Wed 22 Jul 2026 / 20:41 ET
Kernel
Security 3 min read

House defense bill carries 10-year extension for cyber sharing law

The House NDAA would renew CISA 2015 protections, but the Senate has not matched the provision and Rand Paul is threatening a fight.

Dana Voss

By Dana Voss / Security Correspondent

House defense bill carries 10-year extension for cyber sharing law
img: The Record

The House voted Wednesday to attach a 10-year renewal of a key cybersecurity information-sharing law to its annual defense policy bill, giving companies and federal agencies another route to swap threat data without immediately tripping over liability concerns.

The chamber passed its version of the 2027 National Defense Authorization Act by a 216-212 vote. The bill is a $1.15 trillion Pentagon policy package. Only a small number of Democrats backed it, after the measure included no limits on President Donald Trump’s use of U.S. military forces, including in Iran.

Buried in that defense package is the Widespread Information Management for the Welfare of Infrastructure and Government Act, mercifully shortened to WIMWIG. The provision would reauthorize the 2015 Cybersecurity and Information Sharing Act, better known as CISA 2015, for another decade.

CISA 2015 gives legal protections to private companies and the federal government when they share information about hacking threats, including criminal activity and nation-state operations. The mechanism is not glamorous. It is a liability shield for moving indicators, warnings and related cyber threat data between entities that otherwise have lawyers standing in the doorway.

The law briefly lapsed last year, leaving federal officials without the full picture of digital threats facing U.S. critical infrastructure, according to reporting by The Record. Congress later approved a temporary extension that runs through Sept. 30.

The Senate is the problem

The House Homeland Security Committee approved WIMWIG last year, but it has not received a standalone floor vote. Its path through the Senate is also messy.

Sen. Rand Paul, the Kentucky Republican who chairs the Senate Homeland Security Committee, has said he will block any CISA 2015 renewal unless lawmakers add language barring the Cybersecurity and Infrastructure Security Agency from work countering online disinformation. That demand is aimed at CISA the agency, which Congress created in 2018, three years after the information-sharing statute. The law and the agency are not directly linked.

The Senate’s current NDAA draft does not include the same CISA 2015 extension. The issue is expected to surface during the Senate amendment process, but the broader defense bill has already stalled. Democrats earlier this month blocked consideration of the legislation amid their fight to restrict Trump’s actions on Iran.

Even if senators add a renewal, it would still have to survive negotiations between the House and Senate before reaching a final compromise bill.

House lawmakers have tried another route as well. In May, a bipartisan group released an artificial intelligence legislative discussion draft that included a similar provision extending CISA 2015 through 2035. That package has gained little traction.

Pentagon cyber job fight remains unresolved

The House bill also diverges from the Senate on Pentagon cyber leadership. The House version does not include a Senate provision that would combine two major Defense Department cyber roles into one senior post.

The Senate draft would create an undersecretary of Defense for cyber, information and networks. That official would serve both as the department’s chief information officer and as the principal cyber adviser to the secretary of Defense.

According to The Record, the Senate language is meant to head off growing friction between the Pentagon CIO and the assistant secretary of defense for cyber policy over who controls digital operations, especially offensive activity. The change would take effect in two years.

The House-passed NDAA stops short of that merger. It calls instead for a review and realignment of the Pentagon’s cyber roles, which is Congress-speak for admitting the org chart is already causing trouble.

This story draws on original reporting from The Record.

More Security/

view all ↗