In cross-border M&A transactions, parties often focus on meeting the U.S. Treasury Department’s Committee on Foreign Investment in the United States (CFIUS) filing requirements, usually through analyzing whether their transaction requires a mandatory declaration or a voluntary notice should be filed. While this is an important initial question, it does not cover all due diligence or compliance responsibilities. Essentially, CFIUS clearance should not be treated as the endpoint; rather, CFIUS risks persist and should be managed throughout the entire deal process.
Treasury’s CFIUS enforcement guidance indicates broader risk and identifies three categories of conduct that may give rise to civil penalties: (1) failure to timely submit a mandatory declaration or notice, (2) non-compliance with CFIUS mitigation terms, and (3) material misstatements, omissions, or false certifications in CFIUS filings. Thus, the decision to file is only one part of the CFIUS risk profile.
A threshold CFIUS analysis normally considers whether the target is a U.S. business, whether the buyer or investor is a foreign person, whether the transaction is a covered control transaction or covered investment, whether the target is a TID U.S. business, and whether a mandatory declaration requirement applies. This analysis is important, especially where the target is involved in critical technology, covered critical infrastructure, sensitive personal data, or sensitive real estate.
Even when no mandatory declaration is required, a transaction may still present enough national security sensitivity to warrant filing a voluntary notice. Deciding to file a voluntary notice is not purely a legal consideration, but also a commercial one. Such a notice can reduce the risk of a later non-notified investigation (NNI) and may provide greater certainty to the buyer, seller, lenders, board, or investors before closing.
There are, of course, trade-offs associated with submitting a voluntary notice, as it could extend the transaction timeline and require detailed disclosures about the buyer, target, ownership structure, governance rights, proprietary information, etc. Still, in higher-risk transactions, this process may be preferable to closing without clearance and later facing CFIUS scrutiny, mitigation demands, or divestment risk.
For these reasons, the question should not be limited to the need for submitting a mandatory declaration. Deal teams should also assess whether a voluntary notice would reduce deal uncertainty, protect transaction value, and/or reduce post-closing CFIUS intervention risk, thereby further delaying closing.
In addition to filing decisions, CFIUS issues can affect transaction terms before closing. A foreign buyer’s rights to board seats, observer rights, veto rights, access to material nonpublic technical information, access to sensitive personal data, or involvement in substantive decision-making may all be relevant. If these issues are spotted early on, the parties may be able to adjust the structure, limit access rights, modify governance rights, or include appropriate protections in the transaction documents. If identified late, however, managing these issues can be more difficult, possibly requiring revised deal terms, restricted information sharing, an extended timeline, a notice submission, acceptance of mitigation, or reassessment of the transaction’s commercial viability.
Securing CFIUS clearance can also introduce continuing obligations. In some instances, CFIUS may require mitigation measures to address national security concerns, such as data access restrictions, security officers, security committees, protected subsidiaries, limits on foreign ownership rights, restrictions on technology transfer, reporting duties, audits, government monitoring, or divestment commitments. For a buyer, these obligations may materially affect the transaction’s post-closing value, as the buyer may acquire the business but not receive the full access, control, integration, or operational efficiency it may have expected.
Failure to comply with CFIUS regulations can carry hefty penalties. Under current CFIUS regulations, material misstatements, omissions, or false certifications in a declaration or notice may result in civil penalties up to $5 million per violation. Failure to submit a mandatory declaration when required may result in penalties up to $5 million or the value of the transaction, whichever is greater. For certain mitigation violations, the maximum penalty may be tied not only to $5 million, but also to the value of the transaction or the violating party’s interest in the U.S. business.
CFIUS’s enforcement record exemplifies how costly penalties can be. In 2024, CFIUS resolved a $60 million enforcement action against T-Mobile for violating a National Security Agreement entered into in connection with the T-Mobile/Sprint merger. The issue here was not failure to seek CFIUS clearance, but post-clearance compliance, including unauthorized access to sensitive data and delayed reporting. Treasury also reported an $18 million enforcement action where parties failed to transfer sensitive assets to a protected subsidiary as required under a National Security Agreement.
The practical lesson here is that CFIUS risk does not end when a declaration or notice is submitted. Accordingly, deal teams should treat CFIUS as a risk across the life cycle of a deal, not simply as a filing requirement. This means screening for CFIUS issues at the onset, assessing sensitive technology, data, infrastructure, customers, government contracts, and real estate early in due diligence, and controlling pre-closing access to sensitive information where appropriate. Failing to integrate this broader risk management approach means that, even if the transaction closes, ongoing national security obligations could remain or occur unexpectedly.