Extension of CISA 2015 info-sharing protections passes as part of House’s defense bill
The House passed an annual defense policy bill on Wednesday that would renew a landmark cybersecurity info-sharing law for another decade.
A provision to extend the 2015 Cybersecurity and Information Sharing Act was included in the chamber’s version of the 2027 National Defense Authorization Act, which was approved 216-212.
Only a handful of Democrats supported the $1.15 trillion Pentagon policy roadmap that placed no curbs on President Donald Trump's use of U.S. military forces, most notably the Iran war.
The Widespread Information Management for the Welfare of Infrastructure and Government Act would reauthorize CISA 2015, which provides legal protections that allow the private sector and federal government to swap data on criminal and nation-state hacking threats.
The statute briefly expired last year, leaving federal officials in the dark about the full scope of digital threats to U.S. critical infrastructure. It was later temporarily extended through Sept. 30.
The WIMWIG Act was approved by the House Homeland Security Committee last year but has not received a floor vote and faces opposition in the Senate.
Sen. Rand Paul (R-KY), who chairs the Homeland Security Committee, has vowed to block any reauthorization of CISA 2015 unless language is included that would prohibit the Cybersecurity and Infrastructure Security Agency from engaging in any work to counter online disinformation — even though law and the agency are not directly linked. CISA the agency was created in 2018.
In addition, the Senate’s draft of the NDAA does not include a matching extension, though it is expected to come up on the floor as policymakers work through their amendment process. However, the bill has hit a roadblock with Democrats, who earlier this month tanked consideration of the legislation in their months-long fight to rein in Trump on Iran.
If ultimately included, a renewal would still have to survive negotiations between the two chambers before it could be approved in a final compromise bill.
In May, a group of bipartisan House members also unveiled a legislative proposal on AI that included a similar provision to reauthorize CISA 2015 through 2035, though the package has gained little traction.
Pentagon cyber roles
Another notable difference with the Senate is that the House’s version of the NDAA does not include a provision that would merge the Pentagon’s two major cyber roles into a single leadership post.
The Senate’s draft would create a new “undersecretary of Defense for cyber, information, and networks” to serve as the department’s chief information officer and as the principal cyber adviser to the secretary of Defense.
The provision, which would take effect in two years, is an attempt by lawmakers to get ahead of rising tensions between the CIO and the assistant secretary of defense for cyber policy over who is ultimately responsible for digital operations, especially offensive measures.
The House-passed bill also calls for a “review and realignment” of all Pentagon cyber roles.
Martin Matishak
is the senior cybersecurity reporter for The Record. Prior to joining Recorded Future News in 2021, he spent more than five years at Politico, where he covered digital and national security developments across Capitol Hill, the Pentagon and the U.S. intelligence community. He previously was a reporter at The Hill, National Journal Group and Inside Washington Publishers.



