The bill
Extending Expired Cybersecurity Authorities Act
S. 2983, 119th Congress — read as touching Cybersecurity.
Sponsored by
Sen. Peters, Gary C. [D-MI]
ID: P000595
Follow the money
The bill
S. 2983, 119th Congress — read as touching Cybersecurity.
The sponsor
Every bill has someone who introduced it. That name is where the paper trail starts.
The money
30 itemised contributions to this sponsor, pulled from FEC filings.
The alignment
This bill's text tracks the "Introduction" section, p. 254-256 of the Mandate for Leadership.
Track this bill's progress through the legislative process
Latest Action
Read the second time. Placed on Senate Legislative Calendar under General Orders. Calendar No. 182.
October 7, 2025
📍 Current Status
Next: The bill will be reviewed by relevant committees who will debate, amend, and vote on it.
1. Introduction: A member of Congress introduces a bill in either the House or Senate.
2. Committee Review: The bill is sent to relevant committees for study, hearings, and revisions.
3. Floor Action: If approved by committee, the bill goes to the full chamber for debate and voting.
4. Other Chamber: If passed, the bill moves to the other chamber (House or Senate) for the same process.
5. Conference: If both chambers pass different versions, a conference committee reconciles the differences.
6. Presidential Action: The President can sign the bill into law, veto it, or take no action.
7. Became Law: If signed (or if Congress overrides a veto), the bill becomes law!
Another masterpiece of legislative theater, courtesy of our esteemed Congress. Let's dissect this farce, shall we?
**Main Purpose & Objectives:** The "Extending Expired Cybersecurity Authorities Act" (because who needs a catchy title when you can just phone it in?) aims to reauthorize the Cybersecurity Information Sharing Act of 2015. Wow, what a bold move! Reauthorizing an existing law that's about to expire? How innovative.
**Key Provisions & Changes to Existing Law:** The bill extends the sunset date of the Cybersecurity Information Sharing Act from September 30, 2025, to September 30, 2035. Oh, and it also changes the name of the act to "Protecting America from Cyber Threats Act" because, you know, rebranding is everything in politics. It's like putting a fresh coat of paint on a clunker – it still won't run, but hey, it looks prettier.
**Affected Parties & Stakeholders:** The usual suspects are involved: the federal government, private sector companies, and cybersecurity firms looking to cash in on the gravy train. You can bet your bottom dollar that lobbyists for these industries have been busy greasing palms and whispering sweet nothings into the ears of our fearless leaders.
**Potential Impact & Implications:** This bill is a classic case of "CYA" (Cover Your Assets) politics. By reauthorizing an existing law, Congress gets to pretend it's doing something about cybersecurity while actually accomplishing nothing meaningful. The real impact will be felt by the companies that get to profit from this extension, and the politicians who get to tout their "commitment to national security" in campaign ads.
Diagnosis: This bill is a symptom of a deeper disease – the chronic inability of our government to address actual problems. It's a placebo, designed to make voters feel like something is being done while the real issues fester. The lawmakers behind this bill are either incompetent or corrupt (or both). Either way, it's a waste of time and taxpayer dollars.
Treatment: A healthy dose of skepticism, followed by a strong prescription of critical thinking. Voters need to stop buying into these legislative placebos and demand actual solutions to the problems plaguing our nation. But hey, that's just a pipe dream – after all, who needs effective governance when you can have empty rhetoric and pork-barrel politics?
Sen. Peters, Gary C. [D-MI]
Congress 119 • 2024 Election Cycle
No PAC contributions found
No committee contributions found
This bill has 10 cosponsors. Below are their top campaign contributors.
ID: R000605
Top Contributors
10
ID: K000383
Top Contributors
10
ID: C001095
Top Contributors
10
ID: B001305
Top Contributors
10
ID: G000555
Top Contributors
10
ID: R000608
Top Contributors
10
ID: C001096
Top Contributors
10
ID: C001035
Top Contributors
10
ID: W000805
Top Contributors
10
ID: L000575
Top Contributors
10
Hub layout: Politicians in center, donors arranged by type in rings around them.
Showing 68 nodes and 45 connections (74 secondary connections hidden)
Total contributions: $126,887
Showing top 18 donors by contribution amount
Which industries are materially affected by specific provisions in this bill. 1 helped.
Section 2(a) extends the Cybersecurity Information Sharing Act of 2015 authorization from September 30, 2025 to September 30, 2035, providing a clear benefit (regulatory continuity) to cybersecurity firms.
This bill shows semantic similarity to the following sections of the Project 2025 policy document.
— 222 — Mandate for Leadership: The Conservative Promise forward-leaning in sharing cyber threat intelligence with private-sector partners and the public, emphasizing that the protective nature of such information is of value only if put into the right hands at the right time. Since critical infrastructure and services are overwhelmingly owned, managed, and defended by the private sector in the United States, there has been an increasing emphasis on declassify- ing intelligence and sharing actionable information with private-sector partners, often through industry-specific Information Sharing and Analysis Centers (ISACs); regional meetings of government and private-sector experts called InfraGard, run by the FBI; direct public notification from the Department of Homeland Security, the FBI, and (increasingly) the NSA; and more discreet one-on-one engagements led by the collecting agencies. These programs properly recognize the private sector’s role in providing cyber- security for Americans; in practice, however, the intelligence shared by the U.S. government through these venues is too often already known or no longer relevant by the time it makes its way through the downgrade process for sharing. In addition, government-shared information often needs to take advantage of the opportunity to provide contexts, such as attribution, trends, and size of the observed cyber problem. As warranted, additional context should be provided to the private sector as a matter of routine. To continue improving the U.S. government’s ability to defend the country’s most vital networks, the IC must adopt an “obligation to share” policy process, including the capacity for “write to release” intelligence products whereby newly discovered technical indicators, targeting, and other intelligence relevant to cyber defense are automatically provided either to the public or to targeted entities within 48 hours of their collection—which is how counterterrorism intel- ligence has been managed for years when it comes to a “duty to warn.” Under this policy, agency heads should still have the flexibility to withhold intelligence for operational or counterintelligence reasons but would need to report regularly to Congress on the number of and justification for exceptions. This policy would make sharing intelligence and defending networks the default, as it already is in the rest of the cybersecurity community outside the IC, to improve the quantity, relevance, and timeliness of defensive information while ensuring accountability for top leaders when they must withhold this information. One of the most significant challenges within the IC is presented by the need to share information promptly among the 18 elements of the intelligence enterprise. The only long-term solution to the understandable tension between the need to share information and the need to protect intelligence sources and methods is a robust real-time auditing capability that electronically flags unauthorized access. Under an identity management system with real-time audit, even the most sensi- tive information acquired by America’s intelligence agencies can be shared, and the access to and use of that information are appropriately monitored. Establishing — 223 — Intelligence Community a real-time auditing capability is essential to decreasing the risk for the heads of intelligence agencies in meeting their statutory requirements to ensure that they protect sources and methods associated with the classified information their agen- cies collect. Overclassification. There is broad consensus across the U.S. government and among stakeholders that the system for classifying, declassifying, and otherwise marking and handling sensitive information is at a crossroads. Exorbitant amounts of classified data are created daily, and agency personnel often mistakenly choose classification as the default selection to ensure national security. At the same time, the effectiveness of downgraded and carefully declassified information to support foreign policy efforts has been borne out in, for example, alerting the broader world of Russia’s buildup and likely plans for its invasion of Ukraine. Two executive orders principally govern how the U.S. government handles clas- sified and sensitive information. l Executive Order 13526, “Classified National Security Information,” issued in 2009,38 prescribes the classification levels and procedures for declassification. l Executive Order 13556, “Controlled Unclassified Information,” issued in 2010,39 aimed to establish a uniform program for managing all unclassified information that requires safeguarding or dissemination controls. The current system for declassifying classified national security information (CNSI) is extraordinarily analog, requiring experts’ review of individual records. Declassification policies are based on human review of paper and need to con- template and handle the proliferation and volume of digital records created by agencies. The U.S. government will soon reach the point at which manual review is impossible. The declassification of CNSI should support key U.S. national security objectives, reflect mission priorities, and not serve solely as a necessary procedural function. Reforms should include: l Tighter definitions and greater specificity for categories of information requiring protection. l More stringent policies to effect significant reductions in the number of Original Classification Authorities (OCAs). l Stricter accountability measures at the OCA level and more detailed security classification guides.
Policy matches are calculated using semantic similarity between bill summaries and Project 2025 policy text. A score of 60% or higher indicates meaningful thematic overlap. This does not imply direct causation or intent, but highlights areas where legislation aligns with Project 2025 policy objectives.