Multi-Association CISA 2015 CR Letter
July 17, 2026
The Honorable Mike Johnson Speaker United States House of Representatives Washington, DC 20515
The Honorable Hakeem Jeffries Democratic Leader United States House of Representatives Washington, DC 20515
Dear Speaker Johnson and Leader Jeffries,
We, the undersigned trade associations, write to request the inclusion of an extension of the Cybersecurity Information Sharing Act of 2015 (CISA 2015) in the upcoming continuing resolution. Unless Congress acts, CISA 2015 authority will expire on September 30, making the situation urgent.
Over the past decade, CISA 2015 has become a foundational component of the nation’s cybersecurity. The law enables the voluntary sharing of cyber threat indicators and defensive measures between private entities and with the federal government, while providing the liability protections and legal certainty needed to encourage such sharing. These authorities support the timely exchange of actionable threat intelligence and have become central to the collective defense of public and private sector networks, particularly across critical infrastructure sectors.
Today’s advanced AI systems can identify and exploit software vulnerabilities faster than ever before, shrinking the time between discovering a weakness and using it in an attack. AI tools are also making sophisticated cyber capabilities cheaper, faster, and easier to use, allowing threats to spread and adapt in real time.
A long-term reauthorization of CISA 2015 remains critical, and we continue to urge Congress to make that a priority. In the interim, any interruption to these protections would greatly threaten the nation’s ability to respond to cyber threats if companies were forced to pause or reassess information-sharing relationships.
A lapse now would be especially ill-timed—undermining not just longstanding information-sharing practices but also the GOLD EAGLE Initiative, a new clearinghouse that pairs industry and critical infrastructure operators with government agencies to rapidly detect and patch vulnerabilities. The Administration has made clear that GOLD EAGLE depends on the protections CISA 2015 provides, and that the program is fundamentally at risk if CISA 2015 is not extended.
We appreciate your leadership on this important issue and urge extending these critical cybersecurity protections as part of upcoming legislative activity.
Sincerely,
Aerospace Industries Association Alliance for Automotive Innovation American Fintech Council American Hotel and Lodging Association American Petroleum Institute American Public Power Association Bank Policy Institute Business Roundtable Business Software Alliance Cybersecurity Coalition Edison Electric Institute Electronic Transactions Association Healthcare Leadership Council Information Technology Industry Council Institute of International Bankers National Retail Federation National Rural Electric Cooperative Association NCTA — The Internet & Television Association Operational Technology Cybersecurity Coalition SIFMA TechNet U.S. Chamber of Commerce USTelecom — The Broadband Association
Cc: Senate Majority Leader John Thune Senate Democratic Leader Chuck Schumer Office of the National Cyber Director Department of the Treasury Department of War Department of Homeland Security