The U.S. House of Representatives has passed an annual defense policy bill that includes a provision to extend a key cybersecurity information-sharing law for another decade. The 2027 National Defense Authorization Act (NDAA), approved by a vote of 216-212, contains language that would reauthorize the 2015 Cybersecurity and Information Sharing Act (CISA 2015) until 2035.
CISA 2015 provides legal protections for the private sector and federal government to exchange data concerning criminal and nation-state hacking threats. The statute had briefly lapsed last year, which federal officials indicated left them without a full understanding of digital threats to critical U.S. infrastructure. It was subsequently extended temporarily through September 30 of the current year.
The House's reauthorization effort is formally known as the Widespread Information Management for the Welfare of Infrastructure and Government Act (WIMWIG Act). This act was previously approved by the House Homeland Security Committee but has not yet received a floor vote and faces opposition in the Senate.
A significant hurdle to reauthorization comes from Senator Rand Paul (R-KY), who chairs the Senate Homeland Security Committee. Senator Paul has publicly stated his intention to block any extension of CISA 2015 unless it includes language prohibiting the Cybersecurity and Infrastructure Security Agency (CISA, the agency created in 2018) from engaging in work to counter online disinformation. It is noted that CISA 2015 and CISA the agency are not directly linked by law.
The Senate's draft of the NDAA does not currently include a matching extension for CISA 2015, although it is anticipated that the issue may arise during the amendment process. Furthermore, the Senate's consideration of the NDAA has encountered resistance from Democrats, who have been engaged in a prolonged dispute regarding presidential authority on Iran.
Should the CISA 2015 extension ultimately be included in both chambers' versions, it would still require successful negotiation and agreement between the House and Senate to be incorporated into a final compromise bill. In a separate legislative effort in May, a bipartisan group of House members also introduced a proposal on artificial intelligence that contained a similar provision to reauthorize CISA 2015 through 2035, though this package has not gained significant momentum.
Beyond the CISA 2015 extension, the House's NDAA also differs from the Senate's version on Pentagon cyber roles. The House bill calls for a "review and realignment" of all Pentagon cyber positions. In contrast, the Senate's draft proposes merging the Pentagon's two primary cyber leadership roles into a single post, creating a new "undersecretary of Defense for cyber, information, and networks." This new role would serve as both the department's chief information officer and the principal cyber adviser to the secretary of Defense, an initiative intended to address existing tensions between the CIO and the assistant secretary of defense for cyber policy regarding responsibility for digital operations, particularly offensive measures. This Senate provision, if enacted, would take effect in two years.






