Live: Tesla PDF 3s (DI-1F0059F32F) - median 15s across 4 real orders - code DI20-WELCOME - $49 to $39.20 - Order now →
Home / Regulatory DD / CFIUS & Foreign Investment Due Diligence

CFIUS & Foreign Investment Due Diligence: National-Security Review

A practical guide to CFIUS diligence, foreign-investment national-security review, and FIRRMA jurisdiction — how PE and M&A teams underwrite jurisdiction triggers, mandatory declarations, mitigation likelihood, and forced-divestment risk before a deal closes.

Regulatory / national-security workstream
6
CFIUS pillars
50
Checklist items
$30K+
Specialist counsel start
$49
First-pass pack

Many cross-border deals treat CFIUS as a box to check when it is a deal-killer risk. CFIUS and foreign-investment due diligence underwrites whether the Committee on Foreign Investment in the United States has jurisdiction, whether a mandatory FIRRMA declaration is required, whether national-security risk factors will draw scrutiny, whether mitigation will be acceptable, and whether the transaction can both close and stay closed on the hold-period timeline. It is not the same as antitrust diligence (HSR and merger control of competitive harm), compliance diligence (internal program controls), sanctions diligence (OFAC list screening), or generic regulatory diligence (licenses and enforcement). CFIUS work underwrites whether foreign control or access of a US business creates national-security risk the US government can block or unwind.

CFIUS vs antitrust vs export controls vs sanctions

WorkstreamPrimary questionTypical output
CFIUS / foreign-investment DDDoes foreign control or access create US national-security risk?Jurisdiction map, declaration triggers, mitigation likelihood, divestment risk
Antitrust / HSR DDDoes the deal harm competition?Market share, overlaps, merger-control filings
Export-control DDCan the technology lawfully be shared or shipped?ITAR/EAR classification, deemed-export risk, technology control plans
Sanctions DDAre parties or jurisdictions blocked?OFAC/SDN screening, ownership tracing
Compliance program DDDo internal controls work?Program design, monitoring, training

Six pillars of CFIUS & foreign-investment diligence

1. Jurisdiction & FIRRMA scope

Determine whether the transaction is a covered control transaction (acquiring control of a US business by a foreign person) or a covered investment (non-controlling investment in a TID business — critical technology, critical infrastructure, or sensitive personal data of US citizens). FIRRMA expanded jurisdiction to non-controlling investments and certain real-estate transactions near sensitive sites. Map the control test, the TID test, and any applicable exceptions (fund exceptions, certain passive investments). Connect to regulatory diligence and legal diligence.

2. Mandatory declarations & filing strategy

Identify whether FIRRMA mandatory declaration triggers apply: critical-technology transactions in designated industries, certain government-only deals, and other Treasury-designated categories. Mandatory declarations trigger a 30-day review. Voluntary notice provides safe harbor (CFIUS cannot later unwind a transaction it has cleared) but takes longer (45-day review, optional 15-day investigation). Decide short-form declaration vs full notice. Missing a mandatory filing is itself an enforcement risk even when CFIUS would otherwise clear the deal. Align with compliance diligence and antitrust diligence (parallel HSR timing).

3. National-security risk factors

Map the statutory factors at 50 U.S.C. § 4565: domestic production needed for national defense, the target's defense-relevant capacity, the effect of foreign control on that capacity, the acquirer's relationship with a foreign government or military (including subsidies, state ownership, and military-civil fusion exposure), risk of diversion of critical technology, long-term US requirements for the target's products, and other factors the President or CFIUS determine. In practice Treasury weighs critical infrastructure, sensitive personal data of US citizens, cybersecurity posture, and supply-chain resilience. Connect to cybersecurity diligence, technology diligence, and infrastructure diligence.

4. Acquirer profile & beneficial ownership

Trace the full ownership chain to ultimate beneficial owners, flagging state-owned enterprises, sovereign-wealth funds, entities with PRC or Russian military-civil fusion ties, and opaque holding structures. PE funds with foreign LPs must screen whether the LP base itself triggers scrutiny. Prior CFIUS mitigation, enforcement, or divestment involving the acquirer or affiliates is a material signal. Align with sanctions diligence, forensic diligence, and fund diligence.

5. Mitigation agreements & deal-killer risk

Assess likelihood and shape of a national-security agreement (NSA) or mitigation: data localisation, security directors, technology control plans, firewalls, US-only governance, reporting obligations, and continued CFIUS monitoring. Heavy mitigation can gut the investment thesis (lost data access, lost technology transfer, lost offshore operations). Forced-divestment (e.g., Grindr, TikTok, real estate near bases) is the tail risk. Test whether mitigation is acceptable to the acquirer's value-creation plan or whether the deal should be abandoned. Connect to LBO diligence, PMI diligence, and synergy diligence.

6. Timeline, parallel reviews & hold-period realism

CFIUS timeline (declaration 30 days, full notice 45 + up to 15 + re-openings; pulls-and-refiles for failed negotiations) must be sequenced with HSR, Team Telecom (FCC), sector regulators, and foreign equivalents (UK NSI, EU FDI screening, Australia FIRB, Canada ICA). Post-close mitigation can run years. Outbound investment screening (Treasury's emerging regime for US capital into PRC critical tech) adds a new vector. Align with regulatory diligence, market diligence, and deal-timeline diligence planning.

Cost reality: specialist CFIUS counsel, economic mitigation modeling, beneficial-ownership tracing, and full filings often run $30K–$200K+ for complex cross-border deals. A structured public first-pass pack is $49 (or $39.20 with code DI20-WELCOME) — useful for jurisdiction screening, declaration triggers, mitigation likelihood, and timeline framing, not a substitute for full ownership-chain disclosure, technology control plans, or government-facing CFIUS filings.
Order first-pass PDF → View sample report

Stage sequencing (screen to IC)

StageCFIUS focusDeal-team action
Teaser / CIMForeign acquirer, critical-tech narrativeFlag CFIUS and outbound-screening exposure early
Desk diligenceOwnership chain, TID exposure, prior CFIUS historyJurisdiction screen; declaration-vs-notice decision
Deep diligenceRisk-factor mapping, mitigation precedent, parallel reviewsMitigation scenarios; deal-killer test
IC / modelTimeline, cost, forced-divestment downsideBase / upside with and without mitigation
Post-closeNSA compliance, data localisation, ongoing monitoring100-day CFIUS compliance plan

Red flags

SignalSeverityWhy it matters
Acquirer PRC / Russian / state-owned ownershipDeal-KillerHeightened scrutiny; mitigation may gut the thesis or force divestment
Target in semiconductors, AI, quantum, defense-adjacent techDeal-KillerCritical technology triggers mandatory review and high block risk
Large US-person sensitive-personal-data setHighTID business; data localisation and security-director mitigation likely
Real estate near military or sensitive government siteHighCovered real-estate jurisdiction; lease or purchase blocked
Opaque ownership chain hiding ultimate controlHighEnforcement risk; CFIUS assumes adverse inference on obscured ties
Prior CFIUS mitigation or divestment involving acquirerHighTrack record of non-compliance raises re-screening risk
Deal structured to avoid mandatory filingDeal-KillerMissing mandatory declaration is itself an enforcement violation
Plan to move sensitive operations offshore post-closeHighDiversion risk; mitigation or block likely

Cost & timeline (traditional vs first-pass)

ApproachTypical costTimelineBest use
Full CFIUS filing + mitigation negotiation$80K–$200K+3–9 monthsComplex cross-border, critical tech, state-owned acquirer
Declaration + short review$30K–$75K1–2 monthsMandatory trigger, clean acquirer, low mitigation
Public first-pass CFIUS pack$49Minutes to hoursJurisdiction screen before specialist spend / IC framing

50-point CFIUS & foreign-investment diligence checklist

  • Is there a foreign person in the acquirer, seller, target, or LP base?
  • Does the transaction confer control (covered control transaction)?
  • Is the target a TID business (critical tech, critical infrastructure, sensitive data)?
  • Does a FIRRMA mandatory declaration trigger apply?
  • Short-form declaration or full voluntary notice?
  • Is the safe-harbor benefit worth the longer timeline?
  • Full beneficial-ownership chain to ultimate owners
  • State-owned enterprise, sovereign-wealth, or government-subsidy exposure
  • Military-civil fusion or PLA / Russian-state ties
  • Prior CFIUS mitigation, enforcement, or divestment involving acquirer
  • Target in critical technology: semiconductors, AI, quantum, biotech, defense
  • Target in critical infrastructure: telecom, energy, ports, water, finance
  • Sensitive personal data of US citizens held by target
  • Genomic, health, financial, geolocation, or biometric data
  • Real estate near military bases, government sites, or sensitive facilities
  • Defense industrial base or sole-source supplier exposure
  • Export-control overlap (ITAR, EAR, technology control plans)
  • Sanctions overlap (OFAC screening of acquirer and affiliates)
  • Antitrust overlap (HSR filing and merger-control timing)
  • Team Telecom / FCC license review if applicable
  • Foreign-equivalent review (UK NSI, EU FDI, FIRB, ICA)
  • Outbound investment screening exposure (US capital into PRC critical tech)
  • National-security factors assessment (50 U.S.C. 4565)
  • Domestic production needed for national defense
  • Target capacity and capability for defense requirements
  • Effect of foreign control on defense-relevant capacity
  • Acquirer relationship with foreign government or military
  • Risk of diversion of critical technology
  • Long-term US requirements for the target's products
  • Cybersecurity posture and prior incidents
  • Supply-chain resilience and single-source risk
  • Mitigation precedent for analogous deals
  • National-security agreement (NSA) shape and acceptability
  • Data localisation, security directors, technology control plans
  • US-only governance and firewalls
  • Continued CFIUS monitoring and reporting burden
  • Forced-divestment downside case (Grindr, real estate precedents)
  • Whether mitigation guts the value-creation thesis
  • Timeline: declaration 30 days, notice 45 + 15 + re-openings
  • Pull-and-refile scenarios for failed negotiation
  • Parallel regulatory reviews sequenced or staggered
  • PE fund LP composition screening (foreign LP concentration)
  • Fund-exception eligibility for certain passive investments
  • Litigation or political sensitivity of the transaction
  • Media / public-relations exposure of cross-border narrative
  • Post-close Day-1 / 100-day CFIUS compliance plan
  • NSA compliance ownership and reporting cadence
  • Exit implications if mitigation runs for the hold period
  • IC memo: three national-security risks that reprice or kill the deal
  • Public first-pass pack used only as triage, not a CFIUS filing

How deal teams use a first-pass pack

Before specialist CFIUS counsel and full government-facing filings, teams use structured public research to test whether the transaction plausibly triggers CFIUS jurisdiction: acquirer beneficial-ownership and foreign-government ties, target critical-tech and critical-infrastructure exposure, sensitive-personal-data holdings, real-estate proximity to sensitive sites, prior CFIUS mitigation and enforcement actions, and analogous deals blocked or cleared-with-mitigation. The pack frames filing strategy (declaration vs notice), mitigation scenarios, parallel-review sequencing, and IC-level deal-killer tests so expensive counsel time lands on ownership-chain disclosure, technology control plans, and NSA negotiation — not generic cross-border slides. It is screening research, not a substitute for a CFIUS filing, mitigation agreement, or national-security opinion.

Screen the national-security risk before you sign

⇧ Already delivered: Tesla (TSLA) · Alphabet (GOOGL) · Palantir (PLTR) — real orders, real SEC data, every claim source-cited.

Get a structured first-pass diligence pack — useful input for CFIUS jurisdiction screening, declaration triggers, mitigation likelihood, and IC deal-killer tests, not a full CFIUS filing or national-security opinion.

Order report $39.20 → Free brief Sample PDF