1. Home
  2. |Insights
  3. |U.S. National Security Review of Foreign Investment: Revisions to CFIUS Legislation Signed Into Law

U.S. National Security Review of Foreign Investment: Revisions to CFIUS Legislation Signed Into Law

Client Alert | 1 min read | 08.17.18

On August 13, 2018, the President signed the National Defense Authorization Act for Fiscal Year 2019 which includes the Foreign Investment Risk Review Modernization Act of 2018 (FIRRMA) updating national security reviews performed by the Committee on Foreign Investment in the United States (CFIUS). Some FIRRMA provisions are effective immediately, but the effective date of others requires formal rulemaking to be completed within the next 18 months. Included in the provisions effective immediately is a lengthening of the review process (including the ability to provide limited 15-day extensions) and express authority to suspend transactions pending review or to enter into interim mitigation while the review proceeds. The FIRRMA provision authorizing a filing fee of up to $300,000 is effective immediately, and could perhaps be implemented sooner than the other regulations mandated by the Act. Awaiting rulemaking and industry input are such reform provisions as providing for voluntary (and in some cases mandatory) short form declarations. Implementation of the provisions arguably expanding the Committee’s jurisdiction, or at least codifying CFIUS’s broad interpretation of its existing authority, such as review certain real estate transactions and non-controlling investments involving “critical technologies,” “critical infrastructure” or “sensitive personal data of U.S. citizens” will also be addressed in rulemaking. The CFIUS Chair has 180 days to submit an implementation plan to Congress

Contacts

Insights

Client Alert | 4 min read | 08.14.26

License to Hack? The White House Greenlights Private-Sector Offensive Cyber Operations

On August 12, 2026, the White House released a National Security Presidential Memorandum (NSPM), marking a seismic shift in U.S. cybersecurity policy and establishing a framework to authorize private-sector companies to conduct offensive cyber operations—historically strictly prohibited by federal law—against foreign Cyber-Enabled Transnational Criminal Organizations (CE-TCOs).  It builds on an executive order issued in March 2026 that directed federal agencies to develop plans to combat cyber-crimes against Americans....