Document type: Checklist Practice area: Business and Corporate — Regulatory Jurisdiction: United States Last reviewed: 5 September 2026


Part 1 — Term sheet screen (one hour, week zero)

  • Is any party a foreign person, directly or anywhere in its ownership chain?
  • Is the target a U.S. business — any entity engaged in interstate commerce in the United States?
  • Will the foreign person obtain control — the power to determine, direct, or decide important matters? (No percentage threshold applies.)
  • Is the target a TID U.S. business?
    • Critical technology — anything on the United States Munitions List or controlled on the Commerce Control List for national security, chemical and biological weapons, nuclear nonproliferation, missile technology, regional stability, or surreptitious listening reasons; nuclear items; select agents; emerging or foundational technologies.
    • Critical infrastructure — within the enumerated categories in the appendix to 31 C.F.R. Part 800, applying the functional tests.
    • Sensitive personal data — one of the ten categories, on more than one million U.S. individuals in the preceding twelve months, or targeting U.S. government or military personnel.
  • Will the foreign person obtain board membership or observer rights, the right to nominate a director, access to material non-public technical information, or substantive involvement in decisions about technology, infrastructure, or data?
  • Is any real estate involved that is at or functions as part of a covered port, within one mile of a listed installation, or within an extended range zone under 31 C.F.R. Part 802?
  • If any answer is yes, engage CFIUS counsel before the LOI is signed.

Part 2 — Mandatory filing determination

Test 1 — substantial interest:

  • Will the foreign person hold 25 percent or more of the voting interest in a TID U.S. business?
  • Does a foreign government hold 49 percent or more of the voting interest in that foreign person, directly or indirectly?
  • Apply the look-through rules for funds and partnerships.
  • Assess whether the general partner is genuinely independent of any sovereign limited partner; document the analysis.
  • Check whether follow-on rights, anti-dilution, or conversion could push the stake over 25 percent later.

Test 2 — critical technology (start in week one):

  • Classify every product, software, and technology: ECCN, or USML category.
  • Identify the direct acquirer and every person in the ownership chain holding 25 percent or more voting interest.
  • Determine each such person's country.
  • Determine whether a U.S. regulatory authorization would be required to export, reexport, transfer, or retransfer the item to that country and that end user, accounting for reasons for control, license exceptions, and the end-user and end-use controls in 15 C.F.R. Part 744.
  • Document the analysis in a memorandum, whichever way it comes out.

If mandatory:

  • File at least 30 days before closing.
  • Do not close before the Committee concludes action; penalties run to the value of the transaction.

Part 3 — If voluntary, decide

File when:

  • Sensitive data, critical infrastructure, government contracts, classified work, or facility proximity creates real vulnerability.
  • The acquirer has any state linkage.
  • A safe harbor matters for a future financing, sale, or IPO.
  • The parties want certainty rather than speed.

Consider not filing when:

  • The business is plainly outside every TID category.

  • The acquirer is plainly low-threat and the rights are genuinely passive.

  • The parties accept the residual exposure.

  • Whatever you decide, write the privileged memorandum now.


Part 4 — Excepted investor analysis

  • Is the investor organized under the laws of an excepted foreign state or the United States?
  • Is its principal place of business in an excepted state or the United States?
  • Do the required percentages of its board and voting interests belong to nationals of excepted states or the United States?
  • Does no single non-excepted foreign person hold 10 percent or more, and do non-excepted foreign persons not hold 10 percent or more in the aggregate on the applicable measures?
  • Is the investor and its related persons free of the specified adverse CFIUS or enforcement history over the preceding five years?
  • Remember that the exception never applies to covered control transactions.
  • Document the analysis; do not assume excepted status.

Part 5 — Ownership chain (start day one; this is the critical path)

For the acquirer and every entity in the chain:

  • Full legal name, jurisdiction and date of organization, principal place of business.
  • Ownership percentages at every tier, up to natural persons or governments.
  • Organizational chart.
  • For funds: general partner, management company, limited partners above the thresholds, governance arrangements.
  • Any government ownership at any tier, at any percentage, in any country.
  • Any government control rights, golden shares, or special rights.

For each individual above the thresholds and each director and officer:

  • Full name including all names used.
  • Date and place of birth.
  • National identification and passport numbers.
  • Addresses for the required period.
  • Employment history.
  • Travel history, where required.

Process:

  • Secure collection portal established, with an explanation of the legal basis and handling protections.
  • One accountable person designated on the acquirer's side, with authority to escalate.
  • Tracker built; weekly reporting to the deal team.
  • Escalation path agreed for individuals who do not respond.

Part 6 — The U.S. business record

  • Corporate organization, capitalization, cap table.
  • Description of every product and service line.
  • Technology classification memorandum with ECCNs.
  • Every government contract: agency, value, term, classified status.
  • Facility list with addresses, and distances to listed military installations.
  • Data holdings: categories, volumes, U.S. person counts, storage locations, access.
  • Customer list, with government customers identified.
  • Supply chain: sole-source positions and government or critical infrastructure dependencies.
  • Employee population by citizenship (also a deemed export question under the EAR).
  • Any prior CFIUS filings and outcomes.
  • Any export control, sanctions, or security enforcement history.

Part 7 — The transaction description

  • Structure, consideration, and percentages before and after.
  • Every governance right, quoted from the documents: board seats, observer rights, nomination rights, consents, vetoes, information rights.
  • Post-closing integration plans, including any transfer of technology, personnel, or data.
  • Any shareholders' or side agreements.
  • The buyer's stated intentions for the business.
  • Consistency check against the purchase agreement, shareholders' agreement, board resolutions, and any prior statement to the Committee.

Part 8 — Declaration or notice

Choose a declaration when:

  • Low-threat acquirer, no state linkage.
  • Short, easily described ownership chain.
  • Modest vulnerability profile; no critical technology, classified work, or listed-installation proximity.
  • Limited rights obtained.
  • Speed matters more than certainty.

Choose a notice when:

  • Any party is state-owned or state-linked.
  • Critical technology, classified contracts, or large sensitive data holdings.
  • Complex ownership chain.
  • Mitigation is foreseeable — a declaration cannot produce a mitigation agreement.

Part 9 — Filing

  • Pre-filing draft submitted (two to eight weeks; not counted in any statutory period).
  • Staff comments received and addressed completely.
  • Filing fee confirmed against the current tiered schedule and paid.
  • Fee allocation between the parties confirmed per the purchase agreement.
  • Certifications executed by an authorized officer of each party — these carry criminal exposure for material misstatements.
  • Submission made through the CFIUS case management system.
  • Acceptance confirmed in writing; the clock starts on acceptance.
  • Clock diarized: 30 days (declaration); 45 days review plus possible 45 days investigation (notice); 15 days Presidential.

Part 10 — Managing the review

  • Question log established: date received, deadline, owner, response date.
  • Every response complete on the first pass.
  • Every response cross-checked against the filing and prior responses.
  • No advocacy in factual responses.
  • Escalation path in place for questions requiring engineering or foreign parent input.
  • Technical and business witnesses prepared for staff calls: know the filing, answer within knowledge, do not speculate.
  • Site visit arrangements, where applicable.
  • Any material change in the business during the review disclosed promptly.
  • Pull-and-refile decision framework agreed in advance, and the client told it may happen.

Part 11 — Mitigation

Before it is proposed:

  • Rank possible measures: acceptable and cheap; acceptable but costly; serious; deal-changing.
  • Confirm the limit defined in the purchase agreement's efforts covenant.
  • Model the ongoing compliance cost of each category.

In negotiation, push for:

  • Objective standards rather than agency discretion.
  • Notice rather than approval wherever possible.
  • Defined cure periods.
  • A term or a review-and-sunset mechanism.
  • Clarity on which agency decides what, and a single point of contact.
  • Reasonable audit scope, frequency, and cost caps.
  • Confidentiality for the agreement and information provided under it.

Before closing, build the program:

  • Compliance officer appointed and named in the agreement.
  • Security plan and required policies drafted.
  • Access controls and network segregation configured.
  • Covered personnel trained; training documented.
  • Reporting calendar built: quarterly reports, annual certifications, notice triggers.
  • A single owner assigned who will still be in the role in three years.

Part 12 — Deal document provisions

  • "CFIUS Approval" defined precisely as a closing condition.
  • Efforts covenant with an objectively defined limit on the mitigation the buyer must accept: no divestiture of the buyer's other businesses, no proxy or voting trust, no divestiture above a stated revenue threshold, no EBITDA impact above a stated amount, no measures applying outside the United States.
  • Outside date of nine to twelve months, with an extension mechanism.
  • Reverse termination fee, with precisely defined triggers.
  • Cooperation covenants: prompt responses, draft sharing, joint communications with a carve-out for confidential ownership information, cost allocation.
  • Seller representations: technology classification, government contracts, data holdings, facility locations, prior CFIUS history.
  • Buyer representations: ownership chain, foreign government relationships, enforcement history.
  • Interim covenants restricting new controlled technology, new classified work, and facility relocation during the review.

Part 13 — Non-notified inquiry response

  • Engage CFIUS counsel on day one; do not respond substantively first.
  • Issue a litigation hold covering the transaction, the diligence, and any CFIUS analysis.
  • Locate any contemporaneous analysis of whether a filing was required.
  • Reconstruct the facts: rights obtained, TID status at the time, vulnerability profile.
  • Determine whether the filing was mandatory; if so, evaluate voluntary disclosure and expect penalty exposure up to the transaction value.
  • Respond promptly, completely, and accurately.
  • Prepare the client for the possibility of mitigation on a closed transaction.

Part 14 — Post-closing compliance

  • Every obligation in the agreement mapped to an owner and a date.
  • Reporting calendar in the compliance system, not in someone's inbox.
  • Annual certification prepared with supporting evidence, not from memory.
  • Notice triggers understood by the people who would cause them: HR (director and officer changes), facilities (relocations), product (new lines), corporate development (ownership changes).
  • Training refreshed annually.
  • Audit readiness maintained.
  • Any new investment, follow-on round, or change in rights re-analyzed — clearance covers only the transaction as described.

Related documents


This checklist is general information, not legal advice, and does not create an attorney-client relationship.