Fisherphillips CISA 2015 Law Set to Expire Amid New Cyber Incident Reporting Requirements
Article Content
- •CISA 2015 is set to expire on September 30, 2026, affecting data sharing protections.
- •The CIRCIA law introduces new mandatory reporting requirements for critical infrastructure sectors.
- •Industry groups are pushing for the renewal of CISA to avoid gaps in cybersecurity collaboration.
The Cybersecurity Information Sharing Act (CISA) of 2015 is set to expire on September 30, 2026, with Congress yet to decide on its renewal. This law facilitates data sharing between the government and private sector, providing legal protections for companies that report cyber threats. A Congressional Research Service report warns that without CISA, private entities may hesitate to share vital threat information, potentially leading to a lack of comprehensive threat awareness. Concurrently, the Cyber Incident Reporting for Critical Infrastructure Act (CIRCIA) mandates new reporting obligations for tech companies, which will significantly impact compliance across the sector. CISA's expiration could hinder the effectiveness of CIRCIA's implementation, as both laws are intertwined in addressing cybersecurity challenges. The tech industry is advocating for a long-term renewal of CISA to maintain these protections.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (10)
Continue Reading
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…
Critical WSO2 API Manager Vulnerability Under Active Exploitation A critical vulnerability (CVE-2026-5430) in WSO2 API Manager is being actively exploited, allowing unauthenticated attackers to forge admin tokens via JWT authentication bypass. This flaw, which has a CVSS score of 10.0, affects multiple WSO2 products including API Manager, Universal Gateway, Traffic Manager, and API…