A practical guide to CFIUS diligence, foreign-investment national-security review, and FIRRMA jurisdiction — how PE and M&A teams underwrite jurisdiction triggers, mandatory declarations, mitigation likelihood, and forced-divestment risk before a deal closes.
Many cross-border deals treat CFIUS as a box to check when it is a deal-killer risk. CFIUS and foreign-investment due diligence underwrites whether the Committee on Foreign Investment in the United States has jurisdiction, whether a mandatory FIRRMA declaration is required, whether national-security risk factors will draw scrutiny, whether mitigation will be acceptable, and whether the transaction can both close and stay closed on the hold-period timeline. It is not the same as antitrust diligence (HSR and merger control of competitive harm), compliance diligence (internal program controls), sanctions diligence (OFAC list screening), or generic regulatory diligence (licenses and enforcement). CFIUS work underwrites whether foreign control or access of a US business creates national-security risk the US government can block or unwind.
| Workstream | Primary question | Typical output |
|---|---|---|
| CFIUS / foreign-investment DD | Does foreign control or access create US national-security risk? | Jurisdiction map, declaration triggers, mitigation likelihood, divestment risk |
| Antitrust / HSR DD | Does the deal harm competition? | Market share, overlaps, merger-control filings |
| Export-control DD | Can the technology lawfully be shared or shipped? | ITAR/EAR classification, deemed-export risk, technology control plans |
| Sanctions DD | Are parties or jurisdictions blocked? | OFAC/SDN screening, ownership tracing |
| Compliance program DD | Do internal controls work? | Program design, monitoring, training |
Determine whether the transaction is a covered control transaction (acquiring control of a US business by a foreign person) or a covered investment (non-controlling investment in a TID business — critical technology, critical infrastructure, or sensitive personal data of US citizens). FIRRMA expanded jurisdiction to non-controlling investments and certain real-estate transactions near sensitive sites. Map the control test, the TID test, and any applicable exceptions (fund exceptions, certain passive investments). Connect to regulatory diligence and legal diligence.
Identify whether FIRRMA mandatory declaration triggers apply: critical-technology transactions in designated industries, certain government-only deals, and other Treasury-designated categories. Mandatory declarations trigger a 30-day review. Voluntary notice provides safe harbor (CFIUS cannot later unwind a transaction it has cleared) but takes longer (45-day review, optional 15-day investigation). Decide short-form declaration vs full notice. Missing a mandatory filing is itself an enforcement risk even when CFIUS would otherwise clear the deal. Align with compliance diligence and antitrust diligence (parallel HSR timing).
Map the statutory factors at 50 U.S.C. § 4565: domestic production needed for national defense, the target's defense-relevant capacity, the effect of foreign control on that capacity, the acquirer's relationship with a foreign government or military (including subsidies, state ownership, and military-civil fusion exposure), risk of diversion of critical technology, long-term US requirements for the target's products, and other factors the President or CFIUS determine. In practice Treasury weighs critical infrastructure, sensitive personal data of US citizens, cybersecurity posture, and supply-chain resilience. Connect to cybersecurity diligence, technology diligence, and infrastructure diligence.
Trace the full ownership chain to ultimate beneficial owners, flagging state-owned enterprises, sovereign-wealth funds, entities with PRC or Russian military-civil fusion ties, and opaque holding structures. PE funds with foreign LPs must screen whether the LP base itself triggers scrutiny. Prior CFIUS mitigation, enforcement, or divestment involving the acquirer or affiliates is a material signal. Align with sanctions diligence, forensic diligence, and fund diligence.
Assess likelihood and shape of a national-security agreement (NSA) or mitigation: data localisation, security directors, technology control plans, firewalls, US-only governance, reporting obligations, and continued CFIUS monitoring. Heavy mitigation can gut the investment thesis (lost data access, lost technology transfer, lost offshore operations). Forced-divestment (e.g., Grindr, TikTok, real estate near bases) is the tail risk. Test whether mitigation is acceptable to the acquirer's value-creation plan or whether the deal should be abandoned. Connect to LBO diligence, PMI diligence, and synergy diligence.
CFIUS timeline (declaration 30 days, full notice 45 + up to 15 + re-openings; pulls-and-refiles for failed negotiations) must be sequenced with HSR, Team Telecom (FCC), sector regulators, and foreign equivalents (UK NSI, EU FDI screening, Australia FIRB, Canada ICA). Post-close mitigation can run years. Outbound investment screening (Treasury's emerging regime for US capital into PRC critical tech) adds a new vector. Align with regulatory diligence, market diligence, and deal-timeline diligence planning.
DI20-WELCOME) — useful for jurisdiction screening, declaration triggers, mitigation likelihood, and timeline framing, not a substitute for full ownership-chain disclosure, technology control plans, or government-facing CFIUS filings.
| Stage | CFIUS focus | Deal-team action |
|---|---|---|
| Teaser / CIM | Foreign acquirer, critical-tech narrative | Flag CFIUS and outbound-screening exposure early |
| Desk diligence | Ownership chain, TID exposure, prior CFIUS history | Jurisdiction screen; declaration-vs-notice decision |
| Deep diligence | Risk-factor mapping, mitigation precedent, parallel reviews | Mitigation scenarios; deal-killer test |
| IC / model | Timeline, cost, forced-divestment downside | Base / upside with and without mitigation |
| Post-close | NSA compliance, data localisation, ongoing monitoring | 100-day CFIUS compliance plan |
| Signal | Severity | Why it matters |
|---|---|---|
| Acquirer PRC / Russian / state-owned ownership | Deal-Killer | Heightened scrutiny; mitigation may gut the thesis or force divestment |
| Target in semiconductors, AI, quantum, defense-adjacent tech | Deal-Killer | Critical technology triggers mandatory review and high block risk |
| Large US-person sensitive-personal-data set | High | TID business; data localisation and security-director mitigation likely |
| Real estate near military or sensitive government site | High | Covered real-estate jurisdiction; lease or purchase blocked |
| Opaque ownership chain hiding ultimate control | High | Enforcement risk; CFIUS assumes adverse inference on obscured ties |
| Prior CFIUS mitigation or divestment involving acquirer | High | Track record of non-compliance raises re-screening risk |
| Deal structured to avoid mandatory filing | Deal-Killer | Missing mandatory declaration is itself an enforcement violation |
| Plan to move sensitive operations offshore post-close | High | Diversion risk; mitigation or block likely |
| Approach | Typical cost | Timeline | Best use |
|---|---|---|---|
| Full CFIUS filing + mitigation negotiation | $80K–$200K+ | 3–9 months | Complex cross-border, critical tech, state-owned acquirer |
| Declaration + short review | $30K–$75K | 1–2 months | Mandatory trigger, clean acquirer, low mitigation |
| Public first-pass CFIUS pack | $49 | Minutes to hours | Jurisdiction screen before specialist spend / IC framing |
Before specialist CFIUS counsel and full government-facing filings, teams use structured public research to test whether the transaction plausibly triggers CFIUS jurisdiction: acquirer beneficial-ownership and foreign-government ties, target critical-tech and critical-infrastructure exposure, sensitive-personal-data holdings, real-estate proximity to sensitive sites, prior CFIUS mitigation and enforcement actions, and analogous deals blocked or cleared-with-mitigation. The pack frames filing strategy (declaration vs notice), mitigation scenarios, parallel-review sequencing, and IC-level deal-killer tests so expensive counsel time lands on ownership-chain disclosure, technology control plans, and NSA negotiation — not generic cross-border slides. It is screening research, not a substitute for a CFIUS filing, mitigation agreement, or national-security opinion.
⇧ Already delivered: Tesla (TSLA) · Alphabet (GOOGL) · Palantir (PLTR) — real orders, real SEC data, every claim source-cited.
Get a structured first-pass diligence pack — useful input for CFIUS jurisdiction screening, declaration triggers, mitigation likelihood, and IC deal-killer tests, not a full CFIUS filing or national-security opinion.
Order report $39.20 → Free brief Sample PDF