The Committee on Foreign Investment in the United States, universally known as CFIUS, is an interagency committee of the U.S. government that reviews certain foreign investments in U.S. businesses to assess their implications for national security. CFIUS has the authority to require mitigation measures to address identified security risks, and in some cases to recommend that the President block or require divestment of a transaction. Understanding whether a proposed transaction is subject to CFIUS jurisdiction, whether a filing is required or advisable, and what the review process involves is essential for both foreign buyers and U.S. sellers in any transaction that touches the national security considerations that CFIUS is designed to address.
Which Transactions Are Subject to CFIUS Jurisdiction
CFIUS reviews covered transactions, which is a defined statutory concept. A covered transaction includes: (1) a covered control transaction — any transaction through which a foreign person could acquire, directly or indirectly, control of a U.S. business; (2) a covered investment — a non-controlling foreign investment in a TID U.S. business (as defined below) that gives the foreign investor access to material nonpublic technical information, board membership or observer rights, or involvement in substantive decision-making about specified categories of sensitive matters; and (3) certain real estate transactions involving foreign persons acquiring an interest in real property in proximity to U.S. government facilities or in sensitive locations.
The concept of control is broad and not limited to majority ownership. A foreign person who can direct or decide important matters affecting a U.S. business — through equity ownership, contractual rights, board representation, veto rights, or otherwise — may be deemed to have control even with less than 50 percent of the equity. This means that minority investments, joint ventures, and long-term commercial arrangements with foreign entities can be subject to CFIUS review in appropriate circumstances.
TID U.S. Businesses and Sensitive Industries
The Foreign Investment Risk Review Modernization Act of 2018 (FIRRMA) expanded CFIUS jurisdiction to cover non-controlling investments in TID U.S. businesses — businesses involved in critical technology, critical infrastructure, or sensitive personal data. Critical technology includes items controlled under the Export Administration Regulations, the International Traffic in Arms Regulations, and certain other regulatory regimes, as well as technology that is emerging or foundational and subject to export control review. Critical infrastructure includes systems and assets whose incapacitation or destruction would have a debilitating effect on national security, including energy systems, telecommunications networks, water systems, financial infrastructure, and transportation networks. Sensitive personal data includes data on U.S. citizens including financial, health, geolocation, biometric, genetic, and other categories of data that could be exploited by a foreign adversary.
For technology companies, the critical technology category is particularly significant. Companies that develop, manufacture, test, or produce items subject to export controls — including semiconductor technology, defense electronics, advanced materials, cybersecurity technology, and artificial intelligence applications — are likely TID U.S. businesses. Any foreign investment in these companies, even a minority investment, may be subject to mandatory CFIUS filing requirements.
Mandatory vs. Voluntary Filings
CFIUS filings can be either mandatory or voluntary. Mandatory filings are required by regulation for certain categories of transactions and must be submitted before the transaction is completed. Mandatory declarations (a short-form notice) are required for foreign investments that result in foreign government ownership of certain percentages of critical technology companies, certain investments involving foreign persons from countries with CFIUS agreements, and other specified circumstances. Failure to submit a mandatory declaration when required can result in civil penalties of up to the value of the transaction.
Voluntary filings are a full notice submitted to CFIUS at the parties’ option for transactions that do not trigger mandatory declaration requirements but that may present national security concerns. Even when filing is voluntary, parties typically choose to file because completing a CFIUS review (obtaining clearance or being advised that CFIUS has no objection) provides immunity from subsequent CFIUS action with respect to the reviewed transaction. Parties who close a covered transaction without filing, and who are later investigated by CFIUS on a post-closing basis, face the possibility of being required to unwind the transaction — a potentially catastrophic outcome.
The Review Process and Mitigation Agreements
The CFIUS review process has two phases: an initial 30-day review period following submission of a complete notice or declaration, and a 45-day investigation period that is triggered if CFIUS determines that the transaction poses a potential national security risk that requires further analysis. The President has 15 days following a completed investigation to take action to block or impose conditions on the transaction. In practice, most transactions are resolved during the review or investigation period rather than escalating to presidential action.
When CFIUS identifies national security concerns, it works with the parties to develop a national security agreement or mitigation agreement that imposes conditions designed to reduce or eliminate the identified risks. Typical mitigation measures include: restrictions on the foreign investor’s access to sensitive technology, data, or physical facilities; board seat limitations and exclusion of the foreign investor from certain board committees; requirements for U.S. citizens to serve in specific security-sensitive management roles; information security protocols and compliance monitoring; restrictions on the sharing of technical information with affiliated foreign parties; and ongoing reporting and audit requirements. CFIUS retains the right to monitor compliance with mitigation agreements and to take enforcement action if the parties violate their terms.
How CFIUS Risk Affects Deal Structure and Price
CFIUS risk affects deal dynamics in several important ways. First, the identity of the buyer matters enormously: a U.S.-based private equity firm with no foreign investors in a sensitive industry is unlikely to face CFIUS issues, while a Chinese state-owned enterprise acquiring a U.S. defense technology company will face mandatory review and significant clearance risk. Sellers who are running a competitive process should assess which buyers present CFIUS risk and factor that risk into their evaluation of competing bids. A higher-priced bid from a foreign buyer that faces uncertain CFIUS clearance may be worth less on a risk-adjusted basis than a lower-priced bid from a domestic buyer with no CFIUS exposure.
Second, the purchase agreement must allocate CFIUS risk between the parties. Sellers should negotiate for the buyer to bear the cost and risk of obtaining CFIUS clearance, including: an obligation to use best efforts to obtain clearance, an obligation to accept reasonable mitigation conditions, a reverse termination fee payable by the buyer if CFIUS blocks the transaction or if the buyer refuses to accept conditions that CFIUS imposes, and a separate outside date that accounts for the CFIUS review timeline. Buyers who cannot commit to these terms should be viewed with skepticism about their genuine confidence in their ability to obtain CFIUS clearance.
