The House of Representatives passed its version of the fiscal year 2027 National Defense Authorization Act on Wednesday by a narrow 216-212 vote, with only a handful of Democrats backing the $1.15 trillion Pentagon policy bill. Tucked inside the legislation is a provision that would renew the 2015 Cybersecurity Information Sharing Act (CISA 2015) for another decade.
The reauthorization language comes from the Widespread Information Management for the Welfare of Infrastructure and Government (WIMWIG) Act, which the House Homeland Security Committee approved last year but never brought to a standalone floor vote. CISA 2015 provides legal liability protections that let private companies and federal agencies share threat data on criminal and nation-state hacking activity without fear of lawsuits or regulatory blowback.
The statute briefly lapsed last year, a gap that left federal officials with reduced visibility into the scope of digital threats facing U.S. critical infrastructure before Congress approved a temporary extension through September 30.
Senate Roadblocks
The path forward is far from settled. The Senate’s draft NDAA does not currently include a matching CISA 2015 extension, though lawmakers expect the issue to surface during the chamber’s amendment process. Sen. Rand Paul (R-KY), who chairs the Senate Homeland Security Committee, has said he will block any reauthorization unless it includes language barring the Cybersecurity and Infrastructure Security Agency from countering online disinformation, despite the fact that the 2015 law and the CISA agency, created in 2018, are not directly linked.
Democrats have also complicated the bill’s trajectory. Earlier this month, they stalled consideration of the NDAA as part of a broader, months-long effort to constrain President Trump’s use of military force, particularly regarding the Iran conflict. The House-passed bill itself places no such restrictions on presidential war powers.
Even if a CISA 2015 extension survives the Senate, it would still need to be reconciled with the House version during conference negotiations before any final compromise bill reaches the president’s desk. A separate bipartisan AI legislative package unveiled in May proposed extending CISA 2015 through 2035, but that effort has gained little momentum.
Pentagon Cyber Leadership Split
The two chambers also diverge on Pentagon cyber governance. The Senate’s NDAA draft would create a new undersecretary of Defense for cyber, information, and networks, consolidating the chief information officer role with the top cyber policy adviser position to the Defense secretary, taking effect within two years. That change is aimed at resolving friction between the CIO and the assistant secretary of defense for cyber policy over authority on digital operations, including offensive cyber measures. The House version instead calls for a broader review and realignment of Pentagon cyber roles without creating a single consolidated post.
