Marquee Background
Marquee Background

Offit Kurman Blogs

Business

New Mandatory CFIUS Filing Rule for Critical Technologies

October 4, 2023

By Michiel A. Bloemsma

New Mandatory CFIUS Filing Rule for Critical Technologies

Originally posted on 10/12/2020, content updated on 10/04/2023

On September 15, 2020, the U.S. Treasury Department issued a  rule changing the requirements for mandatory filings with CFIUS for a national security review of certain investments by foreign investors in U.S. businesses with critical technologies. As of October 15, 2020, CFIUS no longer reviews whether the critical technology of the U.S. company is used in one of 27 specified industries identified by their North American Industry Classification System ("NAICS") codes (the NAICS test). Instead, critical technology requires a CFIUS filing if the export of the technology from the U.S. to the foreign investor requires a license from the U.S. government (export control test).

In a previous article, the CFIUS filing requirements were addressed in general, including the NAICS test (learn more here »). Whether a CFIUS filing is required is an important issue that needs to be addressed when a foreign company invests in a U.S. technology company. Failure to submit a mandatory filing may result in civil penalties up to the greater of $250,000 or the value of the transaction.

The NAICS test continues to apply to transactions for which the signing or the closing occurred on or after February 15, 2020, and before October 15, 2020. The determination of whether the target U.S. company is engaged in "critical technologies" activities is assessed as of the date of signing a binding written agreement for the transaction. This means that if a technology is declared "critical" by the government after signing the agreement, it is not subject to the mandatory filing requirement. The universe of "critical technologies" will likely expand as the government continues to identify "emerging" and "foundational" technologies under the Export Control Reform Act of 2018 (ECRA).

A U.S. license or authorization may be required under one of the four major U.S. export control regimes: (i) the U.S. Department of State's International Traffic in Arms Regulations (the "ITAR"); (ii) the U.S. Department of Commerce's Export Administration Regulations (the "EAR"); (iii) the Department of Energy's regulations governing assistance to certain foreign atomic-energy activities; and (iv) the Nuclear Regulatory Commission's regulations governing the export and import of certain nuclear equipment and material. Of the export control regimes, the EAR is the one that will be most likely relevant for investments in technology companies. The EAR controls the export and reexport of most commercial items (commodities, software, and technology) and are administered by the Bureau of Industry and Security (BIS), which is part of the U.S. Commerce Department. Only a small percentage of all U.S. export transactions require licenses from the U.S. government, including so-called dual-use items (both civil and military). To determine whether an item is subject to the EAR, one should refer to the EAR's Commerce Control List (CCL) to see if it has an Export Control Classification Number (ECCN). If the item falls under the jurisdiction of the U.S. Department of Commerce and is not listed on the CCL, it most likely will not require an export license. Depending on the destination, end-user, or end use of the item, however, even such an item may require an export license.

If the export control laws provide for any license exceptions, a CFIUS filing will still be mandatory unless any of the EAR license exceptions for technology and software (unrestricted) (TSU), encryption (ENC), and strategic trade authorization (STA) apply. Certain license exceptions may contain procedural requirements. For example, the ENC license exception requires submission of a classification request to the Bureau of Industry and Security 30 days before export. If a license exception imposes certain procedural requirements before export, those procedural requirements will have to be met in order for the CFIUS filing to be non-mandatory.

Since export licenses are much more likely to be required for exports to countries subject to stricter U.S. export controls, such as China and Russia, investors from those countries will become subject to heightened CFIUS review. Under the new export control test, not only will it need to be reviewed whether the (hypothetical) export of the technology from the U.S. to the foreign investor would require a license from the U.S. government, but also to the home countries of those who hold a 25 percent direct or indirect interest in the foreign investor.

Categories: Business

Related People

Related Services

  • Posts
  • About
  • Subscribe

Firm Highlights

  • Events
    AIA Tri-State Conference
    Princeton will serve as the backdrop for three days of connection, learning, and design leadership. From keynotes to tours to the Tri-State Design Awards, this year’s conference is designed to go far beyond education sessions. Kick off the week with pre-conference intensives and individual state component Design Award celebrations, followed by three days of education, inspiration, networking, and design excellence at the 2026 AIA Tri-State Conference—featuring pre-conference intensives, three keynote speakers, 25 education sessions, curated tours, an expo, spec academies, and the AIA Tri-State Design Awards—bringing together architects and design professionals from New Jersey, New York, and Pennsylvania to connect, learn, and celebrate the best of the profession. G2. Designing Secure Practices: Cybersecurity, Data Privacy, Contractual Provisions, and Insurance Risks for Architects (4:00 PM - 5:30 PM) Architects and design professionals increasingly rely on cloud platforms, BIM software, and digital tools to manage sensitive data, creating cybersecurity and privacy risks. A single incident can trigger liability claims, regulatory obligations, reputational harm, and insurance challenges. Yet many firms underestimate how contracts, insurance, and internal practices intersect during a breach. This program offers legal and insurance perspectives on cyber risk in architecture, examining liability exposure, risky contract provisions, and mitigation strategies. A cyber insurance expert will explain policy responses, coverage gaps, coordination with professional liability, and best practices for aligning insurance with contractual risk and protecting firms from evolving cyber threats. Learning Objectives: Identify key cybersecurity and data privacy risks faced by architecture firms and explain how these risks can impact professional liability and project outcomes. Analyze common contractual provisions to determine which clauses may increase exposure to cyber incidents and propose strategies to mitigate these risks. Evaluate the scope and limitations of cyber insurance policies, including coordination with professional liability coverage, to determine how a policy would respond in a breach scenario. Develop actionable risk management strategies by integrating legal, contractual, and insurance considerations to protect sensitive client and project data.