RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Policy & law

Policy & law / From the archive · 30 September 2025 event · prepared 16 September 2026

A 2015 information-sharing law's liability shield briefly lapsed

The U.S. Code's own amendment history shows the 2015 information-sharing law's liability shield lapsed before Congress restored it.

Visual for this record: A 2015 information-sharing law's liability shield briefly lapsed
Visual published by saratogacountyny.gov, shown for identification of the record. Credit: saratogacountyny.gov · source page ↗ Rights: owner-review-pending.

What the document says

The Cybersecurity Information Sharing Act of 2015 gave companies liability protection for voluntarily sharing cyber threat indicators with the government and each other, provided they followed the statute's procedures. Its own enacted text, Section 111, sets an effective period rather than a permanent authorization: the title and its amendments were to apply 'during the period beginning on the date of the enactment of this Act and ending on September 30, 2025,' with earlier actions still covered afterward. That sunset duly arrived. The current codification at 6 U.S.C. 1510 shows the amendment history: Public Law 119-75, enacted 3 February 2026, moved the effective end date forward to 30 September 2026, and Public Law 119-103, enacted 2 September 2026, moved it again to 11 December 2026. The gap between the statute's own original end date and the first restoring law is roughly four months.

Confidence and limits

Both the original enacted text and the current official codification are read directly here, which leaves little room for interpretive error about the dates themselves. What this record does not establish is operational impact: whether any specific information-sharing arrangement actually paused, or simply continued on the assumption Congress would act, is not something the statute or its amendment history can tell us on its own.

Why it mattered

Liability protection is what lets a company's lawyers sign off on sharing a threat indicator with a competitor or the government without treating every disclosure as a fresh legal risk to weigh case by case. A lapse does not delete existing indicators already shared, since the statute's own exception preserves protection for past actions, but it removes the protection for anything shared during the gap itself. A programme built around routine, ongoing sharing depends on that protection being continuously available, not restored after the fact.

Defensive takeaway

If your organisation relies on this statute's liability protection when sharing threat indicators, check the current effective date in force rather than assuming the protection is permanent, and have your legal counsel confirm coverage before, not after, a similar deadline recurs.

  • Does your threat-sharing programme depend on a specific statute's liability protection remaining continuously in effect?
  • Who in your organisation is responsible for tracking statutory deadlines that affect your information-sharing legal posture?
  • Would sharing continue, paused, or stop entirely if a similar protection lapsed again tomorrow?

A ten-year-old statute with a fixed end date is not a permanent feature of the legal landscape, however routine it has become. This one has already lapsed once and been restored twice on separate, later timelines, which is itself the fact worth building into any programme that depends on it.

Defensive takeaway

If your organisation relies on this statute's liability protection, check the current effective date in force rather than assuming the protection is permanent, and confirm coverage before a similar deadline recurs.

The original enacted text and the current official codification are read directly here; neither establishes whether any specific information-sharing arrangement actually paused during the lapse, only that the statutory protection had expired.

Sources & reading trail

Public Law 114-113, Consolidated Appropriations Act, 2016 (Division N, Title I, Cybersecurity Information Sharing Act of 2015) ↗

The Act's own Section 111 setting the original effective period ending 30 September 2025, and Section 104's liability-protection language.

government-primary · Source published: 18 December 2015 · Retrieved: 16 September 2026

6 U.S.C. 1510 - Effective period ↗

The current official codification and its amendment history, showing Public Law 119-75 and Public Law 119-103 successively moved the effective end date forward.

government-primary · Source published: Not established · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.