7.17.2026

Federal: CISA 2015 Multi Association Letter

July 17, 2026

The Honorable Mike Johnson Speaker
United States House of Representatives Washington, DC 20515

The Honorable Hakeem Jeffries Democratic Leader
United States House of Representatives Washington, DC 20515

Dear Speaker Johnson and Leader Jeffries,

We, the undersigned trade associations, write to request the inclusion of an extension of the Cybersecurity Information Sharing Act of 2015 (CISA 2015) in the upcoming continuing resolution. Unless Congress acts, CISA 2015 authority will

expire on September 30, making the situation urgent.

Over the past decade, CISA 2015 has become a foundational component of the nation’s cybersecurity. The law enables the voluntary sharing of cyber threat indicators and defensive measures between private entities and with the federal government, while providing the liability protections and legal certainty needed to encourage such sharing. These authorities support the timely exchange of actionable threat intelligence and have become central to the collective defense of public and private sector networks, particularly across critical infrastructure sectors.

Today’s advanced AI systems can identify and exploit software vulnerabilities faster than ever before, shrinking the time between discovering a weakness and using it in an attack. AI tools are also making sophisticated cyber capabilities cheaper, faster, and easier to use, allowing threats to spread and adapt in real time.

A long-term reauthorization of CISA 2015 remains critical, and we continue to urge Congress to make that a priority. In the interim, any interruption to these protections would greatly threaten the nation’s ability to respond to cyber threats if companies were forced to pause or reassess information-sharing relationships.

A lapse now would be especially ill-timed—undermining not just longstanding information-sharing practices but also the GOLD EAGLE Initiative, a new clearinghouse that pairs industry and critical infrastructure operators with government agencies to rapidly detect and patch vulnerabilities. The Administration has made clear that GOLD EAGLE depends on the protections CISA 2015 provides, and that the program is fundamentally at risk if CISA 2015 is not extended.

Page 2

We appreciate your leadership on this important issue and urge extending these critical cybersecurity protections as part of upcoming legislative activity.

Sincerely,

Aerospace Industries Association Alliance for Automotive Innovation American Fintech Council
American Hotel and Lodging Association American Petroleum Institute
American Public Power Association Bank Policy Institute
Business Roundtable Business Software Alliance Cybersecurity Coalition Edison Electric Institute
Electronic Transactions Association Healthcare Leadership Council Information Technology Industry Council Institute of International Bankers National Retail Federation
National Rural Electric Cooperative Association NCTA — The Internet & Television Association Operational Technology Cybersecurity Coalition SIFMA
TechNet
U.S. Chamber of Commerce
USTelecom — The Broadband Association

Cc:
Senate Majority Leader John Thune Senate Democratic Leader Chuck Schumer Office of the National Cyber Director Department of the Treasury
Department of War
Department of Homeland Security

About the American Fintech Council: The mission of the American Fintech Council is to promote an innovative, responsible, inclusive, customer-centric financial system. You can learn more at www.fintechcouncil.org.