United States: CFIUS Review

In summary

Foreign investment review in the United States has expanded in recent years through the Committee on Foreign Investment in the United States’ (CFIUS) increased authority to review transactions and more frequent requests for in-depth review. Since Congress passed the Foreign Investment Risk Review Modernization Act of 2018, the foreign investment filing requirements continue to change to reflect those legislative reforms through regulations implementing CFIUS’ more expansive authority and jurisdiction. While CFIUS filings traditionally have been voluntary, these legislative reforms have introduced a mandatory filing requirement for certain transactions and increased CFIUS’ focus on all transactions that could raise national security concerns.

Discussion points

  • Legislation introducing mandatory filing requirement for certain transactions and expanding CFIUS’ authority
  • Voluntary filing to obtain safe harbour for transactions
  • Streamlined ‘declaration’ process
  • CFIUS member agencies significantly increase staffing
  • CFIUS devoting increased resources to case processing and monitoring and enforcement of compliance

National security review

The national security review process in the United States, conducted by the Committee on Foreign Investment in the United States (CFIUS), has existed for decades. It originally focused, at least in practice, on the acquisition by foreign companies of US businesses directly or indirectly supplying the US Department of Defense, but, especially after the 9/11 terrorist attacks, the concept of national security – and therefore the types of transactions subject to review under the regime – was broadened by statute and in practice. National security is an ever-evolving concept, and its expansion in recent years has been fuelled by rapid advancements in technology, increasing digitalisation, increasingly globalised supply chains, and the appearance of China as a significant investor and technological competitor. Most recently, concerns over healthcare supplies in the wake of the coronavirus pandemic have brought attention to national security risks inherent in the global healthcare supply chain.

These developments prompted CFIUS to become much more active in recent years, and led Congress to pass the Foreign Investment Risk Review Modernization Act of 2018 (FIRRMA), which was the most sweeping reform of CFIUS in the past 30 years. FIRRMA significantly expanded CFIUS’ jurisdiction, implemented a number of process changes, and strengthened CFIUS’ authorities, such as the authority to share information with foreign governments, mandate filings, enforce voluntary divestments, enforce mitigation and fund operations. Since Congress passed FIRRMA, CFIUS has issued a series of implementing regulations bringing these changes into effect. 1 Additionally, funding authorised by FIRRMA is enabling CFIUS to devote more resources to identifying transactions that are not notified by the parties, leading to an increase in the number of cases subject to CFIUS’ ‘call in’ authority.

Especially in light of FIRRMA, CFIUS has become an important determinant of the success or failure of many transactions. It is important for parties to transactions to consider whether to file with CFIUS because, in some instances as a result of FIRRMA, the submission of a filing is mandatory, and even where there is no mandatory filing, CFIUS has broad authority to act on unreviewed transactions even after they have closed.

Although submitting a transaction to CFIUS for national security review has historically been voluntary, FIRRMA established, for the first time, a mandatory filing requirement for investments involving foreign governments and gave CFIUS the discretion to define other circumstances in which a transaction must be filed with CFIUS. 2 Parties can be fined up to the transaction value for failure to file when required. 3 Specifically, as now provided in regulation, a filing is mandated if, subject to certain exceptions, a foreign person in which a foreign government holds a 49 per cent or greater interest, acquires a 25 per cent or greater interest in a US business involved with ‘critical technology’ or ‘critical infrastructure’, or that holds ‘sensitive personal data’, terms that are defined in the regulations. CFIUS has also exercised its discretion to require that foreign persons, subject to certain exceptions, submit a filing to CFIUS if their transaction involves a controlling or otherwise non-passive investment (ie, an investment that provides the investor with certain rights, such as board representation or certain governance or access rights) in a US business that (i) is involved with a ‘critical technology’ and (ii) the critical technology cannot be exported to the foreign investor (or anyone holding a 25 per cent or greater interest, direct or indirect, in the foreign acquirer) without US government export authorisation. 4

Even when the mandatory filing requirement is inapplicable, parties may still choose voluntarily to submit a notice for review with respect to any transaction subject to CFIUS’ jurisdiction. The risk of not submitting a notice voluntarily can be substantial, because CFIUS can take action even after the parties close the transaction, up to and including recommending that the President order the foreign owner to divest the acquired interest. The President has formally ordered the divestment or prohibition of only six transactions since the relevant statute was adopted in 1988. 5 However, foreign owners have agreed to voluntarily divest their interest in a US business in many instances in light of CFIUS opposition, before CFIUS referred the transaction to the President for a formal order of divestment. Between 2015 and 2019, although the President only formally blocked four transactions, 56 transactions were abandoned in light of CFIUS-related national security concerns, including where CFIUS imposed conditions that the parties found unacceptable. 6 For instance, in 2019, China-based Beijing Kunlun Tech Co Ltd entered into an agreement with CFIUS to divest the online dating site, Grindr LLC, because of data security concerns after Kunlun acquired control of Grindr without advance CFIUS review. 7 In such a circumstance, the foreign person may not be able to recoup the original value of its investment.

Notification and CFIUS clearance may also insulate parties to a transaction from public and political criticism that the transaction threatens US national security. Consequently, companies should consider the national security implications of cross-border transactions and draft appropriate provisions in transaction documents to address, among other things, conditions to closing, cooperation and risk-sharing.

What is the regulation and who administers it?

The US national security review process is conducted pursuant to section 721 of the Defense Production Act of 1950 (section 721), as amended (most recently by FIRRMA). 8 Section 721 grants the President the authority to suspend or prohibit in whole or in part certain enumerated transactions if they threaten to impair the national security of the United States.

CFIUS is charged with conducting the national security review on behalf of the President pursuant to section 721 and, as appropriate, making a recommendation regarding presidential action. CFIUS is an interagency committee consisting of, as chair, the Secretary of the Treasury and, as members, the Secretaries of Commerce, State, Defense, Homeland Security and Energy, as well as the Attorney General, the United States Trade Representative and the Director of the Office of Science and Technology Policy. The Secretary of Labor and the Director of National Intelligence serve as ex officio members. Certain other White House officials, such as Chair of the Council of Economic Advisors, the Director of the Office of Management and Budget, the Assistant to the President for National Security Affairs and the Assistant to the President for Economic Policy, observe and, as appropriate, participate in CFIUS’ activities. 9

In practice, CFIUS operates through staff representatives from each of the CFIUS member agencies, although section 721 strictly limits the ability of members to delegate authority for certain decisions. CFIUS reaches decisions by consensus, but certain actions may be triggered by an individual member agency.

What is national security?

Section 721 does not define ‘national security’, but specifies that CFIUS, at a minimum, may consider the following factors:

  • domestic production needed for projected national defence requirements;
  • the capability and capacity of domestic industries to meet national defence requirements, including the availability of human resources, products, technology, materials, and other supplies and services;
  • the control of domestic industries and commercial activity by foreign citizens as it affects the capability and capacity of the United States to meet the requirements of national security;
  • whether the transaction is a foreign government-controlled transaction;
  • whether the transaction involves a country that does not adhere to non-proliferation regimes or cooperate on counterterrorism efforts, presents a risk for transhipment or diversion of technologies,
  • the potential effects of the proposed or pending transaction on sales of military goods, equipment or technology to any country:
    • identified by the Secretary of State as a country that supports terrorism, is a country ‘of concern’ regarding missile proliferation or the proliferation of chemical and biological weapons, or is listed on the Nuclear Non-Proliferation Special Country List; or
    • that poses a potential regional military threat to the interests of the United States;
  • the potential effects of the proposed or pending transaction on US international technological leadership in areas affecting US national security; and
  • the potential for national security-related effects from the acquisition of US critical technologies and infrastructure, including energy. 10

Critical technologies are defined by reference to a number of export control regulations, including, among others, the International Traffic in Arms Regulations and the Export Administration Regulations. 11 Companion export control reform legislation enacted along with FIRRMA provides that critical technologies will be expanded to include ‘emerging and foundational technologies’ as classified by the US Department of Commerce. 12 Critical infrastructure is defined as those systems and assets, whether physical or virtual, that are so vital to the United States that the incapacity or destruction of such systems or assets would have a debilitating impact on national security. 13 The CFIUS regulations include a subset of designated critical infrastructure, the acquisition of which may be subject to a mandatory filing requirement as discussed below.

What is a covered transaction?

The definition of a ‘covered transaction’ was substantially revised by FIRRMA. Pre-FIRRMA, a covered transaction was any transaction by or with a foreign person that could result in foreign control (direct or indirect) of a US business, 14 including a transfer of control of a US business from one foreign person to another. Post-FIRRMA, a covered transaction includes (i) ‘covered control transactions’, which are transactions 15 that could result in foreign control of a US business, (ii) ‘covered investments’, which are non-passive investments (not amounting to control) in US businesses that are involved in critical infrastructure, critical technologies or sensitive personal data (TID US Businesses), 16 and (iii) ‘covered real estate investments’, which are stand-alone acquisitions, leases or concessions of real estate in certain instances, even if the transaction does not involve the acquisition of an existing US business. 17 Covered investments are defined by reference to access and governance rights rather than a specific investment percentage.

Each of these terms is further defined in the regulations.

The concept of control is broader than in the US antitrust context, because it is based on function rather than structure. Control turns on the ability to determine, direct or decide important matters affecting an entity, and the regulations specifically recognise control through a dominant minority position. 18 In practice, CFIUS interprets control very broadly. An investor, for example, could be determined to have control of a US business if it has consent rights or the ability to block decisions on important matters. Certain minority investor protections, such as anti-dilution rights, are not deemed to be control rights, but not all investor protections necessarily qualify for this exception.

An investment in the context of a covered investment means an acquisition of an equity interest, including a contingent equity interest, and a covered investment subject to jurisdiction includes any non-passive investment of any level or amount that affords the foreign person certain governance (eg, the right to appoint a board observer) or access rights.

Foreign persons include any foreign national, foreign government or foreign entity, or any entity over which control is exercised or exercisable by a foreign national, foreign government or foreign entity. 19

A US business is one engaged in interstate commerce in the United States and thus is not limited to businesses incorporated in the United States. 20

‘Excepted investors’ from ‘excepted foreign states’ are not subject to CFIUS’ expanded jurisdiction over covered investments and covered real estate transactions. Excepted foreign states currently include Australia, Canada and the UK, but not all investors from such states qualify as excepted investors. The criteria for a company from an excepted foreign state to qualify as an excepted investor relate to place of incorporation, principal place of business, composition of ownership and board membership. 21 Foreign government investors and closely held companies have a greater likelihood of qualifying than public companies. The list of excepted foreign states is subject to change, different lists may be applicable for business versus land acquisitions, and whether a specific investor qualifies may also change over time. Therefore, the scope of excepted investors is dynamic rather than static.

Is a filing mandatory?

Only certain transactions falling within CFIUS’ jurisdiction must be notified to CFIUS. Post-FIRRMA regulations provide that certain acquisitions of, or investments in, US businesses involved in critical infrastructure, critical technology or sensitive personal data must be notified to CFIUS. 22 Excepted investors are not subject to the mandatory filing requirement, 23 and there are other limited exemptions in the regulations. Real estate transactions are not subject to any mandatory filing obligation.

Specifically, parties to a transaction must submit a filing to CFIUS – whether a declaration or notice, as discussed below – when the relevant US business manufactures, produces, fabricates, develops, tests or designs critical technology (defined with reference to whether a US government export authorisation is needed to export the relevant technology to the foreign investor or any entity in its ownership chain holding a 25 per cent or greater voting interest). 24 Products, data and technology can be critical technology regardless of whether they are actually exported.

Additionally, a filing is mandated if a foreign person, in which a foreign government holds a ‘substantial interest’ (ie, 49 per cent), acquires a ‘substantial interest’ (ie, 25 per cent) in a US business that holds ‘sensitive personal data’ or that is involved with ‘critical infrastructure’, both defined terms under the regulations. 25

When a mandatory filing obligation is not triggered but CFIUS has jurisdiction, counsel for the parties to a transaction typically assess the national security profile of a particular transaction to determine whether the submission of a voluntary filing is warranted. As discussed above, any filing analysis must also consider that CFIUS may proactively contact parties involved in a transaction that CFIUS thinks implicates national security to encourage the parties to notify a transaction, before or after closing. Although this occurs infrequently, it does happen, and it is happening with greater frequency as CFIUS deploys FIRRMA-authorised funding to identify non-notified transactions. 26 CFIUS set up a hotline that the public can use to report transactions that might be of interest to CFIUS. If CFIUS reaches out to parties and requests a filing, and the parties decline to submit a filing, CFIUS has the authority to initiate a review on its own and impose remedies or seek a presidential prohibition.

In practice, assessing the CFIUS risk in a transaction can involve two-way due diligence: the buyer considers the target’s US business activity, technology, contractual relationships, licences and security clearances to determine whether to file; and the target considers the buyer’s ownership, business profile, relationships, track record of compliance with certain laws, and the strategic relationship of the United States with the buyer’s country, as well as the buyer’s track record, if any, with CFIUS reviews, to determine the risk the buyer poses to clearance (especially in an auction).

Factors that tend to suggest that a filing should be made include, for example, the following.

  • Does the target have classified contracts or access to classified information requiring facility or personnel security clearances?
  • Does the target have any non-classified (prime or sub) contracts related to defence, homeland security or law enforcement?
  • Does the target produce a critical resource?
  • Does the target have any potentially sensitive advanced, emerging or export-controlled technology?
  • Does the target have access to any large or particularly sensitive data sets containing personally identifiable information on US citizens or other information of potential value to a foreign military or intelligence service?
  • Does the target supply, own or operate critical infrastructure?

What information is required in a filing?

The information needed to complete a filing depends on whether a ‘declaration’ or a ‘notice’ is being filed. The declaration is a newer form that is more streamlined and limited than the traditional full notice. 27 A declaration may be used for any transaction, whether filed under the mandatory programme or voluntarily. 28 The declaration requires information regarding the nature of the transaction, the business activities of the parties to the transaction, the rights that the foreign person will receive as a result of the transaction and the critical technologies that are designed, produced or tested by the US business. 29

A notice must include substantial information regarding the nature of the transaction, the nature of the business to be acquired, identification of its government contracts and information about the identity of the foreign acquiring person, including (unlike for declarations) extensive personal identifier data for all officers and directors in the ownership chain between the direct acquirer and the ultimate foreign parent to permit background checks by the US government. The specific information that must be included is outlined in the regulations. 30 A filing fee must be paid with the submission of any notice.

What is the review period?

The applicable review period and process depends on whether the parties opt to file a declaration or notice. Each process is different in terms of timing, potential outcome and fees. When a mandatory filing is triggered, it must be submitted no later than 30 days before closing. The legal requirement is satisfied by the submission of a declaration, but parties may choose to file a notice instead.

Submission of a declaration triggers a 30-day assessment period that generally begins within a week of submission. Only a final, no draft, declaration is submitted, but CFIUS can request additional information during its review, and the parties must provide the information within two business days. At the end of the 30 days, CFIUS can (i) request a full notice from the parties, (ii) state that it had insufficient information to complete its review, leaving the parties without a definitive outcome, (iii) unilaterally initiate a review as if based on a full notice or (iv) inform the parties that it will take no further action, providing the parties safe harbour for that transaction. 31 Because it is possible that the parties may need to submit a full notice after submitting a declaration, parties need to consider on a case-by-case basis the likelihood of a non-definitive outcome and whether it makes sense to skip the declaration and file a full notice in the first instance.

Submission of a notice is generally preceded by a pre-filing period. The regulations recommend that the parties informally file a draft notice at least five business days in advance of formally filing a notice; in practice, parties informally file in draft at least several weeks before filing a final notice. Though not required, most parties submit a draft as a matter of course because CFIUS has the discretion to reject a notice as incomplete or otherwise delay acceptance until it is satisfied that the notice is complete. It typically takes from several weeks to a couple of months from submission of the draft before a notice is accepted as complete and the initial review clock starts. In practice, CFIUS requires the notice to be submitted jointly (when the transaction is not hostile). The parties must also pay a filing fee of up to US$300,000, as determined by the transaction’s value. 32

Formal CFIUS acceptance of a properly prepared notice triggers an initial 45-calendar-day ‘review’ of the notified transaction. By the end of the initial 45-day period, CFIUS must either issue the parties a clearance letter if it perceives no national security concerns or initiate an additional 45-calendar-day ‘investigation’, which can be extended by an additional 15 days in extraordinary circumstances. If a transaction involves either a foreign government-controlled entity or US critical infrastructure, section 721 requires CFIUS to proceed with a 45-day investigation unless expressly waived by the relevant CFIUS member agencies. During either the review or investigation, CFIUS can request additional information, and the parties are required to respond within three business days, except as extended at CFIUS’ discretion.

If CFIUS identifies national security concerns during the investigation, it may require the parties to enter into a mitigation agreement to resolve any such concerns. If it identifies no national security concerns or enters into a mitigation agreement with the parties to resolve any identified concerns, it will then issue a clearance letter and conclude its investigation. Alternatively, at the end of a 45-day investigation, CFIUS may refer the matter to the President, generally with a recommendation that the President prohibit the transaction (or require divestment, if the transaction has been completed). The President then has 15 calendar days to take any action, which must be publicly announced. If CFIUS is unable to complete its assessment within the investigation period or the parties desire additional time to discuss CFIUS’ determination, the parties may be asked, or may seek, to withdraw and refile their notice. Such a refiling will restart the review clock, leading to a new process of up to 90 days.

The CFIUS review process has recently become more time-consuming and intensive. Historically, CFIUS has reviewed fewer than 200 notices per year, 33 but it reviewed around 230 notices in each of the three years between 2017 and 2019, resulting in long lead times as CFIUS tried to juggle its caseload. As a result of the complexity of the transactions and caseload, a number of the transactions notified to CFIUS were withdrawn and refiled, such that the total number of transactions was likely closer to 200 per year between 2017 and 2019. For the past three years for which data has been reported (between 2017 and 2019), CFIUS initiated investigations on average in over 50 per cent of cases. CFIUS started accepting filings in the form of declarations in 2018. In 2018, CFIUS reviewed 21 declarations. CFIUS officials have publicly stated that in 2019, CFIUS reviewed approximately 110 declarations.

What powers does CFIUS have?

CFIUS has the authority to review a covered transaction and impose mitigation measures to address any national security concerns, although in practice these measures are typically negotiated. Mitigation measures may be imposed only after CFIUS has identified a specific US national security concern and determined that other government authorities (such as export controls) are insufficient to resolve that concern. Nonetheless, CFIUS has broad authority to develop mitigation measures, although it uses that authority in only about two dozen cases each year. Between 2016 and 2018, only 76 cases (13 per cent) resulted in the use of legally binding mitigation measures. That percentage has been increasing, however. In 2018, mitigation measures were applied to 29 different transactions, 34 compared to 2015 when measures were applied to only 11 transactions.

Mitigation measures vary on a case-by-case basis and have included, for example, commitments with respect to domestic production, cybersecurity measures or government access to assets, such as computer servers or telecommunications networks for law enforcement purposes. More invasive mitigation measures may include a requirement to establish certain corporate firewall procedures between the US business and its foreign parent, or terminate certain activities of the US business.

While CFIUS is charged with reviewing a transaction and imposing mitigation measures where warranted, section 721 grants the President, and only the President, the authority to suspend or prohibit a covered transaction. Therefore, if CFIUS seeks to prohibit a transaction and the parties are unwilling to voluntarily abandon the transaction, CFIUS must refer the transaction to the President for action. Though unlikely to occur in practice, if CFIUS fails to reach a consensus for a particular case, CFIUS must also send a report outlining the divergent opinions and recommendations to the President. To exercise the authority to suspend or prohibit a transaction, the President must find both that there is credible evidence that a ‘foreign interest exercising control might take action that threatens to impair the national security’ and that other laws do not, in the President’s judgement, ‘provide adequate and appropriate authority’ to protect national security. Presidential action is rare, partly because mitigation measures often address national security concerns, and partly because parties typically abandon a transaction before CFIUS actually refers the case to the President with a prohibition recommendation. There was a recent spike in the number of transactions voluntarily abandoned due to CFIUS opposition from a couple per year to a height of 24 in 2017. 35 This was attributable to CFIUS opposition to a number of proposed transactions by Chinese persons.

Determinations by the President under section 721 are not subject to judicial review. The exemption from judicial review was confirmed by the District Court for the District of Columbia in 2013 when Ralls Corporation sought to have a presidential order requiring it to divest its interest in certain Oregon wind farms overturned by the court. The District Court ruled that the merits of the President’s decision were not subject to judicial review and that a party that completes a covered transaction without clearance assumes the risk of doing so. 36 On appeal, the Court of Appeals for the District of Columbia Circuit agreed that the President’s decision was not subject to judicial review but held that the ‘presidential order deprived Ralls of constitutionally protected property interests without due process of law’ and instructed that, upon remand, Ralls be given access to unclassified evidence in support of the decision. 37 On remand, the District Court ordered CFIUS to provide all unclassified information on which it relied for its decision, afford Ralls an opportunity to respond to that information, and provide Ralls’ response to the information along with CFIUS’ updated recommendation to the President. 38 The parties ultimately resolved the case via settlement. Although CFIUS determinations are theoretically reviewable, this has limited practical implications because CFIUS concerns are generally either resolved through mitigation that the parties voluntarily undertake or the matter is referred to the President, whose decision is not reviewable on its merits.

Involvement of third parties?

CFIUS members deliberate only among themselves, without seeking input from private third parties. The CFIUS process (unless the President makes a determination) is confidential, and third parties have no right to participate in the process. Nonetheless, members of Congress, trade or industry groups and competitors regularly take a public position or write to CFIUS regarding the national security implications of specific transactions. However, in 2020, CFIUS set up a public hotline for public reporting of transactions, so we may see greater third-party involvement going forward, at least at the initial stage. Even to the extent that CFIUS does not formally engage with these outside parties, this pressure can pose political and commercial challenges to the transaction. As a result, it may be prudent to engage public and government relations experts to consider how to manage third-party constituencies.

What types of transactions are subject to review?

Because the national security review process is confidential, CFIUS is prohibited from disclosing information about particular cases under review. Since 2008, CFIUS has published an annual report of aggregated case statistics. The annual reports show that transactions involving acquiring parties from the United Kingdom, Canada, France and Japan historically accounted for a significant percentage of transactions reviewed by CFIUS. This is not surprising as these countries are some of the largest sources of foreign investment in the United States overall. However, from 2016 to 2018, CFIUS reviewed double the number of notices involving Chinese acquiring persons than from any other jurisdiction. 39 The number of notices reviewed involving Chinese acquiring persons has grown substantially, from one transaction in 2005 to 55 in 2018. However, we expect that this trend likely flattened as the overall volume of Chinese merger and acquisition activity in the United States drops.

CFIUS’ purview is not restricted to any specific sector. By way of example, CFIUS has reviewed transactions dealing with information technologies, network security, energy (development and transport), semiconductors, aerospace, telecommunications, optics, robotics, mining and natural resources, agriculture, plastics and rubber, automotive, financial services, coatings and adhesives, chemicals, insurance and steel. The annual reports provide information at a very general level regarding the industries involved in transactions subject to CFIUS review. The annual reports show that, in 2018, transactions involving the finance, information and services sectors accounted for the highest percentage of cases reviewed by CFIUS, with the manufacturing sector accounting for the second-highest percentage. 40 Within the finance, information and services sectors, transactions involving the acquisition of a professional, scientific and technical services company accounted for the largest percentage of transactions reviewed in 2018, followed by acquisitions involving the telecommunications industry. 41


In cross-border transactions involving the acquisition of a US business, it is important to consider not only the merger control implications, but also the potential national security implications of a transaction. As outlined above, the US national security review process is not limited by industry and could potentially apply to any sector. It is important to consider whether a filing is mandatory and, even if it is not, whether the transaction might implicate US national security issues that are significant enough to warrant a voluntary filing and, if so, to ensure the relevant transaction document accounts for the process and risk. Furthermore, it is important to engage with CFIUS to try to ensure a timely and efficient review process, and that any remedies are narrowly tailored and do not materially impair the benefit that the parties expect from the transaction, and, in some cases, to engage with applicable third-party constituencies such as customers (eg, if a target company does significant business with the US Department of Defense or a US defence contractor). Finally, although CFIUS review is an important consideration for any multinational transaction, it is not the only one: the US process should be considered along with those of other countries that also have foreign investment review regimes, including, for example, Canada, China, France and Germany.


