CFIUS Laws and Guidance: Complete Guide 2026
Planet

CFIUS in 2026: Key Rule Changes and “Reverse CFIUS” Impact on Investors

The Committee on Foreign Investment in the United States (CFIUS) is a powerful, inter-agency group that scrutinizes foreign investments in U.S. businesses and real estate for national security risks. Its authority originates from Section 721 of the Defense Production Act of 1950. But its modern, expansive scope is the result of recent laws like the Foreign Investment Risk Review Modernization Act of 2018 (FIRRMA). For any foreign entity considering a U.S. investment, understanding these rules isn’t just a good idea—it’s essential.

CFIUS – The Committee on Foreign Investment in the United States, an inter-agency committee chaired by the U.S. Secretary of the Treasury, is authorized to review certain transactions involving foreign investment in the United States to determine their effect on national security.

Covered Transaction – Any merger, acquisition, or takeover that could result in foreign control of a U.S. business. The term was expanded by FIRRMA to also include certain non-controlling investments in U.S. businesses involved with critical technology, infrastructure, or sensitive personal data.

What is CFIUS and What is Its Purpose?

CFIUS is a federal government committee with a single, critical mission: to review certain foreign investments in U.S. businesses and specific real estate deals to evaluate their effect on the national security of the United States. Its legal foundation is Section 721 of the Defense Production Act of 1950, which has been amended significantly over the years.

The committee’s role has changed dramatically. What was once an obscure process is now a critical checkpoint for global mergers and acquisitions. This transformation gained speed with the Foreign Investment and National Security Act of 2007 (FINSA) and, even more profoundly, with the Foreign Investment Risk Review Modernization Act of 2018 (FIRRMA). These laws didn’t just formalize CFIUS processes; they expanded its jurisdiction and sharpened its focus on emerging threats tied to technology, data, and critical infrastructure.

CFIUS is an acronym for the “Committee on Foreign Investment in the United States.” It’s not a standalone agency. Instead, it is a committee of members from various executive branch departments. The Secretary of the Treasury chairs the committee, which includes nine voting members from departments like Defense, Justice, Homeland Security, Commerce, State, and Energy. This multi-agency approach ensures a holistic review of national security risks, weighing everything from military and law enforcement concerns to economic policy.

How Has CFIUS Law Evolved Over Time?

The legal framework for CFIUS didn’t appear overnight. It was built piece by piece over decades, reacting to shifting geopolitical and economic realities. What began with a narrow mandate has grown into a comprehensive regulatory system.

The foundation is Section 721 of the Defense Production Act of 1950. This authority was initially limited, but the 1988 Exon-Florio amendment gave the President the power to block foreign acquisitions of U.S. companies if they threatened national security.

A major modernization effort came with the Foreign Investment and National Security Act of 2007 (FINSA), enacted on October 24, 2007. FINSA codified the committee’s structure and review processes, establishing firmer timelines for reviews and investigations. It created a more predictable, though still demanding, process for everyone involved.

The biggest expansion of CFIUS power arrived with the Foreign Investment Risk Review Modernization Act of 2018 (FIRRMA), enacted on August 13, 2018, with most implementing regulations taking effect on February 13, 2020. FIRRMA broadened the committee’s reach to include certain non-controlling investments in U.S. businesses involved with critical technology, critical infrastructure, or sensitive personal data—often called “TID U.S. Businesses.” For the first time, it also introduced mandatory filing requirements, forcing parties to notify CFIUS of certain deals.

More recently, executive orders have added clarity. Executive Order 14083, issued by President Biden, was the first formal presidential guidance spelling out the specific risk factors CFIUS must analyze, including supply chain resilience, U.S. technological leadership, and the security of Americans’ sensitive data. A parallel development, Executive Order 14105, created a separate but related framework for screening certain *outbound* investments, adding another layer to the national security review landscape.

From practice: Many investors mistakenly believe CFIUS only reviews transactions involving defence contractors. Since FIRRMA, the definition of “critical technology” has expanded to include a wide range of dual-use technologies, and “sensitive personal data” can cover businesses from health tech to social media. A U.S. business does not need to have government contracts to fall under CFIUS jurisdiction.

What Transactions Trigger CFIUS Jurisdiction?

CFIUS jurisdiction hinges on a “covered transaction.” At its core, this means any merger, acquisition, or takeover that could result in foreign “control” of a U.S. business, no matter the industry. The idea of “control” is defined broadly. It isn’t just about owning a majority of voting shares; control can be established through various board rights, contractual powers, or other means.

The FIRRMA legislation pushed this traditional scope even further. Jurisdiction now covers certain non-controlling “covered investments” by foreign persons in specific U.S. businesses known as “TID U.S. businesses,” which are companies involved with:

  • Technology: Those that produce, design, test, or develop “critical technologies.”
  • Infrastructure: Companies that own or operate “critical infrastructure.”
  • Data: Any business that collects or maintains the “sensitive personal data” of U.S. citizens.

CFIUS also has jurisdiction over certain purchases or leases of U.S. real estate. This authority isn’t a blanket rule; it applies specifically to real estate near sensitive sites like military bases or major ports. Its focus is exclusively on national security, making it completely distinct from financial reporting rules like fasb guidance or federal employment regulations like opm rif guidance.

It’s a common misunderstanding that CFIUS “approves” deals. It doesn’t. Instead, CFIUS “clears” a transaction, which signals that it has finished its review and found no unresolved national security concerns. This clearance allows the deal to proceed without further committee action.

Voluntary Filings: Most transactions under CFIUS jurisdiction—mainly those resulting in foreign control of a U.S. business—can be voluntarily filed. Parties do this to get a “safe harbor.” This safe harbor is crucial because it prevents CFIUS from initiating a review on its own and potentially forcing the parties to unwind the deal long after it has closed.

Mandatory Filings: A filing is compulsory only in specific situations:

  1. Critical Technology Investments: Certain investments in a U.S. business dealing in “critical technologies” require a mandatory filing if a U.S. export license would be needed to transfer that technology to the foreign investor.
  2. Substantial Foreign Government Interest: A filing is required when an entity in which a foreign government has a “substantial interest” (49% or greater voting interest) acquires a “substantial interest” (25% or greater voting interest) in a TID U.S. business.

Missing a mandatory filing deadline can result in severe penalties, potentially equal to the value of the entire transaction.

What Are the Mandatory CFIUS Filing Requirements?

For certain high-risk deals, FIRRMA did away with the traditional voluntary system. Parties in these transactions must submit a filing, usually at least 30 days before the deal is scheduled to close. Failure to file on time can halt the entire deal and expose the parties to significant fines.

The two main triggers for a mandatory filing involve critical technology and foreign government ownership.

First, a mandatory declaration is necessary for specific investments in a U.S. business that produces, designs, tests, manufactures, fabricates, or develops one or more “critical technologies.” This rule kicks in when a U.S. export control authorization, like a license, would be required to send that specific technology to the foreign investor or others in its ownership chain.

Second, a filing is also mandatory when a foreign person, where a foreign government holds a “substantial interest” (a 49% or more direct or indirect voting stake), acquires a “substantial interest” (a 25% or more direct or indirect voting stake) in a TID U.S. business.

When making a mandatory filing, parties have a choice: a short-form “declaration” or a full “written notice.”

  • Declaration: This is a shorter document, often just 5 pages, with basic transaction details. CFIUS has 30 days to assess it. Critically, there’s no filing fee.
  • Written Notice: A far more comprehensive submission that details everything about the parties, the transaction, and the U.S. business. It triggers a 45-day review and requires a filing fee, which became effective on May 1, 2020. While more work, a full notice offers a much higher degree of certainty that you will receive clearance. Parties must weigh the speed and low cost of a declaration against the greater assurance of a full notice.

What Does the CFIUS Review Process Involve?

The CFIUS review is a structured, time-bound procedure governed by federal regulations, mainly 31 C.F.R. part 800. The clock starts ticking only after parties submit a complete filing and CFIUS formally accepts it.

Here’s the formal timeline:

StageTimeline (for a full notice)Description
Pre-FilingVariableParties can engage in informal consultations with CFIUS staff. This is also when they prepare the draft notice or declaration—a critical step where a poorly drafted document can cause significant delays later.
Review Period45 daysOnce CFIUS accepts a full written notice, the clock starts on a 45-day review to assess national security risks. The assessment period for a shorter declaration is just 30 days.
Investigation45 days (optional)If the initial review uncovers potential risks, CFIUS can launch a deeper 45-day investigation. Note that this period can be extended by 15 days if extraordinary circumstances arise.
Presidential Review15 days (optional)When CFIUS can’t resolve security concerns or recommends a block, the issue goes to the President. The President then has 15 days to make a final call.

During the 30-day assessment of a declaration, CFIUS has a few options:

  1. Clear the transaction.
  2. Ask the parties to file a full written notice instead.
  3. Simply inform the parties it cannot complete its work based on the declaration. This isn’t a rejection, but it strongly signals that a full notice is the only path forward.

After a full review or investigation, several outcomes are possible. CFIUS could clear the transaction, allowing it to close. But if it identifies national security risks, it will often negotiate a mitigation agreement. These are legally binding contracts designed to resolve specific security concerns. They might require the company to appoint a government-approved security officer, divest sensitive parts of the U.S. business, or agree to regular third-party audits.

What if an agreement can’t be reached? If CFIUS recommends blocking the transaction, the matter moves to the President of the United States, who holds the ultimate authority to block or even unwind a completed deal. That said, a landmark case, Ralls Corp. v. Committee on Foreign Investment in the United States, confirmed that presidential decisions are not above the law. They are subject to constitutional due process, meaning the affected parties must be shown the unclassified evidence against them and given a chance to respond.

Section 721 requires CFIUS to submit an annual report to Congress. An unclassified version is made public, providing crucial statistics and a window into the committee’s activities. For legal practitioners and businesses, this report is a key source of CFIUS guidance for spotting enforcement trends.

The report usually contains data points like:

  • The total count of notices and declarations filed that year.
  • How many transactions were withdrawn by the parties or simply abandoned after CFIUS signaled concerns.
  • The number of cases that escalated to a full investigation.
  • Where the investments came from, broken down by country.
  • The specific business sectors most frequently reviewed.

Recent reports, for instance, reveal a consistent pattern. A large percentage of transactions get cleared during the initial review (67% in the 2025 report), but a smaller, significant number are withdrawn. These withdrawals often happen once it becomes obvious that CFIUS will require a tough mitigation agreement to proceed.

CFIUS regulations are the rules from the U.S. Department of the Treasury that put the Committee’s legal authority into practice. The main regulations live in Title 31 of the Code of Federal Regulations, specifically 31 C.F.R. part 800 (for investments in U.S. businesses) and 31 C.F.R. part 802 (for real estate deals). It’s in these rules that you’ll find definitions for crucial terms like “control” and “critical technologies,” plus the procedures for filing.

Jurisdiction is triggered by a “covered transaction.” At its core, this means any merger, acquisition, or takeover that might give a foreign entity “control” over a U.S. business. The FIRRMA legislation expanded this scope. Now, jurisdiction also covers certain non-controlling investments in U.S. businesses that handle critical technology, critical infrastructure, or sensitive personal data (known as TID U.S. businesses). Certain real estate transactions near sensitive government sites also fall under its purview.

You absolutely must file with CFIUS in two key situations. First, when a foreign person backed by a substantial foreign government interest acquires a substantial interest in a U.S. “TID business.” Second, certain deals involving U.S. businesses with “critical technologies,” where export control rules would require a license to send that technology to the foreign investor. Failing to file in these cases can trigger significant penalties, so “I didn’t know” is not a valid defense.

A small but important distinction: CFIUS doesn’t “approve” deals. It “clears” them. A clearance is a signal that CFIUS has no unresolved national security concerns. Most filings are voluntary, done to get the “safe harbor” that clearance provides. However, some transactions demand a mandatory filing, particularly those involving “critical technologies” or where a foreign government has a major stake in the deal.

This is a legally required public report detailing CFIUS’s activities for the year. It provides statistics on the number and kinds of filings reviewed, investor home countries, the business sectors involved, and how many cases were investigated or withdrawn. For anyone trying to understand CFIUS’s current priorities, the report is an indispensable tool.

CFIUS stands for the “Committee on Foreign Investment in the United States.” It’s an inter-agency committee, chaired by the Treasury Secretary, with members from top national security and economic departments. Its entire mission is to review the national security risks of foreign investments flowing into the U.S.

Frequently Asked Questions

What is CFIUS and What is Its Purpose?

CFIUS is a federal government committee with a single, critical mission: to review certain foreign investments in U.S. businesses and specific real estate deals to evaluate their effect on the national security of the United States. Its legal foundation is Section 721 of the Defense Production Act of 1950, which has been amended significantly over the years.

How Has CFIUS Law Evolved Over Time?

The legal framework for CFIUS didn’t appear overnight. It was built piece by piece over decades, reacting to shifting geopolitical and economic realities. What began with a narrow mandate has grown into a comprehensive regulatory system.

What Transactions Trigger CFIUS Jurisdiction?

CFIUS jurisdiction hinges on a “covered transaction.” At its core, this means any merger, acquisition, or takeover that could result in foreign “control” of a U.S. business, no matter the industry. The idea of “control” is defined broadly. It isn’t just about owning a majority of voting shares; control can be established through various board rights, contractual powers, or other means.

What Are the Mandatory CFIUS Filing Requirements?

For certain high-risk deals, FIRRMA did away with the traditional voluntary system. Parties in these transactions must submit a filing, usually at least 30 days before the deal is scheduled to close. Failure to file on time can halt the entire deal and expose the parties to significant fines.

What Does the CFIUS Review Process Involve?

The CFIUS review is a structured, time-bound procedure governed by federal regulations, mainly 31 C.F.R. part 800. The clock starts ticking only after parties submit a complete filing and CFIUS formally accepts it.

Planet