The Three Categories of Covered Transactions: How CFIUS Reviews Foreign Investment in U.S. Technology, Infrastructure, and Data
The Committee on Foreign Investment in the United States evaluates non-controlling foreign investments through a tripartite framework targeting critical technology, infrastructure, and sensitive personal data.
- National Security Regulators
- Prioritizes preventing adversarial access to critical technologies and sensitive data over capital market efficiency.
- Venture Capital & Private Equity
- Views the expanded jurisdiction as a source of transaction friction that complicates syndication and delays deal closures.
- Legal & Compliance Practitioners
- Focuses on navigating the statutory ambiguities of the TID framework to secure safe harbor for cross-border investments.
Perspectives this story doesn't cover
- Foreign Sovereign Wealth Funds
- Allied Nation Trade Ministries
At a glance
- CFIUS jurisdiction extends beyond controlling acquisitions to include minority investments in technology, infrastructure, and data businesses.
- The critical technology category is tied to existing export control regimes like ITAR and EAR.
- The sensitive data category triggers review for companies holding identifiable data on over one million individuals.
- Failure to file a mandatory declaration allows CFIUS to investigate and potentially unwind a transaction indefinitely.
The Committee on Foreign Investment in the United States (CFIUS) reviews non-controlling foreign investments in domestic businesses by classifying them into three distinct jurisdictional categories: critical technology, critical infrastructure, and sensitive personal data. Together, these form the "TID" framework, a statutory mechanism that dictates whether a foreign entity can acquire equity, board seats, or information rights in a U.S. company without triggering federal intervention. The architecture of this review process determines how capital flows into the American defense industrial base and the broader technology sector.[1][7][8]
Prior to the passage of the Foreign Investment Risk Review Modernization Act (FIRRMA) in 2018, the committee primarily concerned itself with transactions that granted a foreign person outright "control" over a U.S. business. The modern regulatory framework abandons that threshold for TID businesses, asserting jurisdiction over minority investments if they afford the investor access to material nonpublic technical information, board observer rights, or involvement in substantive decision-making regarding the company's core assets.[6][7]
The first pillar of the TID framework covers critical technologies. This category is tethered directly to existing U.S. export control regimes, capturing businesses that produce, design, test, or manufacture items restricted under the International Traffic in Arms Regulations (ITAR) or the Export Administration Regulations (EAR). If a U.S. startup develops a dual-use algorithm or a specialized semiconductor requiring a license for export to the investor's home country, any equity investment granting the investor access to that technology falls under mandatory CFIUS review.[1][3]
This technology threshold has fundamentally altered the venture capital stack. Defense tech companies must now treat their investor strategy as a national security issue, because accepting capital from a foreign limited partner can freeze a startup out of Department of Defense procurement pipelines. A mandatory declaration must be filed at least 30 days before the transaction closes, shifting the regulatory burden to the earliest stages of capital formation and forcing founders to audit their capitalization tables before signing term sheets.[2][3]
The second category encompasses critical infrastructure. Rather than relying on a broad conceptual definition, the Treasury Department regulations provide a specific appendix listing 28 distinct types of infrastructure and their associated functions. This statutory list includes entities that own, operate, manufacture, or service physical and virtual assets ranging from interstate oil pipelines and high-capacity telecommunications networks to specialized financial market utilities and bulk-power systems.[1][6]
For an investment to trigger the infrastructure provision, the U.S. business must perform a specified function—such as operating a water treatment facility or manufacturing components for the electrical grid—and the foreign investor must acquire rights that could enable the sabotage or disruption of that system. The regulatory logic treats the financial transaction as a vector for physical or operational access, allowing the committee to block investments that could compromise domestic resilience during a geopolitical crisis.[1][8]
For an investment to trigger the infrastructure provision, the U.S.
The third and most expansive category is sensitive personal data. CFIUS asserts jurisdiction over investments in U.S. businesses that maintain or collect identifiable data on more than one million individuals, or that target data on specific populations like military personnel or federal employees. This provision was engineered specifically to prevent foreign intelligence services from acquiring bulk datasets through commercial acquisitions, bypassing traditional espionage methods.[5][8]
Sensitive data under this framework includes genetic information, biometric identifiers, financial distress metrics, and precise geolocation data. Consequently, a health-tech startup with no defense contracts and no critical infrastructure assets can still trigger a mandatory CFIUS review if it processes the biometric data of U.S. citizens and accepts funding from a foreign-backed private equity firm. The data pillar effectively expands national security jurisdiction into the consumer technology sector.[1][5]
To mitigate the friction on allied capital, the framework includes an "excepted investor" carve-out. Investors from specific allied nations—currently limited to a narrow list including the United Kingdom, Australia, Canada, and New Zealand—can bypass certain non-controlling transaction reviews if they meet stringent criteria regarding their ownership structure, board composition, and history of compliance with U.S. law.[4][6]
However, this exception is fragile and highly conditional. An excepted investor can lose its status if it violates U.S. sanctions, export controls, or previous CFIUS mitigation agreements. Furthermore, the exception only applies to non-controlling investments; if an allied investor acquires outright control of a TID U.S. business, the transaction remains subject to the committee's full jurisdictional authority, regardless of the investor's country of origin.[4][6]
When a covered transaction presents a national security risk, CFIUS rarely blocks it outright. Instead, the committee typically imposes mitigation agreements—legally binding contracts that restrict the foreign investor's access to the U.S. business's facilities, networks, or data. These agreements can require the U.S. company to establish a security committee composed exclusively of U.S. citizens, to host its data on domestic servers, or to sever specific foreign supply chain dependencies.[2][3]
The ultimate enforcement mechanism for the TID framework is the committee's power to unwind closed transactions. If parties fail to file a mandatory declaration for a covered investment in a technology, infrastructure, or data business, CFIUS retains the statutory authority to investigate the deal indefinitely. Should the committee find an unresolved national security risk, it can compel the foreign investor to divest its equity stake entirely, regardless of how much time has passed since the capital changed hands.[1][7]
Terms to know
- FIRRMA
- The Foreign Investment Risk Review Modernization Act of 2018, which expanded CFIUS jurisdiction to include certain non-controlling investments.
- TID U.S. Business
- A U.S. business that produces critical Technology, performs specific functions regarding critical Infrastructure, or maintains sensitive personal Data.
- Covered Transaction
- Any transaction proposed or pending that could result in foreign control of a U.S. business, or a specified non-controlling investment in a TID U.S. business.
- Mitigation Agreement
- A legally binding contract between CFIUS and the transaction parties that imposes security conditions to resolve national security risks without blocking the deal.
- Excepted Investor
- A foreign investor from an eligible allied state that meets specific criteria, exempting them from CFIUS jurisdiction over non-controlling transactions.
Questions readers ask
What triggers a mandatory CFIUS filing?
A mandatory filing is triggered when a foreign person makes a controlling or specific non-controlling investment in a U.S. business involved with critical technology, critical infrastructure, or sensitive personal data (a TID business).
What happens if parties fail to file a mandatory declaration?
CFIUS can impose civil penalties up to the value of the transaction and retains the authority to investigate and potentially unwind the deal indefinitely after it has closed.
Who qualifies as an excepted investor?
Investors from a narrow list of allied nations (currently including the UK, Australia, Canada, and New Zealand) who meet strict criteria regarding their ownership structure and compliance history.
Does CFIUS review apply to minority investments?
Yes. Under the FIRRMA regulations, CFIUS has jurisdiction over non-controlling investments if they grant the foreign investor access to material nonpublic technical information, board seats, or substantive decision-making rights.
Sources
[1]Treasury DepartmentNational Security RegulatorsFact Sheet: Final CFIUS Regulations Implementing FIRRMA
Read on Treasury Department →
[2]BakerHostetlerVenture Capital & Private EquityCFIUS and the Venture Stack: Why Defense Tech Companies Must Treat Investor Strategy as a National Security Issue
Read on BakerHostetler →
[3]Pearl CohenLegal & Compliance PractitionersCFIUS for Foreign Investors and U.S. Businesses: What You Need to Know
Read on Pearl Cohen →
[4]Georgetown Law Technology ReviewLegal & Compliance PractitionersDangers of Foreign Excepted Investors with Novel TID Jurisdiction
Read on Georgetown Law Technology Review →
[5]ArentFox SchiffLegal & Compliance PractitionersCFIUS 2.0: 'Sensitive Personal Data' in the National Security Context
Read on ArentFox Schiff →
[6]Holland & KnightVenture Capital & Private EquityNew CFIUS Regulations Finally Take Effect
Read on Holland & Knight →
[7]Practical LawNational Security RegulatorsFIRRMA Signed into Law, Expanding Scope of CFIUS Review
Read on Practical Law →
[8]Factlen Editorial TeamSynthesis by Factlen editorial team
Read on Factlen Editorial Team →
Comments
More in Defense & Security
See all →Air Defense Architecture
How Concurrent Multi-Domain Attacks Are Forcing a Rethink of U.S. Air Defense Architecture
3 sources
Military Doctrine
The Six Principles of Military Deception: How Focus, Objective, and Integration Dictate Success
7 sources
Radar Physics
The Inverse Fourth Power Law: How Range and Power Trade Off in Radar Detection
7 sources
Defense Procurement
The Evidence Pack: Why the Pentagon's $2.4 Trillion Weapons Portfolio Is Now 12 Years Behind Schedule
5 sources
Every angle. Every day.
Get Defense & Security stories with full source coverage and perspective breakdowns delivered to your inbox.




