Skip to main content
ExplainerEconomic StatecraftExplainer· 4 min read· in News & Politics

The Mechanics of CFIUS: Jurisdiction, Review Process, and National Security Risk Factors

The Committee on Foreign Investment in the United States operates as the primary gatekeeper for foreign capital entering the American economy. By evaluating transactions for national security risks, the interagency panel wields the power to alter, delay, or block corporate acquisitions and real estate deals.

By Javier Cruz

National Security Advocates 45%Free Trade Proponents 30%Corporate Compliance Advisors 25%
National Security Advocates
Prioritizes safeguarding critical technology and data, viewing economic entanglement with strategic rivals as a fundamental vulnerability.
Free Trade Proponents
Emphasizes predictability and transparency, warning that overly broad CFIUS jurisdiction chills legitimate foreign direct investment.
Corporate Compliance Advisors
Focuses on the practical burden of navigating the review process, negotiating mitigation agreements, and avoiding strict enforcement penalties.

Perspectives this story doesn't cover

  • Foreign sovereign wealth funds
  • Early-stage startup founders

The short answer

  • CFIUS is an interagency committee that screens foreign investments in the US for national security risks.
  • Jurisdiction has expanded beyond controlling stakes to include minority investments in critical technology, infrastructure, and data.
  • The review process involves strict timelines, ranging from a 30-day assessment to a 45-day investigation.
  • CFIUS frequently negotiates mitigation agreements to resolve risks, but the President retains the ultimate authority to block deals.

The Committee on Foreign Investment in the United States (CFIUS) is an interagency committee authorized to review certain foreign investments in the United States to determine their effect on national security. If a transaction poses a threat, the committee can impose stringent mitigation measures or recommend that the President block it entirely.[3]

Chaired by the Secretary of the Treasury, the committee includes representatives from the Departments of Defense, State, Justice, Commerce, Energy, and Homeland Security, alongside specialized offices like the US Trade Representative. This composition ensures that economic, diplomatic, and military perspectives are integrated into the review of cross-border capital flows.[3]

Historically, CFIUS operated largely in the shadows, reviewing straightforward acquisitions where a foreign entity sought a controlling stake in a traditional US defense contractor or critical infrastructure asset. The primary test was whether the transaction resulted in foreign "control" over a sensitive American business.[2][3]

The landscape shifted dramatically with the passage of the Foreign Investment Risk Review Modernization Act (FIRRMA). This legislation expanded the committee's jurisdiction beyond traditional control transactions to include minority, non-controlling investments in specific sectors of the economy.[2]

This expanded jurisdiction specifically targets "TID" US businesses—entities that deal in critical Technology, critical Infrastructure, or sensitive personal Data. A foreign investor purchasing even a small equity stake in a TID business can trigger CFIUS jurisdiction if the investment grants them access to material nonpublic technical information or board observer rights.[2][3]

FIRRMA expanded CFIUS jurisdiction to include non-controlling investments in Technology, Infrastructure, and Data (TID) sectors.

Real estate also falls under this expanded umbrella. CFIUS now holds the authority to review the purchase or lease of real estate by foreign persons if the property is located near sensitive US military installations, ports, or government facilities, regardless of whether a US business is being acquired.[2]

The review mechanism itself is highly structured. It typically begins when transaction parties submit a voluntary notice or a shorter mandatory declaration. While filing is often voluntary, parties are incentivized to file to obtain a "safe harbor" letter, which prevents CFIUS from unwinding the deal in the future.[3]

Mandatory filings are triggered by specific criteria, most notably when a foreign government acquires a "substantial interest" in a TID US business, or when a transaction involves specific critical technologies subject to export controls.[3]

Once a declaration is filed, CFIUS has 30 days to assess the transaction. For a full notice, the committee conducts a 45-day review. During this period, intelligence agencies conduct a National Security Threat Assessment to evaluate the intent and capabilities of the foreign investor.[3]

Once a declaration is filed, CFIUS has 30 days to assess the transaction.

If national security concerns remain unresolved after the initial review, the process enters a 45-day investigation phase. This phase requires higher-level scrutiny and often involves complex negotiations between the government and the transaction parties.[3][4]

The statutory timeline for CFIUS reviews and investigations.

The definition of what constitutes a "national security risk" has also evolved significantly. A 2022 Executive Order formalized new risk factors, directing CFIUS to explicitly consider a transaction's impact on supply chain resilience, particularly in manufacturing capabilities and critical minerals.[1]

The order also mandates scrutiny of transactions that could compromise US technological leadership in emerging fields such as microelectronics, artificial intelligence, biotechnology, and quantum computing.[1]

Furthermore, CFIUS now evaluates aggregate industry investment trends. The committee recognizes that a series of small, seemingly isolated transactions by foreign entities can cumulatively facilitate the transfer of critical technology or grant adversaries a strategic foothold in a vital sector.[1]

The 2022 Executive Order explicitly defined modern risk factors for CFIUS to evaluate.

When CFIUS identifies a risk, it rarely jumps straight to prohibition. Instead, the committee frequently negotiates National Security Agreements (NSAs) with the transaction parties to mitigate the identified threats.[3][4]

These mitigation measures can be extensive and costly. They may require companies to store sensitive data exclusively on US soil, restrict foreign board members' access to technical information, divest certain product lines, or appoint government-approved security directors.[4]

If mitigation is deemed insufficient or impossible to enforce, CFIUS refers the case to the President. The President possesses the sole statutory authority to suspend or prohibit the transaction, a power that has been utilized with increasing frequency over the past decade.[3]

Recent trends from the 2025 annual report highlight an increasingly rigorous enforcement environment. The data shows a higher rate of withdrawn notices, as parties frequently choose to abandon deals rather than face protracted investigations or insurmountable mitigation requirements.[4]

Investments in critical infrastructure, including major ports, face mandatory scrutiny under expanded CFIUS rules.

The committee has also formalized and expanded its penalty guidelines, signaling that violations of existing mitigation agreements will face strict financial consequences. This marks a shift from merely screening new deals to actively policing past approvals.[4]

Ultimately, the mechanics of CFIUS reflect a structural realignment in global economics. The free flow of capital is no longer assumed to be universally beneficial; instead, cross-border investment is now systematically filtered through the lens of national defense and strategic competition.[5]

Jargon, explained

CFIUS
The Committee on Foreign Investment in the United States, an interagency panel that reviews foreign investments for national security risks.
FIRRMA
The Foreign Investment Risk Review Modernization Act of 2018, which significantly expanded CFIUS jurisdiction over non-controlling investments and real estate.
Covered Transaction
Any merger, acquisition, or takeover that is subject to CFIUS jurisdiction, potentially resulting in foreign control of a US business.
TID US Business
A US business that produces critical Technology, performs functions regarding critical Infrastructure, or maintains sensitive personal Data.
Mitigation Agreement
A negotiated contract between CFIUS and transaction parties that imposes specific security conditions to resolve national security concerns without blocking the deal.

Sources

Source coverage

5 outlets

3 viewpoints surfaced

National Security Advocates 45%Free Trade Proponents 30%Corporate Compliance Advisors 25%
  1. [1]Federal RegisterNational Security Advocates

    Ensuring Robust Consideration of Evolving National Security Risks by the Committee on Foreign Investment in the United States

    Read on Federal Register
  2. [2]Federal RegisterNational Security Advocates

    Provisions Pertaining to Certain Investments in the United States by Foreign Persons

    Read on Federal Register
  3. [3]eCFRNational Security Advocates

    31 CFR Part 800 -- Regulations Pertaining to Certain Investments in the United States by Foreign Persons

    Read on eCFR
  4. [4]Trade Compliance Resource HubCorporate Compliance Advisors

    CFIUS annual report for 2025: Key takeaways

    Read on Trade Compliance Resource Hub
  5. [5]Factlen Editorial TeamFree Trade Proponents

    Synthesis by Factlen editorial team

    Read on Factlen Editorial Team

Comments

Stay informed

Every angle. Every day.

Get News & Politics stories with full source coverage and perspective breakdowns delivered to your inbox.