CFIUS Filing Guide for Growth-Stage Deals

A growth round can trigger CFIUS even if your company is doing only $500,000 to $10 million in revenue. If a foreign investor gets more than a passive stake - like a board seat, observer rights, nonpublic tech access, or say over key decisions - you may need to file before closing.
Here’s the short version: I’d screen the company for critical technology, critical infrastructure, and sensitive personal data first. Then I’d map who owns what, trace foreign links, review investor rights, and decide whether the deal calls for a mandatory declaration, a voluntary declaration, or a full notice. Timing matters too: a declaration can take about 30 days after acceptance, while a full notice can stretch to 45 + 45 + 15 days in harder cases, plus prep time.
If I wanted a simple checklist, I’d use this:
- Check scope first: Is there a foreign person in the deal, and is the company a TID U.S. business?
- Review rights, not just ownership %: Board, observer, veto, and info rights often matter more than stake size.
- Figure out filing type: Some deals require a filing at least 30 days before closing.
- Build the record early: Cap table, ownership tree, export-control data, customer mix, data maps, and governance docs.
- Set owners internally: Legal, finance, product, security, and HR should each own their part.
- Plan for follow-ups: CFIUS response windows can be as short as 2 business days for declarations and 3 business days for notices.
- Leave room for mitigation: Terms may limit board access, data access, or control after closing.
A simple way to think about it: CFIUS is less about company size and more about business activity, investor rights, and foreign ties. If you sort those three points early, you lower closing risk and avoid last-minute filing problems.
Living with Chronic CFIUS: Foreign Investment Review Security Imperatives
sbb-itb-e766981
Step 1: Scope the Deal and Decide Whether CFIUS Review Applies
CFIUS Filing Types: Declaration vs. Full Notice Timeline & Requirements
Identify Covered Transactions and TID U.S. Business Risk
CFIUS starts with a basic question: is a foreign investor, or a foreign-controlled entity, getting rights in the deal? That includes a foreign fund, a foreign parent, or a foreign beneficial owner sitting behind an SPV.
A covered control transaction means a foreign person gets control-like rights. A covered investment is different. In that case, a non-controlling foreign investor may still trigger review if it gets board rights, observer rights, access to nonpublic technical information, or a say in certain decisions involving a TID U.S. business.
To figure out whether your company is a TID U.S. business, work through three checks:
- Does the company produce, design, test, or develop products subject to export controls?
- Does it own or run assets tied to critical infrastructure, such as telecommunications networks, energy systems, or industrial control systems?
- Does it maintain sensitive personal data at scale?[3][8][5][9]
If the company lands in TID territory, the investor's ownership percentage may not be the main issue. For covered investment analysis, CFIUS cares more about whether the foreign investor gets rights that go beyond a passive stake. Defense or intelligence contracts can also draw added scrutiny, even if TID status is a close call.
If the answer is yes, move straight to ownership and rights mapping.
Determine Whether a Filing Is Mandatory or Voluntary
Once you've decided the deal is covered, the next step is figuring out whether the filing is mandatory or voluntary.
Mandatory filings usually come up in two situations: critical-technology deals that hit the rights thresholds, and transactions where a foreign government holds a substantial interest in the foreign investor. Mandatory declarations must usually be filed at least 30 days before closing.[4][10][11]
Voluntary filings cover the rest. Most CFIUS filings still fall into this bucket. The big reason parties file voluntarily is simple: clearance usually puts the matter to bed.[2][6] If there's any doubt about whether a mandatory trigger applies, don't wing it. That's a call for CFIUS counsel.
Choose Between a Declaration and a Full Notice
If a filing makes sense, the deal team has to pick between a short-form declaration and a full notice. That choice turns on deal complexity, risk, and how much certainty the parties want before closing.
| Factor | Declaration | Full Notice |
|---|---|---|
| Information Depth | Abbreviated; less detail required | Comprehensive; deeper disclosure across the deal |
| Review Timeline | 30-day assessment | 45-day review, plus possible investigation |
| Filing Fees | No filing fee | Fees may apply, depending on transaction value |
| Investigation Risk | Lower; CFIUS may request a full notice if it cannot clear the deal | Higher for complex deals; more formal process |
| Typical Use Cases | Low-risk growth rounds | Sensitive or complex deals |
Declarations are faster and less expensive, so they can fit straightforward growth-stage rounds well. The catch is that CFIUS may come back and ask for a full notice if it can't finish its review within the 30-day period.[2][6][7] Full notices take more time and can cost more, but they give both sides more room to explain the deal, deal with national security issues, and tee up any mitigation steps from the start.
For deals involving foreign-government-linked investors, sensitive technology, or tangled ownership structures, a full notice is often the safer path. That choice ties back to ownership and the rights the investor will receive.
Once the filing path is set, map ownership and investor rights next.
Step 2: Map Ownership, Control, and Investor Rights
Once you've picked the filing path, the next job is to map direct and indirect ownership and control. The term sheet won't get you there on its own.
Build an Ownership Map From the Cap Table Up
Start with the latest capitalization table from your equity management system or spreadsheet. Pull in every security:
- common stock
- preferred stock by series
- options
- warrants
- SAFEs
- convertible notes
For each holder, record the full legal name, jurisdiction of organization for entities or citizenship for individuals, percentage ownership on an as-converted, fully diluted basis, and any governance rights.
Then work upward through each entity investor. If it's a venture fund, identify the general partner, management company, and LP base. If it's a corporate or sovereign investor, identify the ultimate parent and any state-owned or state-controlled entities in the chain. SAFEs and convertible notes should be translated to as-converted ownership so diluted ownership shows up on that same basis.
From there, build an ownership tree and a table that shows direct and indirect holdings. Make foreign persons, or capital tied to a foreign government, easy to spot. Before filing, clean up the cap table so direct and indirect ownership lines up across legal, fractional CFO or finance, and investor records. Then use the ownership tree to tie each foreign holder to its governance rights and data access rights.
Review Governance, Information, and Veto Rights
Go through every investor rights agreement, charter, stockholders' agreement, and side letter. Put board seats, observer rights, information rights, and consent rights into one matrix.
Pay close attention to board seats, observer rights, information rights, and veto rights. A foreign investor with governance rights or access to company data can create more CFIUS risk, even with a small ownership stake.[12][13][3]
After that, sort investors based on the mix of ownership, rights, and foreign ties.
Rank Investors by CFIUS Risk Level
Once you've logged ownership and rights, group investors by risk level so counsel and management can aim diligence where it matters most. A practical framework scores each investor across four areas: nationality or jurisdiction, foreign government ties, governance and control rights, and information or data access. That ranking shows which investors need the most paperwork and review before the filing draft starts.
Here's what that can look like in a typical growth-stage deal:
| Investor Category | Foreign Ownership Indicators | Governance / Data Access | CFIUS Review Sensitivity |
|---|---|---|---|
| U.S. VC fund (no foreign control) | No foreign person ≥25%; no sovereign LPs | Board seat held by U.S. person; standard financials only | Low |
| Foreign ally VC fund (EU/UK) | Allied country; no known state ties | Board observer (foreign national); high-level board decks | Low–Moderate |
| Sovereign wealth-backed PE fund | Sovereign LP holds significant share of commitments | No board seat; quarterly financial reports; record inspection rights | Moderate |
| Foreign strategic corporate (Asia-based tech) | Foreign parent with state-influenced governance | Board seat; broad information rights including technical roadmaps | High |
| State-owned enterprise | Directly majority-owned by foreign state | No formal board seat; contractual veto over key contracts | High |
Use this ranking to focus diligence, disclosures, and any rights changes before filing. In practice, the highest-risk investors tend to set the pace for the filing timeline and the data-room checklist.
Step 3: Plan the Filing Timeline, Data Room, and Internal Workstreams
The next step is simple in theory but messy in practice: turn your risk review into an execution plan that matches your actual deal timeline, not the polished version people like to put in slide decks.
Build a Realistic CFIUS Timeline Into the Deal Calendar
For a short-form declaration, CFIUS generally has 30 calendar days from acceptance to respond.[2][14] But the filing window is only part of the story. Growth-stage companies should still set aside 2–4 weeks to pull documents, line up internal teams, and coordinate with investors. Then add another 1–2 weeks in case CFIUS asks follow-up questions or tells you to file a full notice.[15][17]
For a full notice, CFIUS usually gets a 45-day initial review period, followed by an optional 45-day investigation.[6][14] In harder cases, the timeline can stretch to 105 days of statutory review time by itself: 45 days of review, 45 days of investigation, and a possible 15-day extension in extraordinary circumstances.[6][16]
| Scenario | Preparation | Intake Buffer | Formal Review | Investigation / Mitigation | Estimated Total |
|---|---|---|---|---|---|
| Declaration (low-risk) | 2–4 weeks | ~1 week | 30 days | None | ~8–10 weeks |
| Standard notice | 4–6 weeks | 1–2 weeks | 45 days | None | ~12–14 weeks |
| Complex notice with mitigation | 6–8 weeks | 1–2 weeks | 45 days | 45 days + 4–8 weeks negotiation | ~18–24 weeks |
A good rule here: use the longest likely path when setting the long-stop date. Then start document collection from there. Also, make CFIUS clearance an explicit closing condition in the deal documents. That gives the parties room to sign while the review keeps moving, which matters a lot for growth-stage companies working with tight cash runways.[6][15]
Assemble the Filing Package and CFIUS Data Room
Think of the data room as the evidence file behind the filing. If CFIUS asks how ownership works, what data the company holds, or whether a product falls under export controls, this is where the backup should live.
The easiest setup is a folder structure that matches the form itself:
- Ownership and governance
- Technology and export controls
- Customers and government contracts
- Data and cybersecurity
- Compliance policies
It also helps to keep a simple tracking sheet for every item in the room. List the document name, internal owner, last updated date, and status. Nothing fancy. That one spreadsheet can make weekly check-ins much less chaotic and helps surface gaps before they turn into filing delays.
| Document Category | Why CFIUS Needs It | Internal Owner |
|---|---|---|
| Ownership charts / cap table (pre- and post-transaction) | Shows all direct and indirect owners, voting and economic interests, upstream control, and the foreign ownership chain.[18][20] | Finance + Legal |
| Transaction docs and step plans | Explains deal mechanics and resulting ownership interests.[18] | Legal |
| Charter documents and bylaws | Clarifies governance rights and control structure | Legal |
| Export control classifications (EAR, ITAR) | Identifies whether products or technology are controlled[19] | Legal + Compliance |
| Product and technology summaries | Identifies critical technology and sensitive-data exposure[19] | Product + Engineering |
| Customer concentration and U.S. government contracts | Shows government exposure and revenue concentration[19] | Finance + Legal |
| Data maps | Clarifies what sensitive data exists, where it's stored, and who accesses it[19] | Security |
| Compliance policies (security, data protection, export) | Demonstrates compliance posture[19] | Legal + Compliance |
For multi-step deals or minority investments, use pro forma capitalization tables and transaction step plans. CFIUS specifically finds these helpful when sorting out how ownership changes over the life of the deal.[18] For non-publicly traded entities, ownership interests should be labeled clearly and add up to 100%. For publicly traded entities, shareholders with less than 5% each should be grouped together and shown as a single bucket.[18]
Assign Internal Owners for Legal, Finance, and Technical Inputs
This part sounds basic, but it saves a lot of pain: assign one owner per topic.
Legal should run the overall CFIUS workstream. That usually means drafting the main narrative, syncing timing with the broader transaction, and owning the transaction documents and governance statements. Finance should own the cap table, equity history, and financial statements, and make sure the numbers match across internal records, the investor data room, and the CFIUS filing itself.[18][19]
Engineering or product teams should draft plain-English summaries of products, systems, and data flows early. Legal can then turn those into filing-ready text. Information security should handle data flows and access controls. If the filing calls for key personnel or employee data, HR should own that piece. Final certifications should sit with leadership.
Once the owners are set and the documents are mapped, the process moves into investor coordination and CFIUS response prep.
Step 4: Coordinate Investors, Respond to CFIUS, and Prepare for Closing
Set Expectations With Investors and Deal Counterparties Early
With ownership mapped and the data room in place, the next move is investor coordination.
This is where growth-stage deals can get messy. Many involve layered fund structures, so disclosure may go well past the immediate fund and reach parent entities and ultimate beneficial owners.
Send a standard information request to each investor as soon as the filing path is set. Ask for:
- Upstream ownership
- Side letters
- Voting arrangements
- Board designation rights
- Information rights
- Veto rights
- Foreign ownership or control links
Use the ownership tree and rights matrix to aim these requests at the right entities. That helps you avoid a long, frustrating chase for disclosures you don't even need. Some investors may resist upstream fund disclosure or feel uneasy about sharing side-letter terms. In practice, that friction often drops when counsel explains why the request matters.
Tell counterparties early whether the filing path is a declaration or a full notice. That gives everyone a more grounded view of closing timing. A quick heads-up about possible delays or amended terms before closing can save the deal team from a last-minute scramble around an impossible close date.
Prepare for Follow-Up Questions and Possible Mitigation Terms
Once the filing is submitted, expect follow-up questions. CFIUS often asks for more detail on ownership, governance, products, data access, customers, supply chain, export controls, and foreign influence.[6]
The response windows are tight: 2 business days for declarations and 3 business days for full notices.[6] That's a very short clock if no one has clear ownership over the answers or the backup documents.
A live response tracker helps keep things moving. Assign an owner and deadline to every question. Then route each CFIUS request to the internal lead already tied to that topic in Step 3. Legal should draft the responses. Finance should pull investor documents and org charts. Technical teams should explain products, data flows, cybersecurity controls, and any sensitive-data exposure. Move fast, but don't create inconsistencies along the way.
If the review brings up national security concerns, CFIUS may push for mitigation instead of rejecting the deal. If CFIUS raises national security concerns, it may require mitigation instead of blocking the deal. Common terms can limit board participation, data access, cybersecurity, reporting, and operational control. Before agreeing to anything, map each term to the process it changes. That sounds basic, but it's where teams often get tripped up.
Treat mitigation as a closing-term issue, not just a paperwork item. A restriction that looks workable with segmented systems today may become much harder to manage as the company grows or takes new financing. Noncompliance can lead to enforcement and reopen the review.[21][22][1]
Conclusion: Core Steps for a CFIUS-Ready Deal Process
A CFIUS-ready process comes down to a few early choices made with discipline. Screen the deal before signing. Confirm whether the transaction is covered and whether the filing is mandatory or voluntary. Map ownership and investor rights all the way up the chain. Choose the filing path - declaration or full notice - based on the actual risk profile, not just the shortest timeline. Build the data room before deadlines tighten. Then get investors, counterparties, and internal teams aligned around a review calendar that leaves room for follow-up questions and possible mitigation.
Each step cuts execution risk and puts the deal in a better position to close on terms the parties can actually live with.
FAQs
How do I know if my company is a TID U.S. business?
Review your business activities against CFIUS criteria for critical technology, critical infrastructure, and sensitive personal data.
A company may be a TID U.S. business if it:
- develops or produces critical technologies
- owns or operates covered infrastructure
- maintains or collects sensitive personal data of U.S. citizens
The next step is to map your assets, services, and data practices to those categories. That sounds simple on paper, but the definitions can get tricky fast. One product line, one data set, or one service relationship can change the analysis.
Because of that, it often helps to bring in legal and financial advisors with CFIUS experience. They can review the facts, test your assumptions, and help confirm whether your company falls within TID U.S. business status.
What investor rights make a stake non-passive under CFIUS?
The available materials do not say which investor rights make a stake non-passive under CFIUS.
They talk about CFIUS review for deals tied to sensitive technology, critical infrastructure, and personal data. They also cover general due diligence and filing steps. But they do not spell out the specific governance rights or ownership thresholds that would move an investment from passive to non-passive.
When should we choose a declaration instead of a full notice?
Choose a declaration when the transaction is fairly simple and seems to present lower regulatory risk. It’s a shorter filing, so it makes sense when less detail is needed.
Choose a full notice for more complex deals or transactions tied to sensitive sectors, where deeper CFIUS review is more likely. Work with legal counsel to assess your risk profile and filing obligations.



