting America from Cyber Threats Act' is cosmetic but may signal a shift in framing—from information-sharing as the mechanism to threat-protection as the stated purpose, potentially broadening justifications for data collection.
The full analysis lists 3 implications of this text.
Who stands to gain
Technology and telecommunications companies (continued liability protection for data-sharing); Cybersecurity service providers (continued market for threat-intelligence products)