1. Home
  2. |Insights
  3. |U.S. National Security Review of Foreign Investment: Revisions to CFIUS Legislation Signed Into Law

U.S. National Security Review of Foreign Investment: Revisions to CFIUS Legislation Signed Into Law

Client Alert | 1 min read | 08.17.18

On August 13, 2018, the President signed the National Defense Authorization Act for Fiscal Year 2019 which includes the Foreign Investment Risk Review Modernization Act of 2018 (FIRRMA) updating national security reviews performed by the Committee on Foreign Investment in the United States (CFIUS). Some FIRRMA provisions are effective immediately, but the effective date of others requires formal rulemaking to be completed within the next 18 months. Included in the provisions effective immediately is a lengthening of the review process (including the ability to provide limited 15-day extensions) and express authority to suspend transactions pending review or to enter into interim mitigation while the review proceeds. The FIRRMA provision authorizing a filing fee of up to $300,000 is effective immediately, and could perhaps be implemented sooner than the other regulations mandated by the Act. Awaiting rulemaking and industry input are such reform provisions as providing for voluntary (and in some cases mandatory) short form declarations. Implementation of the provisions arguably expanding the Committee’s jurisdiction, or at least codifying CFIUS’s broad interpretation of its existing authority, such as review certain real estate transactions and non-controlling investments involving “critical technologies,” “critical infrastructure” or “sensitive personal data of U.S. citizens” will also be addressed in rulemaking. The CFIUS Chair has 180 days to submit an implementation plan to Congress

Contacts

Insights

Client Alert | 13 min read | 06.12.26

EU Cyber Resilience Act Countdown: 11 September 2026 Incident/Vulnerability Reporting Deadline Less Than 100 Days Away

The EU Cyber Resilience Act (CRA) is an EU product cybersecurity law for connected products (formally, “products with digital elements” under the CRA) commercialized in the EU; it entered into force on 10 December 2024, with direct application across the EU. Full application begins 11 December 2027, but one of its most operationally demanding provisions takes effect in just under 100 days, on 11 September 2026: the mandatory vulnerability and incident reporting under Article 14 CRA....