Document type: Article Practice area: Business and Corporate — Regulatory Jurisdiction: United States Last reviewed: 5 September 2026
There is a particular flavor of unpleasant meeting that happens perhaps eighteen months after a closing, when a letter arrives from the Committee on Foreign Investment in the United States asking about a transaction nobody filed.
CFIUS has authority to review transactions that were never notified to it, to require mitigation, and — where mitigation cannot resolve the concern — to recommend that the President order divestment. There is no statute of limitations on that authority for unfiled transactions. A deal that closed cleanly in 2022 can become an enforcement matter in 2026.
For most cross-border transactions this is background risk rather than a live problem. But the category of transactions that need real analysis has grown substantially, and it now includes deals that a decade ago no one would have considered a national security matter: a minority investment in a data analytics company, a Series B round with a foreign limited partner, a warehouse lease near an airfield.
Understanding when CFIUS matters — and how much — is now part of ordinary transactional practice.
The framework
CFIUS is an interagency committee chaired by the Treasury Department, with members from Defense, State, Commerce, Justice, Homeland Security, Energy, and the U.S. Trade Representative, plus intelligence community input.
Its authority derives from Section 721 of the Defense Production Act of 1950, as amended most consequentially by the Foreign Investment Risk Review Modernization Act of 2018 (FIRRMA). The implementing regulations appear at 31 C.F.R. Part 800 for investments in businesses and 31 C.F.R. Part 802 for real estate.
Its mandate is narrow and specific: national security. CFIUS does not assess whether a transaction is good for the economy, good for competition, or good for employment. Those questions belong to other agencies. CFIUS asks whether a transaction could impair national security, and it uses a structured framework to answer.
The risk equation the Committee applies:
Risk = Threat × Vulnerability × Consequence
- Threat — the intent and capability of the foreign person. Who ultimately controls the acquirer? What is its relationship to a foreign government? What is its history?
- Vulnerability — the nature of the U.S. business. What does it do, what does it hold, and how could a hostile actor exploit access to it?
- Consequence — the potential effect on national security if the vulnerability were exploited.
Where the analysis lands. A transaction with high threat but no vulnerability — a state-owned fund buying a chain of coffee shops — presents no risk. A transaction with high vulnerability but a trusted acquirer — a UK defense contractor buying a U.S. defense contractor — presents manageable risk, addressed through existing security arrangements. Transactions with meaningful threat and meaningful vulnerability are where the Committee spends its time.
What is a covered transaction
Two categories under Part 800, plus real estate under Part 802.
Covered control transactions
Any transaction by or with a foreign person that could result in foreign control of any U.S. business.
"Control" is functional, not numerical. It means the power, direct or indirect, whether exercised or not, to determine, direct, or decide important matters affecting an entity. There is no percentage threshold. A 15 percent stake with board representation and veto rights over budgets can be control; a 40 percent passive stake with no governance rights may not be.
The indicative list of important matters includes: the sale of principal assets; reorganization, merger, or dissolution; closing or relocating facilities; major expenditures within an approved budget; entry into significant contracts; policies on access to sensitive technology or classified information; appointment or dismissal of officers or directors with access to sensitive information; and amendment of governing documents concerning any of these.
"U.S. business" means any entity engaged in interstate commerce in the United States — regardless of nationality of ownership. A foreign parent's U.S. subsidiary is a U.S. business.
Covered investments
FIRRMA extended jurisdiction to non-controlling investments in a specific category of businesses, known as TID U.S. businesses:
- T — Critical Technologies. A business that produces, designs, tests, manufactures, fabricates, or develops one or more critical technologies. "Critical technologies" is defined by reference to existing export control regimes: items on the United States Munitions List, items on the Commerce Control List controlled for specified reasons, nuclear equipment and technology, select agents and toxins, and emerging and foundational technologies identified under export control authorities.
- I — Critical Infrastructure. A business that owns, operates, manufactures, supplies, or services critical infrastructure within specific categories enumerated in an appendix to the regulations — telecommunications, utilities, energy, financial market infrastructure, ports, and others, each with a functional test.
- D — Sensitive Data. A business that maintains or collects, directly or indirectly, sensitive personal data of U.S. citizens.
The sensitive personal data definition matters enormously and is often underestimated. It covers ten categories, including financial data indicating financial distress, consumer report data, insurance applications, physical and mental health data, non-public electronic communications, geolocation data, biometric data, data for generating government identification, security clearance data, and genetic information — where the business (a) targets or tailors products to U.S. executive branch or military personnel or contractors, (b) has maintained or collected such data on more than one million individuals in the preceding twelve months, or (c) has a demonstrated business objective to do so.
The one-million threshold catches ordinary companies. A consumer fintech app, a health platform, a fitness tracker, a dating service, a mobile game with location features — any of these can be a TID business.
A covered investment requires the foreign person to obtain at least one of:
- Access to material non-public technical information;
- Membership or observer rights on the board, or the right to nominate a director; or
- Any involvement, other than through voting of shares, in substantive decisionmaking regarding critical technologies, critical infrastructure, or sensitive personal data.
Standard venture capital rights routinely satisfy this. A board observer seat is enough. Information rights giving access to technical roadmaps are enough.
Other covered transactions
- Changes in rights that result in foreign control or a covered investment — a conversion, an amendment to a shareholders' agreement, a waiver.
- Transactions designed to evade the regulations.
Mandatory filings
Most CFIUS filings are voluntary. Two categories are mandatory, and failing to file carries a civil penalty of up to the value of the transaction.
The substantial foreign government interest trigger
A filing is mandatory where a foreign person acquires a substantial interest in a TID U.S. business, and a foreign government holds a substantial interest in that foreign person.
The thresholds:
- Substantial interest in the U.S. business: 25 percent or more of the voting interest.
- Substantial interest of the foreign government in the acquirer: 49 percent or more of the voting interest, directly or indirectly.
Look-through rules apply to funds and partnerships, and the analysis of a fund with sovereign wealth limited partners requires care. A general partner's independence can matter.
The critical technology trigger
A filing is mandatory for a covered transaction involving a U.S. business that produces, designs, tests, manufactures, fabricates, or develops one or more critical technologies for which a U.S. regulatory authorization would be required to export, reexport, transfer, or retransfer the technology to the foreign person or to certain persons in its ownership chain.
How to analyze it. This is an export control question, not a CFIUS question. The steps:
- Classify the technology. Determine the Export Control Classification Number under the Commerce Control List, or whether the item is on the United States Munitions List.
- Identify the relevant foreign persons — the direct acquirer plus any person in the ownership chain holding 25 percent or more voting interest.
- Determine the country of each.
- Run the license determination: would a license be required to export that item to that country and that end user, considering reasons for control, license exceptions, and the end-user and end-use controls in 15 C.F.R. Part 744?
- If yes, the filing is mandatory.
This analysis requires export control counsel, and it should be done early, because a mandatory filing changes the transaction's timeline by months.
Consequences of not filing
- Civil penalties up to the value of the transaction, per violation, for failing to make a mandatory filing.
- Indefinite review authority. An unfiled non-mandatory transaction remains reviewable forever.
- The non-notified program. CFIUS actively identifies unfiled transactions through public sources, government databases, and referrals, and it opens inquiries. The program has grown considerably.
Two filing tracks
The declaration
A short-form filing, generally limited in length, submitted through the CFIUS case management system.
Timeline: the Committee has 30 days from acceptance to act.
Four possible outcomes:
- Clearance — a written notification that the Committee has concluded all action. This is the good outcome, and it provides a safe harbor.
- A request that the parties file a full written notice.
- A unilateral initiation of review by the Committee.
- A statement that the Committee cannot conclude action on the declaration — meaning the parties may file a notice or proceed without clearance, without a safe harbor.
When a declaration works: clean facts, a low-threat acquirer, a modest vulnerability profile, and no complicated ownership chain. Clearance rates on declarations have varied, and a meaningful proportion of declarations result in a request for a full notice.
When it does not: anything involving a state-owned or state-linked acquirer, sensitive technology, classified work, proximity to military installations, or an ownership chain that is difficult to describe in the space available. In those cases the declaration consumes 30 days and ends with a request for the thing you should have filed.
The written notice
The full filing. Comprehensive, detailed, and the standard route for any transaction with real issues.
The timeline, as the statute writes it:
- Pre-filing draft. Not required, but standard practice and highly advisable. The parties submit a draft; the staff comments; the parties revise. This stage takes two to eight weeks and is not counted in any statutory period.
- Formal filing and acceptance. The Committee reviews for completeness and accepts, which starts the clock.
- Review: 45 days.
- Investigation: an additional 45 days, if the Committee determines one is warranted.
- Presidential decision: 15 days, if the matter is referred.
Total statutory maximum: 105 days from acceptance.
Total realistic elapsed time: three to seven months from engagement to clearance, once the pre-filing period, information requests, and mitigation negotiation are counted.
And the pull-and-refile. Where the Committee's questions cannot be resolved within the clock, parties commonly withdraw and refile, which restarts the 45-day review. Two cycles are not unusual in complex cases, and a third happens.
What the Committee actually examines
The foreign person. Ultimate beneficial ownership traced to natural persons or to a government. Ownership chains through multiple jurisdictions. Relationships with foreign governments, militaries, or intelligence services. Prior CFIUS history. Any sanctions or enforcement history.
The U.S. business. What it makes and does. Its technologies and their classification. Its government contracts, especially classified ones. Its facilities and their locations relative to sensitive government sites. Its data holdings. Its position in supply chains. Its customer base, particularly government customers.
The transaction. Governance rights. Information access. Board composition. Rights over technology, personnel, and facilities. Post-closing integration plans. The buyer's intentions for the business.
The specific concerns that drive outcomes:
- Technology transfer — that sensitive know-how moves abroad, whether through export, personnel, or integration.
- Supply chain disruption — that a foreign owner could cut off a component the government or critical infrastructure depends on.
- Data access — that personal data on U.S. persons, particularly government and military personnel, becomes available to a foreign government.
- Proximity — that a facility's location enables surveillance of sensitive government activities.
- Government contracts — that a foreign owner gains access to classified or controlled information.
- Personnel — that foreign nationals gain access to controlled technology, which is itself a deemed export question under the EAR.
Excepted investors
FIRRMA created a limited carve-out for investors from specified excepted foreign states — a short list, currently Australia, Canada, New Zealand, and the United Kingdom — which have been determined to have robust inbound investment review processes of their own.
What the exception does. An excepted investor is outside CFIUS's covered investment jurisdiction (the non-controlling TID investments) and outside the real estate jurisdiction. It does not exempt the investor from covered control transaction jurisdiction: a UK company acquiring control of a U.S. defense contractor is still fully reviewable.
The qualification requirements are strict and easy to fail:
- The investor must be organized under the laws of an excepted state or the United States.
- Its principal place of business must be in an excepted state or the United States.
- Specified percentages of its board and its voting interests must be held by persons who are nationals of excepted states or the United States, with no single non-excepted foreign person holding 10 percent or more, and no non-excepted foreign persons holding 10 percent or more in the aggregate for certain measures.
- Neither the investor nor specified related persons may have had certain adverse CFIUS or enforcement history in the preceding five years.
In practice, many funds and public companies with international shareholder bases do not qualify, because the 10 percent tests are demanding. Do not assume excepted status; analyze it, and document the analysis.
The real estate regulations
31 C.F.R. Part 802 gives CFIUS jurisdiction over certain real estate transactions independent of any operating business.
Covered real estate transactions are purchases, leases, or concessions by a foreign person of real estate that:
- Is located within, or will function as part of, a covered port (airports and maritime ports identified in Department of Transportation lists); or
- Is within close proximity — one mile — of specified military installations; or
- Is within the extended range — 100 miles — of certain listed installations; or
- Is within specified geographic areas associated with listed installations, including certain offshore ranges.
The lists of installations are appendices to Part 802 and have been expanded, adding sites and increasing the number of locations subject to the 100-mile extended range. The practical effect is that a great deal of U.S. real estate is now within a covered zone, particularly in the western states.
The rights that matter. A covered real estate transaction requires the foreign person to obtain at least three of four property rights: physical access, the right to exclude, the right to improve or develop, or the right to attach fixed structures.
Exceptions include single housing units, real estate in certain urbanized areas (subject to exceptions), certain commercial office space, and land held by excepted real estate investors.
Real estate filings are voluntary, but the same indefinite review authority applies, and the Committee has shown willingness to pursue real estate matters.
Mitigation
Most transactions that raise concerns are not blocked. They are mitigated.
Mitigation is a negotiated agreement — commonly a National Security Agreement, sometimes a letter of assurance or a condition — between the parties and one or more monitoring agencies, addressing the specific risk the Committee identified.
The common measures, from lightest to heaviest:
Information security and access controls. Restrictions on which personnel may access what data or technology; network segregation; U.S.-person-only access to specified systems; security plans subject to agency approval.
Governance restrictions. Limits on board composition; a requirement that specified decisions be made by U.S. citizens; exclusion of the foreign owner from specified categories of decision.
A security officer or committee. A designated U.S. citizen security officer, or a government security committee of the board composed of cleared U.S. citizens, with responsibility for compliance.
Supply assurance. Commitments to continue supplying specified products to U.S. government customers on specified terms and for a specified period, with notice requirements before any change.
Facility and personnel controls. Restrictions on foreign national access to facilities; badging and escort requirements; screening.
Divestiture or carve-out of a sensitive business or asset, either before closing or on an agreed schedule after.
Proxy or voting trust arrangements. For the most sensitive cases, particularly where classified work is involved, a structure that vests voting control in cleared U.S. citizen trustees, insulating the business from foreign owner direction. This is the heaviest measure short of prohibition and it substantially changes the value of the acquisition.
Monitoring and reporting. Periodic compliance reports; annual certifications; audit rights; on-site inspections; a designated agency point of contact.
What living under mitigation is like
It is an ongoing compliance program, not a closing condition. A National Security Agreement typically requires:
- A named compliance officer, often with specified qualifications.
- Written policies and procedures implementing each obligation.
- Training for covered personnel.
- Quarterly or annual reports to the monitoring agencies.
- An annual certification signed by a senior officer.
- Notice before specified changes — a new director, a change in ownership, a facility relocation, a new product line.
- Independent audits, in more demanding agreements, at the company's expense.
- Agency access to facilities, personnel, and records.
Cost. Ongoing compliance for a moderately demanding NSA typically runs $200,000 to $1 million annually, and more where a proxy or a segregated network is involved.
Breach consequences are serious. CFIUS may impose civil penalties, and in the case of a material breach may reopen the review — with divestment available as a remedy.
Negotiate the agreement carefully. Terms that seem reasonable at signing become operational constraints for years. Push for: definitions tied to objective standards rather than agency discretion; notice rather than approval where possible; reasonable cure periods; a defined term or a review-and-sunset mechanism; and clarity about which agency decides what.
What happens when mitigation is not enough
If the Committee cannot resolve the risk, the matter goes to the President, who may suspend or prohibit the transaction, including ordering divestment of a completed one.
In practice, few transactions reach a presidential order, because parties abandon transactions when the Committee signals that clearance is unlikely. The abandonment is the outcome; the order is the formality avoided.
Judicial review is extremely limited. The statute provides that the President's action and findings are not subject to judicial review. Courts have entertained procedural due process challenges to CFIUS process — most notably regarding the adequacy of notice and the opportunity to respond to the evidence relied on — but the substantive determination is not reviewable.
The practical consequence: the process is the protection. A party that does not make its case within the review has very little recourse afterward.
A worked assessment
Tessaly Analytics is a Series C health-data company. It processes claims and clinical data for regional insurers, holds records on approximately 4.3 million individuals, and licenses a proprietary risk-scoring model. Ardencote Capital, a Singapore-based growth fund with a 31 percent limited partner commitment from a sovereign wealth fund, proposes to lead a $90 million round for 22 percent, with one board seat and standard information rights.
Tessaly's counsel, Marguerite Okwuosa-Bell, runs the analysis.
Is it a covered transaction? Ardencote is a foreign person. 22 percent with a board seat is unlikely to be control — no veto rights, no ability to determine important matters. But it is plainly a covered investment if Tessaly is a TID business: Ardencote gets a board seat, which satisfies the access criterion by itself.
Is Tessaly a TID business? The critical technology analysis produces nothing — the risk-scoring model is not on either control list. Critical infrastructure: no. Sensitive personal data: yes, clearly. Tessaly maintains health data on more than one million individuals. It is a TID business.
Is the filing mandatory? Two tests.
Substantial interest test: Ardencote will hold 22 percent, below the 25 percent threshold for a substantial interest in the U.S. business. Not triggered — but Marguerite notes that this is a two-point margin and that any structure change, follow-on, or anti-dilution adjustment could cross it. She flags it for the term sheet.
Critical technology test: No critical technology. Not triggered.
Filing is therefore voluntary. Should they file?
Arguments for filing:
- Sensitive personal health data on 4.3 million U.S. persons is exactly the vulnerability FIRRMA was designed to address.
- A sovereign wealth fund LP at 31 percent is a threat factor the Committee will want to examine.
- Without clearance there is no safe harbor, and the review authority is indefinite.
- The non-notified program actively identifies transactions like this.
- Tessaly's next financing, sale, or IPO will face a diligence question about unfiled CFIUS exposure, and the answer "we did not file" is worth less than a clearance letter.
Arguments against:
- Three to six months of delay and $400,000 to $900,000 in cost.
- A risk of mitigation that limits Ardencote's board access to data — the very thing Ardencote wants.
Marguerite's recommendation: file a declaration. The facts are clean, the investment is non-controlling, there is no critical technology, and the sovereign LP relationship is at the fund level rather than at the general partner level.
What happened. The declaration was filed. On day 28, the Committee requested a full written notice — the sovereign LP relationship and the health data volume together warranted more examination than a declaration permits.
The notice. Filed after a four-week pre-filing draft period. Two rounds of questions focused on: the general partner's independence from the sovereign investor, the sovereign investor's information rights in the fund, Tessaly's data architecture and where the data physically resides, and whether Ardencote's board designee would have access to individual-level data.
The outcome. Cleared with a letter of assurance rather than a full NSA, containing four commitments: Tessaly maintains all U.S. person data on U.S.-based infrastructure; the board designee receives aggregated and de-identified reporting only, with no access to individual-level records; Tessaly maintains a written data access policy and provides an annual certification of compliance; and Tessaly notifies the Committee before any change in Ardencote's rights or ownership percentage.
Elapsed time: five months from engagement to clearance. Cost: roughly $610,000 in legal and consulting fees.
Marguerite's note to the file: "The declaration was the right first move even though it did not clear. It cost thirty days and it produced a Committee that already understood the transaction when we filed the notice. And the four commitments were things Tessaly should have been doing anyway."
Deal documents
CFIUS risk is allocated in the purchase agreement, and the allocation is worth real money.
The closing condition. Where a filing will be made:
CFIUS Approval. "CFIUS Approval" means (a) the Parties have
received written notice from CFIUS that it has concluded all
action under Section 721 with respect to the Transaction and
determined that there are no unresolved national security
concerns; (b) CFIUS has sent a report to the President
recommending no action and the period for Presidential action
has expired without action; or (c) the President has announced
a decision not to exercise authority under Section 721.
The efforts covenant. The most heavily negotiated CFIUS provision.
- "Commercially reasonable efforts" — weakest, buyer-favorable.
- "Reasonable best efforts" — the common middle.
- "Best efforts," with a hell-or-high-water commitment — the buyer must accept any mitigation, including divestiture. Sellers ask for it; buyers resist strongly, because CFIUS mitigation can include a proxy structure or a required divestiture that destroys the deal's rationale.
- A qualified commitment is the workable compromise: the buyer accepts mitigation up to a defined limit — no divestiture of specified businesses, no proxy or voting trust, no measure that would reduce the acquired business's EBITDA by more than a stated amount, no measure applying to the buyer's other operations.
Draft the limit as objectively as possible. "Burdensome condition" undefined is an invitation to litigate; a list of specific measures the buyer need not accept is not.
The outside date. CFIUS timelines are unpredictable, and pull-and-refile cycles add months. An outside date of nine to twelve months is realistic for a transaction with real issues; six months is optimistic.
The reverse termination fee. Where the buyer walks because it will not accept mitigation, or where CFIUS blocks the transaction, sellers negotiate a fee. In transactions with meaningful CFIUS risk, 3 to 8 percent of equity value is a range that appears, and it is one of the clearest signals of how the parties actually assess the risk.
Cooperation covenants. Both sides must supply information, and the U.S. business supplies most of it. Provide for: prompt responses to Committee questions; sharing of draft submissions; no communication with the Committee without the other party's participation (with a carve-out for the acquirer's confidential ownership information); and allocation of filing fees and advisor costs.
Representations. From the seller: the technology classification, the government contracts, the data holdings, the facility locations, and any prior CFIUS history. From the buyer: its ownership chain, its foreign government relationships, and its own CFIUS and enforcement history. These are diligence questions that belong in the agreement because the answers determine whether the filing succeeds.
Where CFIUS shows up unexpectedly
Venture financings. A single foreign LP in a fund, a foreign strategic investor taking a board observer seat, or a foreign angel with information rights can create a covered investment in a TID business. Companies handling significant consumer data should analyze every round.
Follow-on rounds and conversions. A convertible note that converts, a warrant that exercises, or an anti-dilution adjustment can cross the 25 percent substantial-interest threshold and convert a voluntary situation into a mandatory one.
Restructurings and internal reorganizations. A change in rights that gives a foreign parent new governance authority is a covered transaction.
Bankruptcy sales. A § 363 sale to a foreign buyer is a covered transaction, and the compressed bankruptcy timetable sits badly with a 105-day statutory clock. Raise it at the outset of the sale process.
Real estate. Leases and concessions count. A logistics company leasing a warehouse near an airfield, or a data center developer buying land within 100 miles of a listed installation, is in Part 802 territory.
Employment of foreign nationals. Not a CFIUS matter directly, but the deemed export rules under the EAR are analytically adjacent and frequently arise in the same diligence.
Government contractors of any size. A small business with a classified contract has a vulnerability profile out of proportion to its revenue.
What to do in a transaction with any foreign element
One — screen at the term sheet stage. Three questions: Is any party a foreign person, directly or through its ownership chain? Is the U.S. business a TID business? Will the foreign person obtain control, board access, or information rights? If any answer is yes, get CFIUS counsel involved before the LOI.
Two — do the export control classification early. It determines whether a filing is mandatory, and it takes weeks.
Three — map the acquirer's ownership chain to natural persons or governments. This is the longest lead item in most filings, and funds with many limited partners take months to document.
Four — decide declaration versus notice deliberately. A declaration is fast and cheap where the facts are clean and the acquirer is low-threat. It is thirty wasted days where they are not.
Five — build the timeline into the deal. Outside dates, financing commitments, and employee retention arrangements all need to survive a process that may take seven months.
Six — negotiate the efforts covenant and the reverse termination fee as a package. They price the same risk from opposite directions.
Seven — assume the review is a conversation, not a filing. The Committee's questions are the process. Parties that answer promptly, completely, and consistently do better than parties that treat each response as an advocacy exercise.
Eight — if you did not file and should have thought about it, do the analysis now. The non-notified program is real, the review authority is indefinite, and a voluntary filing made before an inquiry is a materially better posture than one made after.
The non-notified program
CFIUS has built a standing capability to find transactions nobody told it about, and it is the development most likely to affect ordinary practice.
How transactions are identified: press reports and deal databases; government contract and grant records; export license applications; securities filings; tips from competitors, employees, and agencies; and referrals from other parts of the government.
What an inquiry looks like. A letter from the Treasury staff asking whether a described transaction occurred and requesting information sufficient to determine whether it was a covered transaction. Responses are voluntary in form and functionally not optional.
The possible outcomes: the Committee concludes the transaction was not covered; concludes it was covered but presents no unresolved national security concern and takes no further action; requests a filing; or opens a unilateral review that can end in mitigation or a referral to the President.
What to do on receiving one. Engage counsel immediately, preserve documents, answer accurately and completely, and do not volunteer the argument that the transaction was outside jurisdiction unless it plainly was. Parties that respond promptly and cooperatively have generally fared better than parties that litigate the threshold.
And the prophylactic point. A company that has closed a transaction with a foreign investor and never analyzed CFIUS should do the analysis now, in privilege, and decide whether a voluntary filing is warranted. A voluntary filing that precedes an inquiry is a materially better posture than one that follows it — and if the filing was mandatory, the penalty exposure is measured by the value of the transaction.
Frequently asked questions
Is a 15 percent investment reviewable? Possibly, in two ways. It can be a covered control transaction if the governance rights amount to control, since there is no percentage threshold. And it is a covered investment if the target is a TID business and the investor gets board access, technical information access, or substantive involvement in decisions about technology, infrastructure, or data.
Our company holds consumer data. Are we a TID business? If you maintain or collect sensitive personal data on more than one million U.S. individuals in the preceding twelve months, or you target U.S. government or military personnel, then yes. Health, financial, geolocation, biometric, and communications data all count.
How long does a filing take? A declaration is 30 days from acceptance. A notice is 45 days of review plus, commonly, 45 days of investigation, preceded by two to eight weeks of pre-filing. Three to seven months elapsed is realistic; pull-and-refile adds more.
What does it cost? $250,000 to $1.5 million in legal and consulting fees for a notice, depending on complexity. Filing fees are tiered by transaction value and are meaningful for large deals. A declaration is substantially less.
Can we close before clearance? Legally, yes, for a voluntary filing — but you close without a safe harbor and with indefinite review exposure. For a mandatory filing, closing before the Committee concludes action exposes you to penalties. Most sophisticated parties make clearance a closing condition.
Are we excepted because our investor is British? Only if the investor satisfies the detailed excepted-investor tests, which many funds and public companies fail because of the 10 percent limits on non-excepted foreign holders. And the exception never applies to covered control transactions.
We closed two years ago and never filed. What now? Do the analysis in privilege. If the filing would have been mandatory, the penalty exposure runs to the value of the transaction and a voluntary filing is almost certainly the right course. If it was voluntary, weigh the indefinite review exposure and the diligence question your next financing will ask.
Is CFIUS a competition regulator? No. Its mandate is national security only. HSR and the antitrust agencies are a separate process on a separate timeline, and a transaction can clear one and fail the other.
Can we appeal a decision? The President's action and findings are not subject to judicial review. Procedural due process challenges to the process have been entertained; the substantive determination has not. The process is your only real opportunity.
What is the single most common mistake? Doing the export control classification too late. It determines whether the filing is mandatory, it takes weeks, and finding out in month three that a filing was required in month one is an expensive discovery.
The wider trend
CFIUS is one instrument in a broader shift, and the transactional lawyer should see the pattern rather than the single tool.
Outbound investment review. A regime restricting certain U.S. investments into specified countries in semiconductors, quantum information technologies, and artificial intelligence now operates alongside inbound review. Deals that would have raised no U.S. regulatory question a few years ago now require analysis in both directions.
Data-focused restrictions. Rules restricting bulk transfers of sensitive personal data and government-related data to countries of concern operate independently of CFIUS and reach commercial arrangements — vendor agreements, cloud contracts, employment — not just investments.
Export controls have expanded into areas of dual-use technology that were previously uncontrolled, and the entity-based controls in 15 C.F.R. Part 744 reach further into ordinary supply chains.
Allied regimes. The European Union's screening framework, the United Kingdom's National Security and Investment Act, and comparable statutes in Australia, Canada, Japan, and elsewhere mean a cross-border transaction may need several filings, with different thresholds, different timelines, and different substantive standards. Sequence them deliberately; approvals in one jurisdiction sometimes inform another.
The practical implication for a transactional practice. National security review has moved from a specialty concern in defense and infrastructure deals to a screening question in any transaction with a foreign element and any business holding technology, data, or infrastructure. The screening takes an hour. Discovering the issue after closing takes years.
Related documents
- Preparing a CFIUS Filing: A Practical Guide
- CFIUS Filing Checklist: A Practical Checklist
- Foreign Investment Review Toolkit: Declarations, Notices, and Mitigation Agreements
- Export Controls and Economic Sanctions: The EAR, ITAR, and OFAC for Ordinary Businesses
- Negotiating the Indemnity Package in a Deal: A Practical Guide
- HSR Premerger Notification: When a Deal Must Be Reported and What Happens Next
- Purchase Agreement Review Checklist: A Practical Checklist
This article is general information, not legal advice, and does not create an attorney-client relationship.
