The Senate Appropriations Committee’s proposed continuing resolution would keep federal agencies operating through December 11, 2026 and, more importantly for IT and security teams, prevent three looming September 30 deadlines from immediately interrupting federal cyber operations: the Cybersecurity Information Sharing Act of 2015, the Federal Cybersecurity Enhancement Act of 2015, and the Technology Modernization Fund.
Federal News Network first reported the provisions in the Senate measure released August 2. The proposal is not law, and it is materially different from the House’s earlier “clean” continuing resolution, which would fund the government only through December 4 and does not carry the same extensions. For agencies, contractors, and private-sector threat-sharing partners, that difference is more than a seven-day funding-calendar dispute: it determines whether federal programs retain authority to accept shared indicators, operate government-wide detection services, and approve new modernization investments after September 30.
The central finding is straightforward: the Senate bill would preserve operational authority, but only for another 72 days. It is a stopgap for the stopgap. Congress would be avoiding an immediate cliff while deferring the substantive decisions on privacy safeguards, liability protections, federal monitoring, and the future financing model for modernization until after the November 2026 midterm elections.
The Senate measure would continue appropriations at fiscal 2026 levels beginning October 1, the first day of fiscal 2027, through December 11. It also extends the Cybersecurity Information Sharing Act, often abbreviated as CISA 2015, and the Federal Cybersecurity Enhancement Act for the same period.
Those are separate statutes, and the shared acronym has repeatedly made the debate harder to follow. CISA 2015 is the information-sharing law; it is unrelated to the Cybersecurity and Infrastructure Security Agency except that the agency is one of the major federal participants in the sharing system.
CISA 2015 creates the legal framework under which companies can voluntarily provide cyber-threat indicators and defensive measures to government partners and other eligible entities. Its protections matter to corporate counsel as much as to security operations teams: the law offers liability protection for compliant sharing and constrains certain uses and handling of information. Without an extension, companies could still cooperate with federal investigators through other channels, but the statutory safe harbor that made routine, automated sharing easier would no longer be available.
This is not a theoretical concern. The law temporarily lapsed during the 2025 government funding fight, and reporting by Axios documented that the interruption led organizations to bring lawyers into decisions that had previously been handled as operational threat-sharing. That slowdown is especially awkward when vulnerability intelligence needs to move in hours rather than after legal review.
The administration’s newer GOLD EAGLE vulnerability-sharing initiative increases the stakes. Federal News Network reported that 23 trade associations warned congressional leaders that the program depends on CISA 2015’s protections. Public accounts of GOLD EAGLE describe it as an effort to coordinate information on AI-related vulnerabilities and remediation across government and industry. Whatever its eventual scale, building it on a law that Congress is extending in short increments is a poor fit for a program that needs companies to make durable disclosure and data-handling commitments.
The Federal Cybersecurity Enhancement Act is the government-facing half of the Senate package. The statute authorizes the Department of Homeland Security to deploy shared intrusion-detection and prevention capabilities across civilian executive-branch agencies. The legal text currently sets its expiration at September 30, 2026. That makes the Senate’s proposed extension necessary even if agencies’ existing tooling, including the long-running EINSTEIN services, does not suddenly disappear from networks on October 1.
The practical risk is authority, support, and future operations—not an overnight switch being thrown on every federal sensor. A lapse would complicate DHS’s ability to continue providing and evolving those services across agencies precisely when federal networks are being asked to absorb more cloud, AI, and identity infrastructure.
The governing statute says that after September 30, 2026, GSA may not award or transfer TMF money for a project that is not already in progress. Existing projects can continue. The fund and board then wind down after those projects are completed, with remaining unobligated funds ultimately returning to the Treasury for deficit reduction.
That distinction is the missing context behind references to the fund “expiring.” A lapse would not necessarily halt an agency modernization project already funded by TMF. It would block the fund’s core forward-looking function: selecting new work and moving money to agencies before legacy systems, security debt, or public-service failures become unmanageable.
The timing is particularly awkward. The TMF’s July 2026 call for proposals sought projects that would advance AI adoption and modernize permitting technology, and it explicitly said proposals received by July 24 could be considered for selection and announcement by September 30. The program is still soliciting work while its ability to make a new award is approaching a statutory cutoff.
Federal News Network reported that acting TMF Executive Director Jessie Posilkin told agencies the program remains “open for business.” That is accurate only through September 30 under current law. The Senate CR would keep that business open through December 11, but it would not give agencies a dependable planning horizon for multi-year modernization efforts.
A government-wide fund cannot operate effectively as a quarterly emergency. Agencies must assemble technical designs, cost estimates, acquisition strategies, cybersecurity plans, executive sponsorship, and repayment or sustainability models before applying. A funding mechanism that may vanish in weeks encourages agencies to prioritize projects that are already nearly ready, rather than the difficult legacy replacements that most need coordinated federal intervention.
For CISA 2015, a long-term reauthorization would force lawmakers to address the questions they have repeatedly postponed: whether the liability protections should change, how shared data should be minimized and protected, whether reporting and oversight mechanisms remain adequate, and how the law should fit alongside newer AI-focused vulnerability programs. An extension through December 11 preserves the current bargain without resolving any of those issues.
For the TMF, the disagreement is more structural. The fund was created under the Modernizing Government Technology Act to finance projects that improve federal IT, cybersecurity, privacy, efficiency, and service delivery. Yet it has relied on episodic appropriations and reauthorizations rather than a predictable capital model.
The Office of Management and Budget has floated a revised approach that would let the TMF operate more like a working-capital fund and retain up to $100 million annually from otherwise expired funds. Supporters see that as a way to reduce dependence on occasional large appropriations. Critics will need to decide whether retaining expired balances gives the program sufficient congressional oversight and whether a revolving model can finance projects at the scale federal legacy-system replacement requires.
The Senate CR does not answer either question. It merely prevents the program from entering a wind-down phase in September.
Security teams that share threat data with federal partners should prepare for two possibilities: a short-term continuation under the present CISA 2015 framework, or a lapse that shifts more sharing decisions into narrower contractual, investigative, and legal channels. The need is most acute for organizations that automate indicator sharing or participate in joint defense arrangements where the statute’s liability and privacy provisions are part of the operating assumptions.
Federal CIO offices with active or planned TMF proposals should document their projects’ readiness, dependency dates, and obligations now. If the Senate language becomes law, the additional time may support new selections through December 11. If it does not, the legal cutoff means no new TMF award can be made after September 30 for work not already in progress.
The Senate’s proposal has bought nothing yet. If enacted unchanged, it would buy cyber programs and the TMF until December 11—long enough to avert a September shutdown of authority, but short enough that agencies will be back in the same planning crisis before the year is out.
The central finding is straightforward: the Senate bill would preserve operational authority, but only for another 72 days. It is a stopgap for the stopgap. Congress would be avoiding an immediate cliff while deferring the substantive decisions on privacy safeguards, liability protections, federal monitoring, and the future financing model for modernization until after the November 2026 midterm elections.
The Senate CR preserves authorities the House bill leaves exposed
The Senate measure would continue appropriations at fiscal 2026 levels beginning October 1, the first day of fiscal 2027, through December 11. It also extends the Cybersecurity Information Sharing Act, often abbreviated as CISA 2015, and the Federal Cybersecurity Enhancement Act for the same period.Those are separate statutes, and the shared acronym has repeatedly made the debate harder to follow. CISA 2015 is the information-sharing law; it is unrelated to the Cybersecurity and Infrastructure Security Agency except that the agency is one of the major federal participants in the sharing system.
CISA 2015 creates the legal framework under which companies can voluntarily provide cyber-threat indicators and defensive measures to government partners and other eligible entities. Its protections matter to corporate counsel as much as to security operations teams: the law offers liability protection for compliant sharing and constrains certain uses and handling of information. Without an extension, companies could still cooperate with federal investigators through other channels, but the statutory safe harbor that made routine, automated sharing easier would no longer be available.
This is not a theoretical concern. The law temporarily lapsed during the 2025 government funding fight, and reporting by Axios documented that the interruption led organizations to bring lawyers into decisions that had previously been handled as operational threat-sharing. That slowdown is especially awkward when vulnerability intelligence needs to move in hours rather than after legal review.
The administration’s newer GOLD EAGLE vulnerability-sharing initiative increases the stakes. Federal News Network reported that 23 trade associations warned congressional leaders that the program depends on CISA 2015’s protections. Public accounts of GOLD EAGLE describe it as an effort to coordinate information on AI-related vulnerabilities and remediation across government and industry. Whatever its eventual scale, building it on a law that Congress is extending in short increments is a poor fit for a program that needs companies to make durable disclosure and data-handling commitments.
The Federal Cybersecurity Enhancement Act is the government-facing half of the Senate package. The statute authorizes the Department of Homeland Security to deploy shared intrusion-detection and prevention capabilities across civilian executive-branch agencies. The legal text currently sets its expiration at September 30, 2026. That makes the Senate’s proposed extension necessary even if agencies’ existing tooling, including the long-running EINSTEIN services, does not suddenly disappear from networks on October 1.
The practical risk is authority, support, and future operations—not an overnight switch being thrown on every federal sensor. A lapse would complicate DHS’s ability to continue providing and evolving those services across agencies precisely when federal networks are being asked to absorb more cloud, AI, and identity infrastructure.
TMF has money and proposals, but its authority runs out
The Technology Modernization Fund faces a different kind of deadline. It is not simply a line item that disappears if a continuing resolution fails. The fund is a statutory program administered by the General Services Administration, with the Technology Modernization Board deciding which agency projects receive support.The governing statute says that after September 30, 2026, GSA may not award or transfer TMF money for a project that is not already in progress. Existing projects can continue. The fund and board then wind down after those projects are completed, with remaining unobligated funds ultimately returning to the Treasury for deficit reduction.
That distinction is the missing context behind references to the fund “expiring.” A lapse would not necessarily halt an agency modernization project already funded by TMF. It would block the fund’s core forward-looking function: selecting new work and moving money to agencies before legacy systems, security debt, or public-service failures become unmanageable.
The timing is particularly awkward. The TMF’s July 2026 call for proposals sought projects that would advance AI adoption and modernize permitting technology, and it explicitly said proposals received by July 24 could be considered for selection and announcement by September 30. The program is still soliciting work while its ability to make a new award is approaching a statutory cutoff.
Federal News Network reported that acting TMF Executive Director Jessie Posilkin told agencies the program remains “open for business.” That is accurate only through September 30 under current law. The Senate CR would keep that business open through December 11, but it would not give agencies a dependable planning horizon for multi-year modernization efforts.
A government-wide fund cannot operate effectively as a quarterly emergency. Agencies must assemble technical designs, cost estimates, acquisition strategies, cybersecurity plans, executive sponsorship, and repayment or sustainability models before applying. A funding mechanism that may vanish in weeks encourages agencies to prioritize projects that are already nearly ready, rather than the difficult legacy replacements that most need coordinated federal intervention.
A December extension solves the deadline, not the policy fight
Congress has chosen short extensions before, but the Senate proposal shows that the underlying policy disagreements remain unresolved.For CISA 2015, a long-term reauthorization would force lawmakers to address the questions they have repeatedly postponed: whether the liability protections should change, how shared data should be minimized and protected, whether reporting and oversight mechanisms remain adequate, and how the law should fit alongside newer AI-focused vulnerability programs. An extension through December 11 preserves the current bargain without resolving any of those issues.
For the TMF, the disagreement is more structural. The fund was created under the Modernizing Government Technology Act to finance projects that improve federal IT, cybersecurity, privacy, efficiency, and service delivery. Yet it has relied on episodic appropriations and reauthorizations rather than a predictable capital model.
The Office of Management and Budget has floated a revised approach that would let the TMF operate more like a working-capital fund and retain up to $100 million annually from otherwise expired funds. Supporters see that as a way to reduce dependence on occasional large appropriations. Critics will need to decide whether retaining expired balances gives the program sufficient congressional oversight and whether a revolving model can finance projects at the scale federal legacy-system replacement requires.
The Senate CR does not answer either question. It merely prevents the program from entering a wind-down phase in September.
What federal IT leaders should do before September 30
Agencies should not treat the Senate proposal as a completed extension. It remains a committee measure that must clear the Senate, be reconciled with the House, and be signed into law before the fiscal year ends on September 30, 2026.Security teams that share threat data with federal partners should prepare for two possibilities: a short-term continuation under the present CISA 2015 framework, or a lapse that shifts more sharing decisions into narrower contractual, investigative, and legal channels. The need is most acute for organizations that automate indicator sharing or participate in joint defense arrangements where the statute’s liability and privacy provisions are part of the operating assumptions.
Federal CIO offices with active or planned TMF proposals should document their projects’ readiness, dependency dates, and obligations now. If the Senate language becomes law, the additional time may support new selections through December 11. If it does not, the legal cutoff means no new TMF award can be made after September 30 for work not already in progress.
The Senate’s proposal has bought nothing yet. If enacted unchanged, it would buy cyber programs and the TMF until December 11—long enough to avert a September shutdown of authority, but short enough that agencies will be back in the same planning crisis before the year is out.
References
- Primary source: Federal News Network
Published: 2026-08-03T21:58:43+00:00
Senate stopgap extends key cyber authorities, TMF | Federal News Network
The Senate's CR would keep the government open through Dec. 11, while extending cyber information sharing authorities and the Technology Modernization Fund.federalnewsnetwork.com - Related coverage: cbsnews.com
- Related coverage: senate.gov
U.S. Senate: Commonly Searched for Legislation (119th Congress)
_Commonly Searched for Legislation (119th Congress)www.senate.gov
- Related coverage: dailypress.senate.gov
Tuesday, September 30, 2025 - U.S. Senate Daily Press
8:24 p.m. The Senate adjourned. 7:59 p.m. Senator Coons, Klobuchar and Kim spoke on the government shutdown. 7:49 p.m. Majority Leader Thune wrapped up. 7:49 p.m. Senator Whitehouse spoke on government shutdown. 7:36 p.m. Senator Blumenthal spoke on health care. 7:31 p.m. Senator Rosen spoke on...www.dailypress.senate.gov - Related coverage: appropriations.senate.gov
- Related coverage: appropriations.senate.gov
- Related coverage: axios.com
Rand Paul's last-minute demands push key cybersecurity law to the brink
Congressional aides say Paul hasn't been open to negotiations.www.axios.com
- Related coverage: axios.com
Cyber threat information-sharing slows as lawyers get involved
After Congress let decade-old protections lapse, companies are unsure how to proceed with information government.www.axios.com
- Related coverage: techradar.com
Congressional stopgap deal could end US government shutdown | TechRadar
Funding extension secures US cybersecurity - for nowwww.techradar.com - Related coverage: democrats.senate.gov